Skip to content

Process

How a scanning engagement unfolds

A predictable sequence so your IT contacts, MSP, and leadership know what happens before, during, and after the scan window.

Timeline sketch of a vulnerability assessment engagement on a desk with coffee and scope documents
  1. Discovery call

    We confirm business context, asset types, and whether you need an external, internal, or web application focus. You leave with a draft asset list and proposed blackout hours.

  2. Scope letter

    A written letter lists in-scope hosts or URLs, authorised techniques, contacts, and the scan window. Work does not begin until you accept the letter.

  3. Scan window

    Probing runs in the agreed hours. Your monitoring team receives our source ranges in advance so authorised traffic is not blocked mid-assessment.

  4. Analysis and verification

    We review automated output, manually verify high-severity items where practical, and draft both a leadership summary and a technical appendix.

  5. Delivery and clarification

    You receive the report, then a scheduled call to walk through priorities. Remediation stays with your team or MSP; we can quote a retest once fixes land.