What Do Vulnerability Assessments Find Most Often?

Scope Is Agreed Before Any Technical Work Starts
People sometimes picture a vulnerability assessment as someone pointing a scanner at your network and handing over a report. That’s not how we do it. We start with a 15 minute founder call to work out if we’re even a fit for each other. If that goes well, we move to a full 45 minute discovery call, where we get into your systems, your staff numbers, and what you’re actually trying to protect.
From there we run a Cyber Risk Assessment. This is the step that surfaces the gaps, the old admin account nobody deactivated, the unpatched server, the firewall rule someone set years ago and forgot about. It gives us a real picture of your business rather than an educated guess, and that assessment is what shapes the proposal, not the other way around.
Why should you care about any of this as the buyer? Because scope creep on a security job is a real risk. A provider can quietly test more than was agreed, flag things outside your control, or bill for work you never asked for. Running the discovery call and risk assessment first means you see the proposal before anything technical touches your systems.
We’ll also tell you plainly if we don’t think it’s the right fit. We work with businesses of five staff and up, and for smaller outfits the discovery call sometimes ends with us saying it isn’t the right time or the right size for what we do. That’s a genuine outcome, not a formality we go through to seem thorough.
- 15 minute founder call to check basic fit
- 45 minute discovery call to understand your systems and staff numbers
- Cyber Risk Assessment to find the gaps that actually exist
- Customised proposal built from what the assessment finds, not a template
If you want a closer look at what the assessment step covers on its own, our Vulnerability Assessments page goes into more detail on what gets checked.
Not Every Finding on the List Carries the Same Weight
A vulnerability assessment report usually sorts findings into critical, high, medium, low and informational. That label comes from a scoring system called CVSS, applied automatically by the tool. It has no idea how your network is actually set up. So a business owner staring at a report full of red critical tags can assume the worst, when a good chunk of those findings might sit on a machine that isn’t even reachable from the internet.
This happens because scanners score a vulnerability on technical severity alone, in isolation from everything around it. A missing patch that would let someone take over a server scores critical whether that server is sitting on the open internet or tucked away on an internal network with no outside access. The technical score doesn’t change. The actual risk to your business does.
Before we tell a client what to fix first, we weigh a few things:
- Whether the affected system is internet-facing or sits behind other layers of the network
- Whether the system holds or connects to sensitive data, like finance or customer records
- Whether a fix is straightforward or needs planning around business hours
- Whether the finding affects something covered by SMB1001 or ISO 27001 requirements you’re working towards
That reordering is really the point of the assessment. Producing a list of raw scanner output isn’t hard. Turning that list into three or four things worth doing this month, with a longer list that can wait, takes someone who’s read a lot of these reports and knows what actually matters.
We won’t pad a report by ranking low-impact findings as urgent just to make it look more serious. If something is technically real but low risk given how your network is built, we say so plainly and place it further down the list. Some clients expect a document full of alarm bells. What they get instead is a shorter list of things that matter, ordered around how their business actually runs, not how a scanner ranks a database of known flaws.
A Vulnerability Assessment and a Penetration Test Answer Different Questions
A vulnerability assessment finds and lists the weak points across your network, devices, and accounts. A penetration test goes a step further and actually tries to use one of those weak points to get in, the way an attacker would. People ask us which one they need, and the honest answer depends on what question you’re trying to answer.
The confusion is common because insurers, auditors, and even some IT providers use the two terms loosely. A cyber insurance renewal might ask for a penetration test when a vulnerability assessment would satisfy the requirement just fine. We’ve seen businesses pay for the wrong one simply because nobody explained the difference before the invoice landed.
- A vulnerability assessment is broad. It scans systems, servers, and endpoints and produces a ranked list of gaps.
- A penetration test is narrow and active. It picks a target and attempts real exploitation, with a report on what an attacker could actually reach.
- Most businesses starting out need the assessment first. It’s what tells you where the real gaps sit before you spend money proving them further.
Our process starts with a 15-minute founder call, then a 45-minute discovery call to make sure we’re aligned on scope. From there we run a Cyber Risk Assessment to find the gaps, and we build a proposal around what needs fixing rather than a generic package. This sits under our Vulnerability Assessments work, and we’re ISO 27001 certified for information security, which shapes how we scope and document that assessment.
If your board or insurer has specifically asked for a penetration test by name, tell us early. It changes the scope of work and the report we produce. We’d rather clarify that on the discovery call than deliver the wrong document at the end.
Thinking about Vulnerability Assessments? Let’s talk.
Get a free 15-minute IT health check. OxygenIT is ready to help.
Automated Scanning Alone Is Not the Same as a Reviewed Assessment
A lot of business owners have already run a free or automated scan before they call us. That’s fine as a first step, but it isn’t the same thing as a proper vulnerability assessment. A scanner runs through a list of known checks against your network and spits out a report. It doesn’t know your business, doesn’t know which server holds your payroll data, and can’t tell you whether a flagged issue is a real risk or just noise.
