Service · Cybersecurity

Vulnerability scanning

A vulnerability scan can easily produce a two-hundred-page report with four hundred findings, and that report usually sits unread in the IT manager's inbox. The value is not in the scan, which is automated, but in what follows: separating what can really be exploited from what merely sounds alarming, deciding who fixes each item and checking the following month that it was fixed. Our service covers the whole loop. We scan what the internet sees of your company and, through an agent or a remote sensor, what sits inside. We prioritise by whether a flaw is being actively exploited, using INCIBE-CERT advisories and the CISA KEV catalogue as references, and by how exposed each system is. Then we chase every item until it is closed.

Monthly
external and internal scans
KEV and INCIBE-CERT
to rank what is being exploited
A short list
of what is urgent, not 200 pages
Until closed
follow-up on every fix

What falls within the scope of this service

Wherever possible the scan is authenticated: with read-only credentials the tool sees real versions and settings and produces far fewer false positives.

Pin down the details with one of our engineers

External surface

Public IP addresses, domains and subdomains, websites, mail and published services. It is the first thing any attacker sees and the first thing we check.

Internal network

Servers, workstations, printers, NAS boxes, cameras and network devices, scanned from a remote sensor or through agents, with nobody needing to travel.

Web applications

Automated checks on your shop, client portal or e-government site for known flaws, outdated CMS versions and vulnerable modules.

Cloud and Microsoft 365

Risky settings in Azure, AWS or Google Cloud and in your Microsoft 365 tenant: public storage, open network rules and accounts without MFA.

Prioritisation

Each finding is ranked by real-world exploitation, exposure and the value of the system. A critical flaw on an isolated server can wait for the maintenance window; a medium one on an internet-facing firewall cannot.

Patch follow-up

A remediation table with owner and date, and a rescan that confirms closure. Anything that cannot be patched is documented alongside its compensating measure.

How the engagement unfolds, one stage at a time

The first scan is the longest and noisiest. From the second month on, the report focuses on what is new and what is still open.

01

Scope

We agree what is scanned, when and with which credentials, and notify your hosting providers if needed.

02

First scan

Full results and a video call to go through the main findings and agree the order of fixes.

03

Remediation

Your team or Apply's applies the patches and changes according to the plan. Under a support plan, it is done as part of it.

04

Monthly cycle

Scheduled scans, a short report on what has changed and follow-up of open items. An immediate alert if something critical appears between scans.

A CVSS score tells you how bad a flaw could be, not how likely someone is to use it. Many vulnerabilities rated 9 are never exploited, while some rated 7 turn up in every ransomware campaign. That is why we prioritise on what happens in practice, not only on the number in the report.

Common questions

Vulnerability scanning is automated, recurring and broad: it finds known flaws across your whole estate. A penetration test is manual, one-off and deep: a person tries to exploit flaws and chain them together as an attacker would. They complement each other, and the second is covered by our penetration testing service.

It is rare, but some older or industrial devices are sensitive to heavy scanning. We identify them beforehand, scan them with a gentle profile or out of hours, and never run destructive tests. In a plant with PLCs, that part is agreed with the production manager.

Yes. The ENS includes measures on vulnerability management and security configuration, and NIS2 lists vulnerability handling among its risk-management measures. Regular reports and the follow-up table are exactly the evidence an auditor asks for.

We document it and isolate it: its own network segment, access only from the machines that need it, no internet access and closer monitoring. We also put in writing the accepted risk and the plan to retire it. The worst case is an unsupported system nobody knows exists.

Find out which vulnerabilities really matter

Tell us what you want checked: websites, servers, internal network or cloud. We will reply with a scope and a date for the first scan.

Hours
Monday to Friday, 9:00-18:00 Spanish time (CET), answers within a working day
Meetings
Video calls via Google Meet or Teams

This site only stores the cookies it needs to work and to remember your chosen city. No advertising or tracking cookies are set. See our privacy policy for the details.