What you receive
Findings on known weaknesses and recommended next steps for remediation.
Findings on known weaknesses and recommended next steps for remediation.
Your IT team investigates applicability, implements fixes and records exceptions.
Follow-up scanning and manual validation are specified in the quotation.
A clearly defined scope. A scan reports detectable, known weaknesses in the agreed targets during the assessment window. It does not guarantee that every issue has been found, and a report with no findings is limited to the checks and scope used.
For a repeatable check of known weaknesses on nominated systems. For public information about your brand, choose an OSINT review. Explore public exposure checks.
We’ll agree the targets, exclusions, access and written authorisation before any scanning begins.
A vulnerability scan checks for known weaknesses across an agreed set of assets. It gives your team a starting point for reducing exposure and directing security effort where it matters. We agree the scope and reporting requirements before work begins.
Depending on the target and scan access, checks can identify signs of missing security updates, vulnerable software versions and detectable configuration issues. Findings should be reviewed before making changes.
External scanning helps you understand the services visible on your agreed public targets and the known weaknesses detectable from outside your network. This can highlight services that need patching, restricting or further investigation.
A scan can flag areas for investigation, but it cannot assess every business logic flaw or attack path. Where you need more detailed assurance, discuss penetration testing, a code review or a cloud security review with Fig.
External and internal describe where a scan runs from. Authenticated and unauthenticated describe the access it uses. An internal scan is not automatically authenticated, and a website scan may use a login even when it runs from outside your network.
| Decision | Option | What changes |
|---|---|---|
| Location | External | Examines the authorised services reachable from outside your network. It helps establish what is exposed to an internet-based scan. |
| Location | Internal | Examines targets reachable from a position inside your environment. Connectivity and network boundaries determine what can be reached. |
| Access | Unauthenticated | Uses no supplied login. Checks are limited to what the target exposes to that connection. |
| Access | Authenticated | Uses authorised credentials to inspect additional system information or application functions. Coverage depends on the permissions and checks available. |
A scanner alert is a starting point for investigation. Version detection, configuration evidence and asset context help establish whether a finding applies. Your quotation should state the level of manual validation included, who investigates disputed findings and whether follow-up scanning is included.
Regular scanning helps turn security maintenance into a repeatable process. Its value comes from acting on the findings and checking the results.
Identify detectable weaknesses so your team can address them earlier. Fixing exposed vulnerabilities can reduce opportunities for unauthorised access, data compromise and service disruption.
Consider the affected system, its exposure and the data or business service it supports. This helps your team prioritise urgent fixes and plan lower-priority work with a clear rationale.
Follow-up scans can show whether reported issues remain detectable after remediation. Repeated checks help identify new findings after software updates, infrastructure changes or the publication of new vulnerabilities.
A useful scan connects technical findings to business decisions: what needs investment, who needs to act and what evidence you can share.
A prioritised action list gives your team a basis for scheduling updates and planning improvements. It can also help explain why ageing systems need replacement or additional protection.
A scoped report and evidence of remediation can help answer security questionnaires and due-diligence requests. Share an appropriate summary with customers while protecting sensitive technical details.
Addressing weaknesses proactively can reduce the likelihood of security incidents that interrupt services and consume staff time. The benefit depends on remediation; a scan alone does not prevent an incident.
Offer scanning under your own brand with Fig’s white-label security services. Use findings to structure client conversations, agree remediation work and plan ongoing reviews while retaining the client relationship.
Tell us which websites, IP addresses and systems you want assessed, why you need the scan and any reporting deadline. We agree the targets, exclusions, access requirements, scan window and written authorisation before testing begins.
Automated tools check the authorised targets for known vulnerabilities and detectable configuration weaknesses. The coverage depends on the systems, access and scan settings agreed for your engagement.
Use the findings to identify affected assets, understand the potential impact and decide which issues need attention first. Consider exposure and business importance alongside technical severity; a severity score alone does not describe your business risk.
Turn the findings into an action list for your IT team or MSP. Actions may include applying updates, changing configurations, restricting access or replacing unsupported software. Assign owners and target dates so the report leads to action.
Agree any follow-up scan or retest as part of the engagement. Use the results to check whether reported issues remain detectable and decide when to scan again as systems and threats change.

Scanning is authorised in writing before testing begins, and stays within the agreed targets and windows.
Related services answer different questions. Confirm which scope you are buying before you compare quotes.
| Approach | What it tells you | Scope to confirm |
|---|---|---|
| External vulnerability scanning | Known weaknesses detectable on agreed internet-facing targets. | Covers the nominated internet-facing targets. Logged-in workflows are included only when suitable credentials and checks are part of the scan. |
| Internal vulnerability scanning | Checks targets reachable from inside the network to identify known weaknesses on internal systems. | Network position and login access are separate decisions. Specify whether the checks will use credentials. |
| Penetration testing | Manual investigation of how weaknesses may be exploited in agreed systems. | A separate testing scope, useful when you need deeper investigation of behaviour and impact. |
Illustrative example, not a client case study
This is a teaching example of a finding record, not an extract from a customer report or a promise of a particular report template.