What people usually notice first is the sheer length of the report. Automated tools tend to flag dozens, sometimes hundreds, of findings, many of them low priority or outright false positives. Without someone reviewing that output against how your business actually runs, you’re left guessing which five items matter and which fifty don’t. We’ve seen owners sit on a stack of scan results for months because nobody could tell them what to fix first.
This happens because scanning tools are built to be broad, not smart. They check for patched versions, open ports, weak configurations and known vulnerabilities across thousands of systems the same way, whether you’re a five-person accounting firm or a 150-seat manufacturer. The scanner has no concept of what your data is worth, what regulations apply to you, or what a breach would actually cost you in downtime.
Our vulnerability assessments start with scanning as one input, not the whole answer. From there our engineers review the findings, weigh them against the SMB1001 framework we build our cybersecurity work around, and put together a proposal that reflects your actual setup rather than a generic checklist. That review step is where the real value sits, and it’s also where a lot of cheaper offerings stop short, because reviewing takes time and expertise no automated tool can replace.
We’ll say plainly that no scan, ours or anyone else’s, tells you everything. A point-in-time assessment shows you what your environment looks like on the day it runs. New vulnerabilities get disclosed every week, so an assessment is a snapshot, not a permanent state. That’s part of why ongoing monitoring and managed security matter alongside a one-off assessment, and it’s worth understanding before you buy either on its own.
If you want the full picture on how our assessment fits with the rest of our cyber security work, our Vulnerability Assessments page walks through the process end to end.
- A raw scan report lists findings without weighing which ones matter to your business
- A reviewed assessment adds engineer judgement, business context, and a prioritised path forward
- Both are a snapshot in time, useful but not a permanent state of security
Staff Numbers and Regulatory Requirements Change the Scope
The biggest question we get before we’ve even quoted a vulnerability assessment is why one business pays more than another for what sounds like the same thing. It comes down to two factors: how many staff and endpoints you have, and what regulations apply to your industry.
A 12-person accounting firm and a 60-person logistics company aren’t the same job. More staff means more devices, more logins, more software, and more places a gap can hide. We map every endpoint under review, not a sample, because a scan that skips half the network doesn’t tell you much.
Regulation adds a second layer. If you’re chasing SMB1001 certification, working toward ISO 27001 alignment, or need to satisfy a cyber insurance readiness check, the assessment has to test against those specific requirements. That’s different work from a general health check. We build our cybersecurity approach around the SMB1001 framework, so if certification is on your radar, we already know what the assessment needs to cover.
We’ve seen the opposite mistake too, businesses under 20 staff assuming they need the same depth of testing as a 150-person firm with contractual security obligations. That’s money spent on scope you don’t need yet.
One limitation worth naming: we don’t take on residential clients or businesses under five employees. Below that size, a full vulnerability assessment usually isn’t proportional to the risk, and we’d rather say that upfront than sell you something oversized.
- Staff and endpoint count set the base scope of testing
- Industry regulations (insurance, SMB1001, ISO alignment) add specific test requirements
- Businesses under five employees fall outside what we take on
- Scope is set during our discovery process, not guessed from a headcount alone
This is also where our Cyber Risk Assessment earns its place, it’s how we work out the real scope before anything gets quoted, rather than applying a flat rate to every business regardless of size. You can see how that fits into our wider Vulnerability Assessments work and what it covers.
If you want to know what this looks like in dollar terms for a business your size, that detail sits on our pricing page rather than here.
Vulnerability Assessment: Frequently Asked Questions
What does a vulnerability assessment actually find?
Most assessments turn up unpatched software, misconfigured services, and accounts that should have been closed when someone left or changed role. The list is usually longer than a business expects, because most have never had all of those areas checked in one sitting.
Is every finding on the report a serious problem?
No. Findings are ranked by real exposure, not by how alarming the scanner label sounds. A high-severity label on a system that is not reachable from the internet can matter far less than a medium finding on an account with administrative rights.
How is a vulnerability assessment different from a penetration test?
A vulnerability assessment identifies and ranks weaknesses across your environment. A penetration test actively tries to exploit a defined target to prove whether it can be broken into. The assessment tells you where the gaps are, the test proves what an attacker could do with one of them.
Is an automated scan the same as a vulnerability assessment?
No. Automated scanning is one input. A scanner cannot tell you which findings matter in your environment, which are false positives, or which are already mitigated by a control it cannot see. A reviewed assessment is a person interpreting that output against your setup.
What changes the scope of an assessment?
Staff numbers and regulatory requirements are the two biggest factors. More endpoints means more to check, and a business working towards a certification or a cyber insurance renewal needs specific controls evidenced rather than a general sweep.
Related reading