Skip to content
For UK businesses and MSPs

Vulnerability scanning services
Find known weaknesses before an attacker does.

Fig Group scans websites and systems for known security weaknesses. Receive findings and recommended next steps to help your IT team prioritise remediation. The engagement defines target coverage, reporting detail, validation and follow-up scanning.

At a glance

Your engagement at a glance

What you receive

Findings on known weaknesses and recommended next steps for remediation.

Your team’s part

Your IT team investigates applicability, implements fixes and records exceptions.

Follow-up arrangements

Follow-up scanning and manual validation are specified in the quotation.

A clearly defined scope. A scan reports detectable, known weaknesses in the agreed targets during the assessment window. It does not guarantee that every issue has been found, and a report with no findings is limited to the checks and scope used.

For a repeatable check of known weaknesses on nominated systems. For public information about your brand, choose an OSINT review. Explore public exposure checks.

Start with a scope discussion

We’ll agree the targets, exclusions, access and written authorisation before any scanning begins.

Request a vulnerability scan
Coverage

What can a vulnerability scan tell you?

A vulnerability scan checks for known weaknesses across an agreed set of assets. It gives your team a starting point for reducing exposure and directing security effort where it matters. We agree the scope and reporting requirements before work begins.

Where known weaknesses may exist

Depending on the target and scan access, checks can identify signs of missing security updates, vulnerable software versions and detectable configuration issues. Findings should be reviewed before making changes.

What is exposed to the internet

External scanning helps you understand the services visible on your agreed public targets and the known weaknesses detectable from outside your network. This can highlight services that need patching, restricting or further investigation.

Where deeper testing is needed

A scan can flag areas for investigation, but it cannot assess every business logic flaw or attack path. Where you need more detailed assurance, discuss penetration testing, a code review or a cloud security review with Fig.

Assessment detail

Scan location and login access answer different questions

External and internal describe where a scan runs from. Authenticated and unauthenticated describe the access it uses. An internal scan is not automatically authenticated, and a website scan may use a login even when it runs from outside your network.

Two independent decisions for vulnerability scan coverage
DecisionOptionWhat changes
LocationExternalExamines the authorised services reachable from outside your network. It helps establish what is exposed to an internet-based scan.
LocationInternalExamines targets reachable from a position inside your environment. Connectivity and network boundaries determine what can be reached.
AccessUnauthenticatedUses no supplied login. Checks are limited to what the target exposes to that connection.
AccessAuthenticatedUses authorised credentials to inspect additional system information or application functions. Coverage depends on the permissions and checks available.

A scanner alert is a starting point for investigation. Version detection, configuration evidence and asset context help establish whether a finding applies. Your quotation should state the level of manual validation included, who investigates disputed findings and whether follow-up scanning is included.

Security benefits

The security benefits of vulnerability scanning

Regular scanning helps turn security maintenance into a repeatable process. Its value comes from acting on the findings and checking the results.

Find issues before they are exploited

Identify detectable weaknesses so your team can address them earlier. Fixing exposed vulnerabilities can reduce opportunities for unauthorised access, data compromise and service disruption.

Focus remediation on the right assets

Consider the affected system, its exposure and the data or business service it supports. This helps your team prioritise urgent fixes and plan lower-priority work with a clear rationale.

Check progress as your environment changes

Follow-up scans can show whether reported issues remain detectable after remediation. Repeated checks help identify new findings after software updates, infrastructure changes or the publication of new vulnerabilities.

Commercial value

The commercial benefits for your business

A useful scan connects technical findings to business decisions: what needs investment, who needs to act and what evidence you can share.

Use IT time and budget more effectively

A prioritised action list gives your team a basis for scheduling updates and planning improvements. It can also help explain why ageing systems need replacement or additional protection.

Support customer and supplier assurance

A scoped report and evidence of remediation can help answer security questionnaires and due-diligence requests. Share an appropriate summary with customers while protecting sensitive technical details.

Reduce avoidable operational disruption

Addressing weaknesses proactively can reduce the likelihood of security incidents that interrupt services and consume staff time. The benefit depends on remediation; a scan alone does not prevent an incident.