The quote depends on the number and type of targets, external or internal access, authenticated checks, scan frequency, reporting detail and follow-up scanning. Agree whether the price covers a single assessment or a recurring schedule.
Provide your target list, asset owners, hosting arrangements and testing restrictions. Explain which systems support critical services and whether you need technical findings, a management summary or both. Share credentials only through an agreed secure channel.
Allow for access preparation, the scan window, report delivery and your team’s remediation work. Confirm the delivery format, dates and any follow-up scanning in your quote so each team knows when its input is needed.

Use the report to turn detected weaknesses into owned remediation work. Keep the tested targets, supporting evidence and remaining actions together so technical staff and decision-makers can interpret the results.
Document the targets, assessment dates, access level and exclusions so readers understand the coverage and limitations of the results.
Use affected assets, severity information, available technical evidence and recommended remediation to create work your IT team or MSP can assign and track.
Record remediation decisions, owners and target dates. Where follow-up scanning is agreed, retain the results alongside the original findings to show what has changed and what remains open.
For ongoing oversight, explore how the Fig platform helps manage vulnerability findings, remediation and evidence.
Explore vulnerability management in the Fig platformPractical answers about cost, coverage, frequency and what happens after a scan.
Compare all six security servicesVulnerability scanning uses automated tools to identify known security weaknesses in agreed systems, networks or websites. It helps you understand what may need fixing, but coverage depends on the scope, access and checks used. Findings need to be assessed in the context of your organisation.
Link to this answerNo. Scanning identifies potential weaknesses. Vulnerability management is the wider process of assessing findings, assigning fixes, tracking exceptions and checking remediation. Fig provides a scanning service and a separate platform capability for managing findings and evidence.
Link to this answerAn authenticated scan uses authorised credentials to inspect information that an unauthenticated scan may not see, such as installed software or local configuration. It requires suitable permissions and does not mean every part of the system has been assessed. Agree its inclusion before testing.
Link to this answerA scan provides automated checks for known weaknesses. A penetration test adds manual investigation and authorised attempts to exploit weaknesses, including issues that automated checks may miss. Choose the testing depth based on your systems, risks and assurance requirements.
Link to this answerFig provides a quote based on the number and type of targets, access requirements, scan frequency, reporting needs and any follow-up testing. Share your scope and deadline so we can agree the work and price before testing starts.
Link to this answerSet a schedule around the importance and exposure of your systems, how often they change and your customer requirements. Repeat scans after significant changes or remediation where appropriate. A single scan provides a view of the tested systems during that assessment; new weaknesses can emerge afterwards.
Link to this answerScans generate traffic and can affect sensitive or older systems. Tell us about critical services, hosting restrictions and operational constraints during scoping. We agree timing, exclusions and an escalation contact before testing, so the approach reflects your environment.
Link to this answerTell us which internal and internet-facing assets you want included. Internal scanning needs a suitable connection to the nominated targets. Authentication is a separate choice: internal and external scans can use credentials where the selected checks support them. The quotation identifies the location, access and coverage.
Link to this answerYes. MSPs can white-label Fig security testing services and retain the client relationship. We agree scope, permissions, reporting format and communication responsibilities before the engagement.
Link to this answerNo. A scan does not guarantee that every weakness has been found or provide certification. It can inform remediation and support assurance discussions, but any certification requires its own assessment. A report with no detected findings is limited to the checks and scope used.
Link to this answerScanning, manual testing and configuration reviews answer different questions. Choose the service around the systems and assurance you need.
Specialist testing
Investigate exploitable weaknesses within an authorised scope.
ExploreConfiguration review
Examine access, storage and logging configuration in scoped cloud accounts.
ExploreSource review
Understand weaknesses in source code before they reach production.
ExploreSoftware
Manage vulnerability findings, remediation and supporting evidence.
ExploreIndependent sources that explain the methods and controls behind the review.
Independent guidance
Guidance on selecting scanning approaches and understanding access and coverage.
Work with Fig directly or through your MSP. Your proposal identifies the contracting entity, assessment scope and delivery responsibilities.
The companies
See the entities, licences and people behind the platform and our assessments.
ExploreMSP partners
Offer these services under your own brand and retain the client relationship.
ExplorePublished evidence
Verify our company details, licences and the claims we make in public.
ExploreContent updated .
Tell us which websites or systems you want scanned, your objectives and any deadline. We’ll discuss the scope, reporting and follow-up requirements and provide a quote.