Security assessment
Vulnerability Assessments
Find the weaknesses that matter, verify the evidence behind them and give owners a practical order for reducing exposure.
The engagement
Separate verified weaknesses from scanner output
A scanner result is an input, not a risk decision. It can miss an exposed path, report a condition that is not present or assign severity without understanding the asset, identity, compensating control or business consequence.
GDF combines discovery, configuration review, selected scanning and analyst validation within an agreed scope. The assessment records what was examined, when it was examined and which limits affected coverage. Findings separate confirmed exposure from items that require further testing and identify the evidence needed to verify remediation.
Scope
External exposure assessment
Identify reachable systems, services, certificates and common configuration weaknesses across the authorized internet-facing scope.
Internal vulnerability assessment
Assess supported internal networks, hosts and services with access, safety and operational boundaries defined in advance.
Cloud and identity review
Examine supported cloud configuration, permissions, administrative paths, authentication and exposure that automated network scans do not cover.
Application and dependency review
Assess supported applications, endpoints, components and dependency evidence at the depth agreed for the engagement.
Analyst validation
Review material findings to remove obvious false positives, confirm affected assets and distinguish direct evidence from an unverified tool result.
Remediation verification
Retest selected corrections and record whether the original condition remains, changed or is no longer observed.
Methodology
How the assessment runs
-
Scope
Agree targets, credentials, exclusions, maintenance constraints, contacts and handling rules.
-
Discover
Identify authorized assets, services, configurations and candidate weaknesses using appropriate manual and automated methods.
-
Validate
Review material results in their technical and business context without crossing into exploitation unless separately authorized.
-
Prioritize
Order remediation by exposure, consequence, dependency and effort, then define the evidence needed for closure.
Evidence commonly examined
Evidence reviewed
- Authorized asset and target inventory
- Discovery and service-identification records
- Scanner output and configuration evidence
- Cloud, identity and application settings
- Asset criticality and exposure context
- Remediation and retest records
What you can expect
What you receive
- Assessment scope and coverage record
- Validated findings with affected assets and evidence
- Risk-ranked remediation plan
- Selected retest and closure record
Frequently asked
Common questions
How is this different from a penetration test?
A vulnerability assessment identifies and validates weaknesses across an agreed surface. A penetration test separately authorizes controlled exploitation to test realistic attack paths and consequence. The two can inform each other, but their objectives and rules are different.
Is this only an automated scan?
No. Selected tools support discovery and coverage, while an analyst reviews scope, context and material findings. The report identifies results that were validated and those that remain tool observations.
Can you assess cloud and identity configuration?
Yes, where supported access is authorized. Cloud permissions, administrative roles and identity paths often require configuration and evidence review beyond a network scan.
Does a clean report mean no vulnerabilities exist?
No finite assessment can establish that. The report states the scope, methods, date, credentials and limitations so the result is not read more broadly than the work supports.
Related capabilities
Related services
Talk with an examiner
Discuss the matter and the next step.
Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.
24/7 hotline: 1-800-868-8189