Build a repeatable service for MSP clients

Offer scanning under your own brand with Fig’s white-label security services. Use findings to structure client conversations, agree remediation work and plan ongoing reviews while retaining the client relationship.

How it works

Our vulnerability scanning process

  1. Agree the scope and permissions

    Tell us which websites, IP addresses and systems you want assessed, why you need the scan and any reporting deadline. We agree the targets, exclusions, access requirements, scan window and written authorisation before testing begins.

  2. Scan the agreed systems

    Automated tools check the authorised targets for known vulnerabilities and detectable configuration weaknesses. The coverage depends on the systems, access and scan settings agreed for your engagement.

  3. Understand and prioritise the findings

    Use the findings to identify affected assets, understand the potential impact and decide which issues need attention first. Consider exposure and business importance alongside technical severity; a severity score alone does not describe your business risk.

  4. Plan and implement remediation

    Turn the findings into an action list for your IT team or MSP. Actions may include applying updates, changing configurations, restricting access or replacing unsupported software. Assign owners and target dates so the report leads to action.

  5. Verify fixes and plan the next scan

    Agree any follow-up scan or retest as part of the engagement. Use the results to check whether reported issues remain detectable and decide when to scan again as systems and threats change.

Colleagues discussing a review in a meeting

Scanning is authorised in writing before testing begins, and stays within the agreed targets and windows.

Compare approaches

Which type of vulnerability assessment do you need?

Related services answer different questions. Confirm which scope you are buying before you compare quotes.

Compare the purpose and scope of related approaches
ApproachWhat it tells youScope to confirm
External vulnerability scanningKnown weaknesses detectable on agreed internet-facing targets.Covers the nominated internet-facing targets. Logged-in workflows are included only when suitable credentials and checks are part of the scan.
Internal vulnerability scanningChecks targets reachable from inside the network to identify known weaknesses on internal systems.Network position and login access are separate decisions. Specify whether the checks will use credentials.
Penetration testingManual investigation of how weaknesses may be exploited in agreed systems.A separate testing scope, useful when you need deeper investigation of behaviour and impact.

Illustrative example, not a client case study

An exposed service with a reported software vulnerability

How to read a finding: evidence, decision and next action
Scope
Internet-facing service on portal.example; unauthenticated checks.
Observation
A scanner identifies a software version associated with a published weakness. The detection and scan date belong in the evidence record.
Validation
The owner checks the installed build and configuration against the advisory. Banner detection alone may be wrong. Record applicable, not applicable or unresolved with the supporting reason.
Priority and owner
Consider external reachability, affected data and service importance alongside technical severity. Assign the application owner to investigate and plan the fix.
Action and verification
Apply a suitable update or restriction, then record whether a follow-up scan still detects the issue. Retain any accepted exception and its review date.

This is a teaching example of a finding record, not an extract from a customer report or a promise of a particular report template.

Cost and preparation

What affects the scope and cost?

The quote depends on the number and type of targets, external or internal access, authenticated checks, scan frequency, reporting detail and follow-up scanning. Agree whether the price covers a single assessment or a recurring schedule.

What to prepare for your enquiry

Provide your target list, asset owners, hosting arrangements and testing restrictions. Explain which systems support critical services and whether you need technical findings, a management summary or both. Share credentials only through an agreed secure channel.

Plan the engagement around your deadline

Allow for access preparation, the scan window, report delivery and your team’s remediation work. Confirm the delivery format, dates and any follow-up scanning in your quote so each team knows when its input is needed.

A person planning an engagement with a notebook and laptop
Report and outcomes

From scan results to a remediation plan

Use the report to turn detected weaknesses into owned remediation work. Keep the tested targets, supporting evidence and remaining actions together so technical staff and decision-makers can interpret the results.

A clear record of what was tested

Document the targets, assessment dates, access level and exclusions so readers understand the coverage and limitations of the results.

Findings that support action

Use affected assets, severity information, available technical evidence and recommended remediation to create work your IT team or MSP can assign and track.

A view of the next steps

Record remediation decisions, owners and target dates. Where follow-up scanning is agreed, retain the results alongside the original findings to show what has changed and what remains open.

