Security assessment

Vulnerability Assessments

Find the weaknesses that matter, verify the evidence behind them and give owners a practical order for reducing exposure.

Isolated test laptop connected to a network appliance.

The engagement

Separate verified weaknesses from scanner output

A scanner result is an input, not a risk decision. It can miss an exposed path, report a condition that is not present or assign severity without understanding the asset, identity, compensating control or business consequence.

GDF combines discovery, configuration review, selected scanning and analyst validation within an agreed scope. The assessment records what was examined, when it was examined and which limits affected coverage. Findings separate confirmed exposure from items that require further testing and identify the evidence needed to verify remediation.

Scope

  • External exposure assessment

    Identify reachable systems, services, certificates and common configuration weaknesses across the authorized internet-facing scope.

  • Internal vulnerability assessment

    Assess supported internal networks, hosts and services with access, safety and operational boundaries defined in advance.

  • Cloud and identity review

    Examine supported cloud configuration, permissions, administrative paths, authentication and exposure that automated network scans do not cover.

  • Application and dependency review

    Assess supported applications, endpoints, components and dependency evidence at the depth agreed for the engagement.

  • Analyst validation

    Review material findings to remove obvious false positives, confirm affected assets and distinguish direct evidence from an unverified tool result.

  • Remediation verification

    Retest selected corrections and record whether the original condition remains, changed or is no longer observed.

A repair list your owners will actually work from

A scanner run against a mid-sized network produces a report several hundred pages long, most of it noise. Someone still has to decide what to do on Monday. GDF's vulnerability assessments validate the weaknesses that matter and tie them to specific systems and business exposure. Your technical owners get a prioritized list they can start working from. Leadership gets a version they can read in fifteen minutes.

Clients bring us this work for a scheduled security review, an acquisition, an infrastructure change or a specific worry about exposure. We settle the objective before picking tools, so the work answers the question you are paying to resolve rather than the question the scanner happens to be good at.

What was covered, and what only looked covered

An assessment is worth exactly as much as its coverage record. We compare the authorized targets against your asset information and account for exclusions, systems we could not reach and areas that need a different method entirely. A network scan alone does not establish whether cloud permissions are correctly configured. Those controls need their own review.

Authenticated assessment uses approved credentials to inspect a system from the inside: installed software, local configuration, missing patches the network cannot see. Unauthenticated assessment shows what an outsider sees on exposed services. They answer different questions, and a report should never present one as the other. Credentials that silently failed on half the hosts do not produce a clean result. They produce a coverage gap, and we report it as one.

Every result carries the method and access level that produced it, so your team can tell an examined system from one that simply appeared on the target list.

Which weaknesses matter, and which matter together

Analyst review checks whether the reported version or configuration is actually present, whether the service is reachable and what access an attacker would need. Confirmed conditions are separated from observations that still need validation. We do not exploit anything unless the engagement separately authorizes it.

Some findings are more dangerous in combination. A weak administrative permission and an exposed management interface might each receive a moderate rating when reviewed separately. Together they may be a path to full domain control. The assessment identifies that relationship and recommends targeted testing where proving the full chain matters. It will not present the inferred chain as though we had walked it.

Business context shifts priority too. A medium on the backup server or the identity provider may deserve attention before a critical on a kiosk nobody has logged into in a year. Generic severity is one input to that decision, and rarely the deciding one.

Remediation you can measure

A finding you can act on names the affected assets, the evidence, the responsible owner and the proposed fix. The handoff distinguishes urgent exposure reduction from routine repair work and longer-term improvements. Exceptions get a reason, an accountable owner and a date to look at them again.

Retesting checks the corrections against the original condition in the agreed environment. If the service moved to a new host or a compensating control went in, the record explains what that did to the exposure. Closing a ticket and reducing risk are different events, and the retest is how you tell them apart.

Methodology

How the assessment runs

  1. Scope

    Agree targets, credentials, exclusions, maintenance constraints, contacts and handling rules.

  2. Discover

    Identify authorized assets, services, configurations and candidate weaknesses using appropriate manual and automated methods.

  3. Validate

    Review material results in their technical and business context without crossing into exploitation unless separately authorized.

  4. Prioritize

    Order remediation by exposure, consequence, dependency and effort, then define the evidence needed for closure.

Evidence commonly examined

Evidence reviewed

  • Authorized asset and target inventory
  • Discovery and service-identification records
  • Scanner output and configuration evidence
  • Cloud, identity and application settings
  • Asset criticality and exposure context
  • Remediation and retest records

What you can expect

What you receive

  • Assessment scope and coverage record
  • Validated findings with affected assets and evidence
  • Risk-ranked remediation plan
  • Selected retest and closure record

Discuss your security assessment

Discuss your environment, operating constraints and reporting needs. Agree on authorized methods and deliverables before work starts.

Preview the reporting questions

This is an illustrative outline to discuss during scoping, not a report from a client engagement.

  • Scope: what was authorized, assessed and excluded?
  • Evidence: what supports each finding, and what are the limits?
  • Impact: what does the finding mean for this environment?
  • Action: what should be addressed, by whom, and how can it be validated?
Get a free consultation

Frequently asked

Common questions

Can you review results from our existing scanner?

Yes. A validation and risk prioritization engagement on your existing output is often the most cost-effective starting point. Not every engagement needs a new platform.

Can you include cloud and identity?

Yes, where we have authorized access and a supported method. Those areas go into the scope explicitly, with their own coverage record.

Will a clean report mean we are secure?

It means the agreed work produced the stated results on the stated dates. The coverage and the limitations are part of the conclusion, and we would rather you read them than skip to the summary.

How is this different from a penetration test?

A vulnerability assessment identifies and validates weaknesses across an agreed surface. A penetration test separately authorizes controlled exploitation to test realistic attack paths and consequence. The two can inform each other, but their objectives and rules are different.

Is this only an automated scan?

No. Selected tools support discovery and coverage, while an analyst reviews scope, context and material findings. The report identifies results that were validated and those that remain tool observations.

Can you assess cloud and identity configuration?

Yes, where supported access is authorized. Cloud permissions, administrative roles and identity paths often require configuration and evidence review beyond a network scan.

Does a clean report mean no vulnerabilities exist?

No finite assessment can establish that. The report states the scope, methods, date, credentials and limitations so the result is not read more broadly than the work supports.

Get a useful assessment from GDF

Get a vulnerability assessment that reduces real risk. Bring GDF your current findings, your target environment, your access constraints and the outcome you need from the review. We can scope validation, prioritization, remediation guidance and retesting so the report supports decisions your technical owners and leadership can act on. Your initial consultation is free.

Get a useful assessment from GDF

Related services and resources: cybersecurity penetration testing, application penetration testing, OT vulnerability management.

Talk with an examiner

Discuss your matter and next step

Tell us the systems, evidence and deadline. We can review relevant experience, potential conflicts and the scope before engagement.

Since 1992 · 24/7 dispatch · Court-tested experts

Or call 1-800-868-8189

Email or phone is required. A submission does not create an engagement. For an active incident, please call. Read what we send with the request.

Talk with a security specialist

Discuss the matter and the next step.

Tell us what happened and what you need to find out. Speak with a GDF expert about how we can help.

24/7 hotline: 1-800-868-8189

Privacy center

Choose your site settings

Optional technology stays off until you choose otherwise. You can change these browser settings at any time. Access to the core site does not depend on optional technologies.

Technology preferences
Sale or cross-context sharing: not used GDF does not sell or share website personal information for cross-context behavioral advertising.