Vulnerability scanning
Automated checks of agreed websites and systems for known weaknesses, helping you prioritise what needs attention.
Explore vulnerability scanningChoose a focused review or combine services around the systems and risks that matter to you.
Automated checks of agreed websites and systems for known weaknesses, helping you prioritise what needs attention.
Explore vulnerability scanningReview laptop and mobile-device protection, including encryption, screen locks, updates and lost-device risks.
Explore device security reviewsReview AWS, Azure or Google Cloud configurations, including access permissions, exposed storage, account protection and logging.
Explore cloud security reviewsIdentify information an attacker can find publicly, such as exposed files, leaked credentials and lookalike domains.
Explore public exposure checksExamine source code for weaknesses such as embedded secrets, unsafe input handling and missing access checks.
Explore code security reviewsA qualified tester attempts to exploit weaknesses in agreed applications, APIs or networks, with written authorisation. Includes a report, fix guidance and a retest of the findings.
For MSPs
Keep the client relationship while Fig provides the specialist testing. We agree scope, permissions, reporting and client communications with your team before the engagement.
Use the Fig platform to manage findings, remediation tasks and evidence alongside your wider client work. Work with us to certify clients when they need a scheme assessment.
Explore the MSP partnershipPractical questions about testing, scope and how we work with your team.
A vulnerability scan checks for known weaknesses using automated tools. A penetration test adds manual investigation and attempts to exploit weaknesses within an agreed scope. They provide different levels of assurance and are not interchangeable.
Yes. MSPs can white-label Fig’s security testing services and retain the client relationship. We agree the testing scope, permissions, reporting format and communication responsibilities before work begins.
We agree the systems, testing depth, dates and written authorisation before testing. Your statement of work records the scope, fixed quote, deliverables and retest arrangements. Whitebox, greybox and blackbox approaches are available, depending on how much access and information you provide.
No. Testing reports on findings within its agreed scope and testing period. It does not guarantee that every weakness has been found, and it is not a substitute for Cyber Essentials, Cyber Essentials Plus or DCC assessment.
Share the systems involved, your objectives and any deadline. We’ll discuss the right scope and provide a quote.