For ongoing oversight, explore how the Fig platform helps manage vulnerability findings, remediation and evidence.

Explore vulnerability management in the Fig platform
Questions

Vulnerability scanning questions

Practical answers about cost, coverage, frequency and what happens after a scan.

Compare all six security services
What is vulnerability scanning?

Vulnerability scanning uses automated tools to identify known security weaknesses in agreed systems, networks or websites. It helps you understand what may need fixing, but coverage depends on the scope, access and checks used. Findings need to be assessed in the context of your organisation.

Link to this answer
Is vulnerability scanning the same as vulnerability management?

No. Scanning identifies potential weaknesses. Vulnerability management is the wider process of assessing findings, assigning fixes, tracking exceptions and checking remediation. Fig provides a scanning service and a separate platform capability for managing findings and evidence.

Link to this answer
What is an authenticated vulnerability scan?

An authenticated scan uses authorised credentials to inspect information that an unauthenticated scan may not see, such as installed software or local configuration. It requires suitable permissions and does not mean every part of the system has been assessed. Agree its inclusion before testing.

Link to this answer
What is the difference between a vulnerability scan and a penetration test?

A scan provides automated checks for known weaknesses. A penetration test adds manual investigation and authorised attempts to exploit weaknesses, including issues that automated checks may miss. Choose the testing depth based on your systems, risks and assurance requirements.

Link to this answer
What does a vulnerability scan cost?

Fig provides a quote based on the number and type of targets, access requirements, scan frequency, reporting needs and any follow-up testing. Share your scope and deadline so we can agree the work and price before testing starts.

Link to this answer
How often should we scan for vulnerabilities?

Set a schedule around the importance and exposure of your systems, how often they change and your customer requirements. Repeat scans after significant changes or remediation where appropriate. A single scan provides a view of the tested systems during that assessment; new weaknesses can emerge afterwards.

Link to this answer
Will a vulnerability scan disrupt our systems?

Scans generate traffic and can affect sensitive or older systems. Tell us about critical services, hosting restrictions and operational constraints during scoping. We agree timing, exclusions and an escalation contact before testing, so the approach reflects your environment.

Link to this answer
Can Fig scan internal systems as well as public websites?

Tell us which internal and internet-facing assets you want included. Internal scanning needs a suitable connection to the nominated targets. Authentication is a separate choice: internal and external scans can use credentials where the selected checks support them. The quotation identifies the location, access and coverage.

Link to this answer
Can MSPs offer Fig vulnerability scanning under their own brand?

Yes. MSPs can white-label Fig security testing services and retain the client relationship. We agree scope, permissions, reporting format and communication responsibilities before the engagement.

Link to this answer
Does a vulnerability scan certify that we are secure?

No. A scan does not guarantee that every weakness has been found or provide certification. It can inform remediation and support assurance discussions, but any certification requires its own assessment. A report with no detected findings is limited to the checks and scope used.

Link to this answer
Your next step

Need a different depth of review?

Scanning, manual testing and configuration reviews answer different questions. Choose the service around the systems and assurance you need.

Specialist testing

Penetration testing

Investigate exploitable weaknesses within an authorised scope.

Explore

Configuration review

Cloud security reviews

Examine access, storage and logging configuration in scoped cloud accounts.

Explore

Source review

Code security reviews

Understand weaknesses in source code before they reach production.

Explore

Software

The Fig platform

Manage vulnerability findings, remediation and supporting evidence.

Explore
Further reading

Further technical guidance

Independent sources that explain the methods and controls behind the review.

Accountability

Working with Fig

Work with Fig directly or through your MSP. Your proposal identifies the contracting entity, assessment scope and delivery responsibilities.

The companies

Meet the companies behind Fig

See the entities, licences and people behind the platform and our assessments.

Explore

MSP partners

Security services for MSP partners

Offer these services under your own brand and retain the client relationship.

Explore

Published evidence

Company details and published evidence

Verify our company details, licences and the claims we make in public.

Explore

Know what needs fixing. Plan what happens next.

Tell us which websites or systems you want scanned, your objectives and any deadline. We’ll discuss the scope, reporting and follow-up requirements and provide a quote.

Request a vulnerability scan