UTMStack

Find the weaknesses inside your network before an intruder does

We remotely assess the systems inside your network for known vulnerabilities and insecure settings, then hand you a reviewed, prioritized report. After you fix the issues, we check again at no extra cost.

A stack of servers scanned by a plane of light, with weak spots highlighted
  • Up to 100 IP addresses

    Each assessment covers up to 100 internal IP addresses and is carried out remotely.

  • False positives removed

    We filter out false positives before the final report, so your team only works on real issues.

  • Proven tools

    We use Burp Suite, DirBuster, Nmap, SQLMap and OWASP ZAP, among others.

  • Free retest

    After you fix the findings, we check again for free to confirm the fixes work.

  • Experience across industries

    We assess networks for organizations in healthcare, banking, transportation, real estate and education.

What’s included

  • Remote internal assessment of up to 100 IP addresses
  • Checks of servers, network devices, services and web applications
  • Exploitative or non-exploitative testing, as agreed with you
  • Review of findings to remove false positives
  • Report with critical vulnerabilities, best-practice recommendations and the full list of tests
  • Management and executive reports
  • Free retest after you fix the findings

Inside weaknesses need inside checks

Many attacks start with one compromised laptop and spread through the network from there. An internal assessment finds the unpatched servers, weak services and insecure settings an intruder would use next.

How it works

We connect remotely, agree on the address ranges and the type of test, and run our toolkit against each target. Findings are reviewed and false positives are removed before the report is written.

Assessment or penetration test?

A vulnerability assessment looks broadly inside your network for known weaknesses. A penetration test looks at your internet-facing systems and tries to prove how far an attacker could get. Many organizations need both, and we can scope them together.

Questions buyers ask

What does the assessment cover?

Up to 100 internal IP addresses, assessed remotely. We check servers, network devices, services and web applications for known vulnerabilities and insecure settings.

Which tools do you use?

Burp Suite, DirBuster, Nmap, SQLMap and OWASP ZAP, alongside other commercial and open source tools.

How often should we run an assessment?

At least once a year, and after major changes to your network. Regular assessments also support compliance requirements such as PCI DSS and HIPAA.

Is this the same as the vulnerability scanner in UTMStack?

No. The scanner in the platform lets your own team run scans whenever it likes. This service is an assessment carried out by our testers, with a reviewed report and a free retest.

How much does an assessment cost?

Pricing depends on the number of addresses and the scope. Contact us for a quote.

Get a quote

Tell us about your environment. We reply within one business day with scope, timing and price.

We reply within one business day. See our privacy policy.