BrickellTechnologies

Service

Vulnerability Assessments

Broad coverage across everything you own, then a human pass that removes the false positives and ranks what is left by what an attacker would reach first.

Coverage first, then judgment

A penetration test goes deep on a narrow scope. An assessment goes wide: every host, every container image, every endpoint, every cloud workload, credentialed where possible. That breadth is worth having, and it is also why the raw output is unusable. Something has to sit between the scanner and your engineers.

That is the actual service. We run the tooling, then work the results by hand until what remains is short, true, and ordered by consequence.

What the human pass removes

  • Findings the scanner inferred from a version banner that was wrong
  • Backported security patches that leave the version string unchanged, which distributions do constantly and scanners misread as unpatched
  • Issues on hosts that are already unreachable from anywhere an attacker starts
  • Duplicate findings reported once per host across an identical fleet, collapsed to one item with a count
  • Critical-rated issues in components you do not have loaded, enabled, or exposed

How we rank what is left

CVSS on its own is a poor queue. It has no idea whether the host is on the internet, whether an exploit exists, or whether the affected service is even running. We rank on four things instead: reachability from an attacker's realistic starting position, whether working exploit code is public, EPSS probability, and what sits behind the host if it falls.

In practice this reorders the list substantially. An unauthenticated remote code execution on an edge appliance with a Metasploit module beats a theoretically higher-scored local privilege escalation on a workstation, every time, and your team should spend Monday on the first one.

Scanning on a schedule

Point-in-time assessment is a start, but estates drift. We can run this on a recurring basis, with each cycle producing a short delta report: what is new, what got fixed, what has been sat on past its remediation deadline. That trend line is also the evidence most compliance frameworks are actually asking for when they say "vulnerability management programme".

If a scan turns up something that looks exploitable and interesting, we will tell you and offer to prove it. That is a penetration test question, and it is a separate conversation about scope.

Questions we get asked

How is this different from just buying a scanner?

The scanner is the cheap part; the expensive part is somebody reading the output. A first authenticated scan of a mid-sized estate routinely returns thousands of findings, a large share of which are wrong, unreachable, or already mitigated by something the scanner cannot see. We do the reading, and you get a short list you can actually action instead of a CSV nobody opens twice.

Authenticated or unauthenticated scanning?

Authenticated, wherever we can get credentials. Unauthenticated scanning guesses at patch level from banners and gets it wrong constantly, in both directions. Credentialed scans read the actual package versions, which cuts the false positive rate hard and finds the things that never show up on a port.

How often should we run one?

Monthly for internal, and continuously for anything internet-facing, with a human review each quarter. PCI DSS wants quarterly external scans by an approved vendor plus a rescan after significant change; most other frameworks are looser about frequency and stricter about evidence that you acted on the results.

Will scanning break anything?

Rarely, but "rarely" is not "never" and old kit is where it happens. Printers, building management systems, medical devices and industrial gear all have a history of falling over when scanned hard. We identify that equipment during scoping and either scan it gently or leave it out with a note explaining the gap.

Do you also fix what you find?

We write the remediation guidance and we will sit with your team while they work through it, but we are not your patching vendor. If you have no one to do the work, say so early and we will keep the recommendations shaped for a small team rather than handing you a plan that assumes a dedicated crew.

Know what an attacker would reach first.

Tell us what you run and what worries you. We will come back with a scope, a fixed price and the earliest week we can start.