Vulnerability Assessment

Systematic investigation of weaknesses in systems, applications and processes.

A vulnerability assessment is a systematic examination of systems, applications, networks and processes to identify security weaknesses that could be exploited by threats. Unlike penetration testing, which actively attempts to exploit vulnerabilities, a vulnerability assessment focuses on discovery and classification, typically using a combination of automated scanning tools and manual analysis. Findings are prioritised based on severity, exploitability and potential business impact.

Regular vulnerability assessments are a fundamental component of any information security programme and are required by standards such as ISO 27001, PCI DSS and SOC 2. They provide a clear picture of an organisation's attack surface and feed directly into vulnerability management and remediation workflows. Combining assessments with threat intelligence ensures that the most relevant and dangerous weaknesses are addressed first.

Frequently asked questions

What is a vulnerability assessment?
A vulnerability assessment is a systematic review that identifies, classifies and prioritises weaknesses across systems, networks and applications, usually combining automated scanning with expert interpretation of the results.
How does a vulnerability assessment differ from a penetration test?
A vulnerability assessment favours breadth: it finds and ranks as many weaknesses as possible. A penetration test favours depth: a tester actively exploits a smaller number to prove real-world impact. Most compliance programmes need both.
How often should you run one?
Scanning is typically continuous or monthly, with a fuller assessment quarterly and after any significant change. Neither ISO 27001 nor SOC 2 fixes a frequency, but auditors under both expect a defined, documented cadence rather than ad-hoc checks.