A specialist service from CyPro
Managed vulnerability scanning at a published monthly price
A vulnerability scanning service for UK businesses that pairs continuous, automated scanning with a consultant who reads every result. You get a ranked fix list each month, not a thousand-row export, and the price is on the page before you ever speak to us.
- Monthly per-IP bands, published
- Every finding human-triaged
- PCI, CE Plus and ISO 27001 evidence
- UK consultants throughout
Trusted by
What we run for you
Vulnerability management, delivered as a service
Six ways in, from a monthly scanning retainer to a one-off assessment, each with its scope defined and its price printed before you enquire.
Managed Monthly Scanning
Your estate scanned on schedule, every finding read by a consultant, and a report that tells you the five things to fix first. Per-IP monthly bands, printed on the pricing page.
One-Off Vulnerability Assessment
A scoped assessment at a fixed fee: scan, prioritised findings, a remediation plan and a retest to prove the fixes landed. No day rates, no open-ended scope.
VAPT, Unbundled
Vulnerability assessment and penetration testing sold as what they are: two disciplines with different jobs. We run the assessment leg; CyPro's CREST team delivers the testing.
External and Internal Scanning
Internet-facing assets scanned from the attacker's side of the fence, and internal scanning by agent or appliance for what a foothold would reach.
PCI ASV Scans
The quarterly external scans PCI DSS demands, run through an Approved Scanning Vendor partner and managed end to end: scoping, failures, rescans and attestation evidence.
Human Triage and Fix Guidance
The difference between a scanner and a service: a person removes the false positives, ranks what is left by exploitability and stays with each finding until it closes.
What does a vulnerability scanning service include?
A managed vulnerability scanning service runs scheduled scans of your external and internal systems, verifies and prioritises what the scans find, and reports the results as a ranked fix list with remediation guidance, on a cadence that satisfies PCI DSS, Cyber Essentials Plus and ISO 27001 A.8.8 evidence requirements. Some organisations need a one-off vulnerability assessment first; most need the scanning to simply keep happening, month after month, with a person accountable for what it finds.
Why this service
Continuous, automated scanning with a person in the loop
Prices on the page, not behind a quote
Quote-only consultancies charge upwards of a thousand pounds a day for assessments, and the big scanning platforms hide their fees behind trials. Every one of our figures is printed on the pricing page.
A consultant reads every scan
Raw scanner output is noise with a severity column. Nothing reaches your inbox until a person has removed the false positives and ranked the rest by how exploitable they really are.
Continuous coverage, not annual snapshots
Automated scans run to schedule between reports, so a critical vulnerability published on a Tuesday is in front of a consultant that week, not at the next annual review.
Evidence your auditor can use
PCI DSS quarterly scans, Cyber Essentials Plus readiness, ISO 27001 A.8.8 records and insurer questionnaires all draw from the same dated, triaged reporting trail.
Findings arrive as a fix list
Reports are written for the people doing the patching: what to fix, in what order, with the guidance to do it. Your team keeps ownership of the systems; we keep the list honest.
CyPro's bench behind the service
The consultants triaging your findings sit beside CyPro's CREST penetration testers and incident responders, so when a finding needs more than a patch, the escalation path is in the same building.
Your experts hold
Client outcomes
Results clients put their names to
Before you ask us
Frequently asked questions
What is the difference between a vulnerability scan and a penetration test?
A vulnerability scan is a broad, repeatable sweep that finds known weaknesses across your estate; a penetration test is a targeted manual exercise where a tester attempts to exploit them. You need scanning continuously and testing periodically, and they answer different questions.
Our VAPT page explains how the two disciplines pair up, and CyPro's CREST-accredited team delivers the testing side.
How often should we run a vulnerability scan?
Monthly is the sensible floor for most organisations, weekly where change is frequent, and continuous where exposure is high. Compliance sets minimums, not good practice: PCI DSS requires quarterly external ASV scans and quarterly internal scans, Cyber Essentials Plus involves scans of in-scope systems at assessment, and ISO 27001 auditors expect a defined, evidenced cadence under control A.8.8.
New critical vulnerabilities do not wait for your next quarter, which is why our managed bands scan monthly at minimum and weekly on the Professional band.
What does vulnerability scanning cost?
Every figure is printed on the pricing page: monthly per-IP bands for the managed service, a fixed fee for a one-off vulnerability assessment, and a PCI ASV add-on. Most of this market is quote-only, with traditional assessments commonly charged at more than a thousand pounds a day, so we put our numbers in public and let you compare.
What happens after you find vulnerabilities?
A consultant reads the raw results before you ever see them: false positives are removed, findings are prioritised by real-world exploitability rather than raw CVSS score, and what reaches you is a ranked fix list with clear remediation guidance for your IT team or provider.
We then track each finding through to your next scan, so the report shows what was fixed, what is outstanding and what is new.
See what your attackers see
Find out what a scan of your estate would actually surface
The scoping call is free, lasts 45 minutes and is taken by a consultant, not a salesperson. It covers what you have exposed, the cadence your compliance obligations demand, and exactly what the service would cost per month.