
Find the weaknesses before somebody else does
A vulnerability scan walks past everything attached to the network and compares it against a list of known problems. That is not a luxury but maintenance: new ones arrive every week, and the question is not whether something is open but for how long.
What a scan does and does not see
Knowing the limit saves a false sense of security.
- What it does findMissing updates, expired certificates, default passwords, services running without reason, and equipment nobody remembered. That last one is often the most useful outcome.
- What it does not findFlaws in the logic of your own application, permissions set too wide, or an employee giving away a password. That is what a penetration test or an audit is for.
- What it also deliversAn inventory. On almost every first scan, systems surface that were not on the list, and those are by definition not patched.
From scan to less risk
Four steps. The third is where it stalls at most organisations.
Scanning
From inside and from outside. What is visible from outside weighs heaviest, because that is what an attacker sees too.
Prioritising
A first scan produces hundreds of lines and that paralyses. What counts is the combination of severity and reachability: a serious problem on a system unreachable from outside can wait behind one that is not.
Remediating
Patch, close off or replace, with an owner and a date per item. Without those two a report stays a report.
Scanning again
Only a second scan shows the remediation worked. That is also the number with which you show a customer or an auditor that the process is running.
What belongs with this
Scanning is the continuous side of security.
Know what is open right now
Tell us what is attached to the internet. You get a first scan with a list sorted on severity and reachability, so there is an order to work through.
Practical IT knowledge in your inbox
New guides on management, security and the workplace, written by the people doing the work. No sales talk, and you can unsubscribe in one click.