Security assessment

Vulnerability Assessments

Find the weaknesses that matter, verify the evidence behind them and give owners a practical order for reducing exposure.

Isolated test laptop connected to a network appliance.

The engagement

Separate verified weaknesses from scanner output

A scanner result is an input, not a risk decision. It can miss an exposed path, report a condition that is not present or assign severity without understanding the asset, identity, compensating control or business consequence.

GDF combines discovery, configuration review, selected scanning and analyst validation within an agreed scope. The assessment records what was examined, when it was examined and which limits affected coverage. Findings separate confirmed exposure from items that require further testing and identify the evidence needed to verify remediation.

Scope

  • External exposure assessment

    Identify reachable systems, services, certificates and common configuration weaknesses across the authorized internet-facing scope.

  • Internal vulnerability assessment

    Assess supported internal networks, hosts and services with access, safety and operational boundaries defined in advance.

  • Cloud and identity review

    Examine supported cloud configuration, permissions, administrative paths, authentication and exposure that automated network scans do not cover.

  • Application and dependency review

    Assess supported applications, endpoints, components and dependency evidence at the depth agreed for the engagement.

  • Analyst validation

    Review material findings to remove obvious false positives, confirm affected assets and distinguish direct evidence from an unverified tool result.

  • Remediation verification

    Retest selected corrections and record whether the original condition remains, changed or is no longer observed.

Methodology

How the assessment runs

  1. Scope

    Agree targets, credentials, exclusions, maintenance constraints, contacts and handling rules.

  2. Discover

    Identify authorized assets, services, configurations and candidate weaknesses using appropriate manual and automated methods.

  3. Validate

    Review material results in their technical and business context without crossing into exploitation unless separately authorized.

  4. Prioritize

    Order remediation by exposure, consequence, dependency and effort, then define the evidence needed for closure.

Evidence commonly examined

Evidence reviewed

  • Authorized asset and target inventory
  • Discovery and service-identification records
  • Scanner output and configuration evidence
  • Cloud, identity and application settings
  • Asset criticality and exposure context
  • Remediation and retest records

What you can expect

What you receive

  • Assessment scope and coverage record
  • Validated findings with affected assets and evidence
  • Risk-ranked remediation plan
  • Selected retest and closure record

Frequently asked

Common questions

How is this different from a penetration test?

A vulnerability assessment identifies and validates weaknesses across an agreed surface. A penetration test separately authorizes controlled exploitation to test realistic attack paths and consequence. The two can inform each other, but their objectives and rules are different.

Is this only an automated scan?

No. Selected tools support discovery and coverage, while an analyst reviews scope, context and material findings. The report identifies results that were validated and those that remain tool observations.

Can you assess cloud and identity configuration?

Yes, where supported access is authorized. Cloud permissions, administrative roles and identity paths often require configuration and evidence review beyond a network scan.

Does a clean report mean no vulnerabilities exist?

No finite assessment can establish that. The report states the scope, methods, date, credentials and limitations so the result is not read more broadly than the work supports.

Talk with an examiner

Discuss the matter and the next step.

Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.

24/7 hotline: 1-800-868-8189

Privacy center

Choose your site settings

Optional technology stays off until you choose otherwise. You can change these browser settings at any time. Access to the core site does not depend on optional technologies.

Technology preferences
Sale or cross-context sharing: not used GDF does not sell or share website personal information for cross-context behavioral advertising.