Hero

WE ARE

HACKIFY

What is a vulnerability scan

Icon of a vulnerability scan

Cyber threats change constantly. Almost every day new vulnerabilities are discovered, and hackers try to exploit them straight away. An annual pentest gives you a snapshot: a picture of your security at one specific moment. A vulnerability scan gives you continuous insight into your systems and applications, including open ports, so that you quickly detect and fix new weak spots.

A vulnerability scan (also known as a security scan or vulnerability assessment) is an automated way to find vulnerabilities in your IT environment. Think of outdated software, misconfigurations or known vulnerabilities from the CVE database. Our service goes a step further: we combine multiple commercial and open-source scanners and show the results in a clear dashboard. In doing so, our experts separate the false positives and the noise from the alerts that really matter.

A traditional scan often produces a report of hundreds of pages of technical output. We filter out the alerts that do not matter and merge findings that share the same advice. All alerts about a weak TLS configuration, for example, become one clear finding with practical advice. That way you can see at a glance what the real risks are, without drowning in data.

👉 Download our whitepaper about vulnerability scanning here


Why and when is a vulnerability scan important?

Your IT environment changes constantly. New services are added, software is updated, configurations are adjusted and new vulnerabilities appear. An annual pentest gives a snapshot, but in the time between two pentests vulnerabilities can arise that go unnoticed. Most incidents arise from known vulnerabilities and outdated software that were not patched in time.

A vulnerability scan is a sensible choice in the following situations:

  • To scan your IT infrastructure regularly and flag new vulnerabilities early.
  • To meet the vulnerability management requirements of ISO 27001, NIS2 or SOC 2.
  • After a change to your infrastructure, such as a new service, a cloud migration or an adjusted configuration.
  • As an addition to your pentest, so that you also keep visibility between pentests.
  • To see when new ports are opened that an attacker could abuse.

It is wise to have your entire IT infrastructure scanned regularly. A vulnerability scan flags new vulnerabilities early. A pentest then shows which of them an attacker can actually abuse.


What do you see in the dashboard?

Instead of a static report, you get a dashboard that shows the results of the scan at a glance. The dashboard is designed to let you act quickly and to make collaboration between security, IT management and management easier.

  • Smart filtering and prioritisation. You only see the vulnerabilities that really matter, because our experts have already removed the false positives and the noise. The findings are prioritised and you can filter by system, supplier, urgency or risk category.
  • Grouped findings. Similar alerts are merged into one clear piece of advice, for example all weak SSL ciphers in a single finding.
  • Monitoring of open ports. You see which ports are open and receive an alert when a new one is opened, so that you notice an unexpected configuration change early.
  • Progress and trends. You track whether vulnerabilities are being resolved and how your security develops across multiple scans.
  • Tags and organisation. You label IP addresses or hosts with supplier, owner or risk category, so that you can filter and report in a targeted way.
  • From CVE to concrete advice. We translate CVE numbers into understandable recommendations.

Why choose Hackify?

  • Proven expertise - Ethical hackers with at least 5 years of experience, 3 certificates and relevant expertise per test component (not the industry minimum of 1 year and 1 certificate)
    • Track record - Responsible disclosures at Philips, Zoom, Oracle, the Dutch Police and many others
    • Hacking competition winners - Prizes at Hack010, PVIB CTF, Hackerhotel and HackTheHague
  • Expertise in triage - Our experts can distinguish false positives and noise from results that really matter
  • Direct contact - No account managers; speak directly with the security experts who run your scans
  • Flexibility - Vulnerability scans can be started within 2-3 weeks

More about our approach and expertise on our about us page.

Ready for ongoing vulnerability scanning?

We scan your IT infrastructure every month and filter out the noise, so that only the real risks end up on your plate. Request a tailored proposal.

Get in touch

Or email us directly at [email protected]

Frequently asked questions about vulnerability scans

What is the difference between a vulnerability scan and a pentest?

A vulnerability scan and a pentest complement each other, but each puts the emphasis on something different.

A vulnerability scan:

  • Is an automated scan that you can run regularly
  • Maps known vulnerabilities, outdated software and misconfigurations
  • Works non-intrusively and has hardly any impact on your production environment
  • Is run monthly or quarterly
  • Shows the results in an interactive dashboard

A pentest:

  • Is an in-depth manual investigation, in which ethical hackers actually try to exploit vulnerabilities
  • Examines complex attack paths and business logic flaws
  • Is carried out once or twice a year
  • Delivers a comprehensive report with the findings

Together they form a strong approach. The vulnerability scan flags new vulnerabilities early, while the pentest shows which of them an attacker can actually abuse.

What are the most common vulnerabilities you find?

Most incidents arise from known vulnerabilities and outdated software. Our vulnerability scans mainly come across the following:

  • Outdated software - Web servers, applications and systems without security updates
  • Misconfigurations - A weak TLS configuration, missing security headers and unprotected services
  • Open management ports - Ports such as SSH and RDP, or management services of firewalls and routers that you would rather shield from the internet
  • Known CVEs - Vulnerabilities from the CVE database that have not yet been patched By discovering these risks early, you prevent data breaches and other security incidents.