Services / What Is a Vulnerability Assessment?
Definition

What Is a Vulnerability Assessment?

A clear, plain-language answer for anyone scoping their first assessment, briefing a non-technical stakeholder, or just trying to understand what they're actually paying for.

Key Takeaways
  • A vulnerability assessment finds and prioritizes weaknesses; it doesn't actively exploit them the way a penetration test does.
  • Good assessments cover configuration and access issues, not just missing patches.
  • It's a recurring practice, not a one-time project — environments change constantly.
  • It's one input into a broader security program, not a replacement for having one.

The Short Answer

A vulnerability assessment identifies your assets, scans and reviews them for known weaknesses, and produces a risk-rated report so you know what to fix first. It's a structured way of answering the question every business eventually has to ask: where are we actually exposed?

The output isn't just a list of problems — a good assessment tells you which problems matter most, given your specific environment and what an attacker could realistically do with each weakness.

What It Finds

Assessments typically surface a mix of technical and configuration issues. Some are obvious once flagged — unpatched software with a known vulnerability — while others are subtler, like an access control that's technically working as configured but was configured too permissively in the first place.

  • Unpatched software with known vulnerabilities
  • Misconfigured systems and access controls
  • Weak or default credentials
  • Exposed services that shouldn't be internet-facing
  • Overly broad permissions on cloud storage or shared resources

What It Doesn't Do

It doesn't actively exploit those weaknesses to prove they're dangerous — that's the job of a penetration test. An assessment tells you what could go wrong; a pentest shows you what actually would go wrong, and how far an attacker could get once they were in.

It also isn't a substitute for ongoing monitoring. An assessment is a snapshot in time; your environment keeps changing after the report is delivered, which is why a recurring cadence matters more than a single one-off engagement.

Questions
How often should we run one?

Quarterly or annually is common for most businesses, with additional assessments after major infrastructure changes, new product launches, or significant staff turnover in IT.

Is this the same as a penetration test?

No. See our comparison page for the difference — they're complementary, not interchangeable, and most mature security programs use both.

Do small businesses really need this?

Yes. Smaller businesses are often targeted precisely because attackers assume less mature defenses — an assessment scoped to your actual size and budget is still valuable, even if the scope is smaller than an enterprise engagement.

Related Reading

Have a Question We Didn’t Cover?

Email Our Team