Vulnerability Scanning
Book Free Consultation ›As part of a robust cyber security strategy, regular vulnerability scanning is essential for identifying and addressing weaknesses before they can be exploited. At Evolve North, we help organisations proactively manage cyber risk by delivering comprehensive vulnerability scanning services that support compliance, improve resilience and strengthen your overall security posture.
Find Your Price
- Scope
- Scale
- Schedule
What do you need to scan?
Choose one or more. Many organisations combine external and internal scanning, and there's a discount for doing both.
Internet-facing systems
External scanning of your public websites, servers and services. A target is one internet-facing IP address or hostname, for example your website, mail server or VPN gateway. We scan them from the outside, just as an attacker would see them.
Internal devices, via agents
A lightweight agent on each laptop or server, reporting in from anywhere. A small piece of software installed on each device. Agents check the device from the inside and report in wherever it is, which makes them ideal for remote and hybrid workforces.
Internal network, via an appliance
A scanning appliance we supply and manage, scanning your network from the inside. A physical or virtual scanning appliance installed on your network. It discovers and scans everything it can reach from the inside. Typically you need one per site or network.
How many?
Volume discounts are built in automatically: the more you add, the lower the rate on each additional one. Pricing is graduated in bands: your first few targets or agents are charged at the standard rate, and each further band costs less per unit. Your quote applies those rates automatically.
How often, and for how long?
Regular scanning keeps you protected as new vulnerabilities appear every day. Most of our customers scan quarterly or monthly.
Scanning frequency
Quarterly
A full scan and report every three months. The standard for good practice and most compliance schemes.
Monthly
A scan and report every month, for a tighter grip on fast-moving estates.
One-off
A single scan and report. A good starting point if you've never been scanned before.
One-off scans aren't available because you've selected PCI ASV attestation, which requires ongoing scanning.
Please note: PCI ASV attestation is only provided on a quarterly basis, not monthly. Your monthly scans in between are for your own assurance.
Contract term
Your indicative price
What is Vulnerability Scanning?
Vulnerability scanning is the process of systematically identifying known security weaknesses in your systems, networks and applications. Using automated tools, we scan your environment for vulnerabilities and provide a detailed report with risk ratings. This helps you prioritise remediation efforts effectively.
Regular scanning ensures that your organisation stays ahead of emerging threats, maintains compliance with standards such as PCI DSS and verifies that existing controls are functioning as intended.
Vulnerability Scanning vs. Penetration Testing
Vulnerability scanning is an automated process that identifies known vulnerabilities. It is cost-effective, fast and suitable for regular use.
Penetration testing is a manual, in-depth assessment that simulates real-world attacks to test the effectiveness of your defences. It is typically performed less frequently but provides deeper insights.
We can help you determine which service is right for your organisation or how both can work together to enhance your cyber security posture.
What’s covered
Our Service
At Evolve North, we take a structured, organisation-wide approach to vulnerability management. Our service includes:
Internal and external vulnerability scans
Comprehensive scanning across your internal network and external-facing assets to identify weaknesses before attackers do.
Quarterly ASV attested reports
Approved Scanning Vendor attested reports delivered every quarter to support your PCI DSS compliance requirements.
Risk-rated findings with clear remediation
Every finding is prioritised by risk and paired with practical, clearly written remediation guidance your team can act on.
Ongoing guidance to implement improvements
We stay alongside you after the report lands, helping you work through fixes and strengthen your security posture over time.
Tailored to your environment
Scans are shaped around your infrastructure, your compliance obligations, and the specific risks relevant to your organisation.
Scheduled scanning for continuous monitoring
Flexible scheduling options mean vulnerabilities are caught as they emerge, not just at point-in-time assessments.
Arrange a FREE Consultation
Whether you're introducing vulnerability scanning for the first time or looking to enhance your existing approach, our experienced consultants are here to support you. In a free consultation, we’ll assess your current scanning practices, highlight areas for improvement and explore how our tailored services can help strengthen your organisation’s cyber security posture. Let’s work together to reduce risk and build lasting resilience.
