Vulnerability Assessment
Not everything needs a full penetration test, and not every budget stretches to one each quarter. A vulnerability assessment gives you breadth: a sweep of your estate for known weaknesses, triaged by our engineers so you get a genuine priority list rather than a thousand-page scanner export.
Who this is for
- You want a regular security cadence between annual penetration tests
- You need a fast, affordable baseline across a large estate before deciding where deeper testing should focus
- A framework or policy requires periodic vulnerability assessment with evidence of review
- You run scans internally but nobody has time to separate the signal from the noise
What we test
Coverage runs in depth, not breadth alone — each stage goes past where the one above it stops.
- Coverage
Everything in scope, scanned
Known vulnerabilities across servers, workstations and network devices, internal or external, using industry-standard tooling — breadth first.
- Configuration
Beyond missing patches
End-of-life software and insecure service configuration, including weak TLS and management interfaces exposed where they should not be.
- Credentials
The defaults nobody changed
Default and well-known credentials on common services and devices — consistently among the fastest routes in, and consistently missed.
- Triage
Where this stops being a scan
Our engineers validate every result, strip false positives and consolidate duplicates before anything reaches your report. Raw scanner output is not a deliverable.
What you get
The package in three parts — what you read, what you act on, and what happens after.
What you read
A working priority list, not raw output.
- A triaged, deduplicated findings list rated by CVSS
- An honest severity picture: what needs fixing this week, this quarter, and what is acceptable risk
What you act on
Written for whoever actually does the work.
- Straightforward remediation guidance for each finding, suitable for your IT team or MSP to action
- Trend visibility when run on a cadence, showing whether your patching process is keeping up
What happens after
Closure verified rather than assumed.
- Free remediation retest of the issues we raised*
* Free remediation retesting applies to penetration testing engagements. It is subject to the size of the assessment and available for three months from delivery of your report. A web application test is typically covered; a large engagement — an internal test across hundreds of systems, for example — is scoped and quoted, and a full re-assessment is always chargeable.
How it runs

The same six phases, every engagement
Threat Model Development
We agree what the exercise is replicating: the credible threats to your organisation, the starting position, the objectives, and which controls are in scope. It is also where disruption is bounded, so the test does not cost you a working day.
Information Gathering
Enumerating the systems and services actually in play from that starting point, so the attack surface is mapped as it is rather than as the asset register describes it — and choosing tools and techniques that suit it.
Vulnerability Identification
Examining that surface for weakness, using automated tooling for breadth and manual technique for everything a scanner cannot reason about. Neither finds what the other does, which is why the blend is deliberate.
Attack Vector Development
Weighing each weakness against your actual environment — how exploitable it really is, what skill it demands, what it would cost you. The output is the routes that are practical here, not the ones theoretically possible somewhere.
Exploitation
Where it is appropriate, we exploit, which usually opens a fresh attack surface and sends us back round the cycle. Where exploiting would cause harm we verify the finding is genuine rather than a stale banner, and assume the worst case.
Reporting
One document for two audiences: an executive summary your board can act on, and the technical chain your engineers can reproduce step by step, each finding carrying its severity and its remediation.
Prerequisites
- Scope of IP ranges or hostnames, and internal access (VPN or appliance) for internal assessments
- Allowlisting of Laneden's scanning addresses where protective controls would block coverage
- A signed Laneden authorisation form
Frequently asked questions
How is this different from a penetration test?
Honestly: it is lighter. An assessment identifies and validates known weaknesses in breadth; a penetration test adds human exploitation, chaining and business-logic attack in depth. We will always tell you which one your situation actually calls for.
Can't we just run the scanner ourselves?
You can, and some clients do. What we add is the triage: validating results, removing false positives and applying a tester's judgement about which findings are genuinely exploitable. That is usually where in-house time runs out.
How often should we run an assessment?
Quarterly is the most common cadence, sitting between annual penetration tests. Monthly suits fast-changing estates; the right answer depends on how quickly your environment changes.
Will scanning disrupt our systems?
Scans are configured for safety, with fragile or legacy systems flagged at scoping and handled with lighter checks or agreed windows. Disruption is rare and we schedule to suit your operations.
Related services
Internal Infrastructure Testing
When an attacker gets past the perimeter — through phishing, a compromised laptop or a rogue device — how far can they go?
Learn more →
External Infrastructure Testing
Everything you expose to the internet — mail, VPN, remote access, forgotten subdomains — is being probed constantly by people who never asked permission.
Learn more →
Web Application Testing
Your web applications are your most exposed attack surface.
Learn more →
Ready to test your defences?
Tell us about your vulnerability assessment requirement — we'll come back with a scoped proposal within two working days.
Free remediation retesting* to confirm your fixes (subject to assessment size).
