Services / Vulnerability Assessment
Vulnerability Assessments for Iowa Businesses
A vulnerability assessment finds the missing patches, insecure services, and misconfigurations across your network before an attacker does. Sanctus combines credentialed scanning with manual validation, so every finding in your report is real and comes with clear steps to fix it.
What a vulnerability assessment finds
Most breaches of small and mid-sized businesses don't start with anything exotic. They start with a server that missed an update, a service exposed to the internet that shouldn't be, or a device still using its default password. A vulnerability assessment looks for exactly those gaps across every system in scope.
- Missing patches and outdated software on servers, workstations, and network devices
- Services and admin interfaces exposed where they shouldn't be
- Default passwords and weak or risky configurations
External and internal assessments
External vulnerability assessment
Everything you expose to the internet, seen the way an attacker sees it. That includes firewalls, VPNs, email, websites, and remote access portals. This is where opportunistic attacks start, so it's often the first place to look.
Internal vulnerability assessment
The systems inside your network, including servers, workstations, file storage and NAS devices, phone systems, and network equipment across each of your network segments. This shows what an attacker could take advantage of after getting a foothold, for example through a phishing email.
Validated, not just scanned
Raw scanner output is full of false positives and duplicates, and it rarely tells your team what actually matters. We review and validate the results by hand. Every finding in your report is backed by evidence, and anything we can't confirm doesn't go in.
Validation is non-destructive. We confirm each issue with the lightest safe check and stop there. A vulnerability assessment never tries to break in. That's what a penetration test is for.
How it works
-
1. Scoping
We talk through your network, locations, and key systems and agree on what's in scope and what to exclude. For internal assessments you set up VPN access and scan accounts, and we pick a testing window that works for your team. You get a quote before any scanning starts.
A few days, mostly on your schedule
-
2. Scanning and validation
Credentialed scanning across every in-scope segment with industry-standard tools, followed by manual review and validation of the results. Our assessment process follows NIST SP 800-115, the federal guide to security testing and assessment.
Typically two to three business days of active scanning
-
3. Reporting and walkthrough
You receive a plain-English report, then we walk your team through the findings and what to fix first.
Report within a week, then a one to three hour walkthrough
What you receive
- Executive summary you can share with leadership, your insurer, or a customer asking about your security
- Findings report with every validated vulnerability rated Critical, High, Medium, or Low using CVSS v4.0, explaining what it is, why it matters, and exactly how to fix it
- Prioritized remediation roadmap so your IT team tackles the biggest risks first
- Results walkthrough to go over the findings and answer questions after delivery
What a vulnerability assessment costs
Vulnerability assessments start at $2,500. Where yours lands depends on a few factors.
- Whether the assessment is external, internal, or both
- The number of systems and network segments in scope
- The number of locations
Internal assessments usually cost more than external ones because there are more systems to scan and more results to validate.
Vulnerability assessment or penetration test?
| Vulnerability assessment | Penetration test | |
|---|---|---|
| Goal | Find and validate weaknesses across the whole environment | Show how far an attacker could actually get |
| Approach | Breadth-first scanning with non-destructive validation | Hands-on exploitation, chaining weaknesses together |
| Best for | Regular security hygiene and a first look at where you stand | Testing real-world defenses, insurer or customer requirements |
Who it's for
- Small and mid-sized Iowa businesses that haven't had a recent security assessment
- IT teams who want an independent, validated list of what to patch and reconfigure
- Organizations answering cyber insurance or customer security questionnaires that ask about vulnerability scanning
- Businesses planning a penetration test that want to fix the obvious issues first
Assessments are performed by GPEN, GCIH, and GSEC certified consultants. We are independent. We don't manage your IT or sell security products, so we have no reason to downplay what we find.
Vulnerability assessment questions
How much does a vulnerability assessment cost?
Our vulnerability assessments start at $2,500. External and internal assessments are scoped separately, and internal assessments usually cost more because there are more systems to scan and more results to validate. We scope every assessment up front, so you have a quote before any scanning starts.
What is the difference between a vulnerability assessment and a penetration test?
A vulnerability assessment finds and validates weaknesses across your whole environment without exploiting them. A penetration test goes further. It actually exploits weaknesses and chains them together to show how far an attacker could get. A vulnerability assessment is the better choice for broad coverage and regular security hygiene, and it is often the right first step before a penetration test.
How long does a vulnerability assessment take?
For a typical small business scope, active scanning takes two to three business days within a testing window we agree on with you, and the report is typically delivered within a week of scanning.
Will scanning disrupt our network?
We use non-destructive checks, scan during a testing window you approve, and confirm findings with the lightest safe check rather than exploiting them. If you have fragile or business-critical systems, tell us during scoping and we will exclude them or schedule them separately.
What is credentialed scanning, and do we have to give you passwords?
Credentialed scanning means the scanner logs in with an account you create for the assessment, so it can see missing patches and insecure settings inside each system, not just what is visible from the network. It finds far more than an unauthenticated scan. You control the account and can disable it as soon as the assessment is finished.
Do you need to be on site?
Usually not. External assessments are performed from the internet, and internal assessments can be performed remotely over a VPN connection into your network.
How often should we have a vulnerability assessment?
New vulnerabilities are published every week, so a single assessment is a snapshot. Many organizations scan quarterly, and at minimum once a year and after significant changes such as new systems, a new office, or a major upgrade.
Ready to find out where you stand?
Tell us what's prompting the question. We'll come back with a few questions of our own, not a sales pitch.
Find Out Where You Stand