Asked and answered

Frequently asked questions

The questions UK teams bring to us before committing to a scanning service, answered plainly by the people who then run it. Whatever is not covered here gets a straight answer on the scoping call.

Frequently asked vulnerability scanning questions
What is the difference between a vulnerability scan and a penetration test?

A vulnerability scan is a broad, repeatable sweep that finds known weaknesses across your estate; a penetration test is a targeted manual exercise where a tester attempts to exploit them. You need scanning continuously and testing periodically, and they answer different questions.

Our VAPT page explains how the two disciplines pair up, and CyPro's CREST-accredited team delivers the testing side.

How scanning and CREST penetration testing pair up

How often should we run a vulnerability scan?

Monthly is the sensible floor for most organisations, weekly where change is frequent, and continuous where exposure is high. Compliance sets minimums, not good practice: PCI DSS requires quarterly external ASV scans and quarterly internal scans, Cyber Essentials Plus involves scans of in-scope systems at assessment, and ISO 27001 auditors expect a defined, evidenced cadence under control A.8.8.

New critical vulnerabilities do not wait for your next quarter, which is why our managed bands run monthly at minimum and weekly on the Managed band.

What each band includes

What does vulnerability scanning cost?

Every figure is printed on the pricing page: monthly fees for the three managed bands, Essential, Managed and Complex, and the PCI ASV add-on. You hold the licence for your scanning tool, so our fee covers the management around it: running or ingesting the scans, our proprietary risk analysis and driving the fixes. Most of this market is quote-only, with traditional assessments commonly charged at more than a thousand pounds a day, so we put our numbers in public and let you compare.

See the published prices

What happens after you find vulnerabilities?

A consultant reads the raw results before you ever see them: false positives are removed, then every finding goes through our proprietary risk analysis, which weighs actual exposure and the business value of the affected system rather than raw CVSS score alone. What reaches you is a ranked fix list with clear remediation guidance for your IT team or provider.

We then track each finding through to your next scan, so the report shows what was fixed, what is outstanding and what is new.

The full process, step by step

Do we need internal scanning, external scanning, or both?

External scanning covers what an attacker on the internet can reach and is the minimum every organisation should run. Internal scanning shows what an intruder or malicious insider could reach once inside, and matters as soon as you hold sensitive data on internal systems or face PCI DSS internal scan requirements.

Our Essential band covers the external view only; the Managed band adds internal coverage through your scanner's agents or an appliance.

External and internal scanning compared

How long does a vulnerability scan take?

A typical external scan of a small estate completes in a few hours; larger estates and authenticated internal scans can run for a day or more. Duration depends on the number of live hosts, the depth of checks and how the scan is throttled.

For the managed service the practical answer is that scans run on schedule in the background on your own tooling and you receive the triaged report on a fixed day, so scan duration never becomes your problem.

Will scanning disrupt our systems?

Modern scanning is designed to be safe on production systems, and we tune scan intensity, timing and exclusions around your environment during onboarding. Fragile legacy systems can be scanned in maintenance windows or excluded with a documented rationale.

Disruption is rare and almost always traces to configurations we identify and work around at setup.

Is vulnerability scanning required for PCI DSS?

Yes. PCI DSS v4 requires quarterly external scans by a PCI SSC Approved Scanning Vendor with passing results (Requirement 11.3.2) and quarterly internal vulnerability scans (Requirement 11.3.1), plus rescans after failures and after significant changes.

We manage the whole cycle, with the ASV scans performed through a PCI-SSC Approved Scanning Vendor partner.

Quarterly ASV scans, managed end to end

Is vulnerability scanning required for Cyber Essentials Plus?

Cyber Essentials Plus is an audited certification and your assessor will run vulnerability scans of in-scope systems as part of it. Regular scanning between assessments is how you make sure the audit holds no surprises: it keeps patching honest all year rather than in the month before renewal.

Our sister service explains the scheme itself; we keep you pass-ready in between.

Cyber Essentials Plus, explained by CyPro

Is vulnerability scanning required for ISO 27001?

ISO 27001:2022 control A.8.8, management of technical vulnerabilities, requires you to identify vulnerabilities, assess exposure and act on it. The standard does not mandate a specific tool or frequency, but in practice auditors expect a defined scanning cadence, records of findings and evidence of treatment.

A monthly triaged report with tracked remediation is exactly that evidence trail.

Do cyber insurers require vulnerability scanning?

Increasingly, yes. Proposal forms now routinely ask how you identify and remediate vulnerabilities and how quickly critical patches are applied, and weak answers show up in premiums, excesses or exclusions. A managed scanning service gives you a documented, dated answer rather than a hopeful one.

Do you scan with agents or agentless?

Both approaches have a place, and the choice belongs to your scanner deployment. External scanning is agentless by nature. For internal coverage your scanner, whether Nessus, Tenable, Qualys or another, can run either lightweight agents on endpoints and servers or a network appliance. We advise on the right mix at onboarding based on your infrastructure, remote working profile and change appetite, then configure the deployment on your tooling or guide your team through it.

Are the scans authenticated or unauthenticated?

External scans are unauthenticated, showing what an outside attacker sees. Internal scans are usually authenticated: your scanner logs in with read-only credentials and can verify patch levels and configurations directly, which produces far fewer false positives and much more accurate findings. We configure authenticated internal scanning on your tooling wherever the estate allows it, or advise your team on the setup where you prefer to run the scans yourselves.

Can you fix what you find, as well as finding it?

Every report comes with specific remediation guidance, and on the Managed band a consultant walks your team through the fixes on a call. The hands-on remediation itself sits with your IT team or provider, because they own the systems.

Where a finding needs deeper security work, penetration testing or incident response, CyPro's wider team takes it on directly.

CyPro's full service line

Rocket above the Managed Vulnerability Scanning call to action

A question we missed?

Bring it to the scoping call

That is what the scoping call is for: 45 minutes, free, on what you expose, which compliance clocks are ticking and which band fits, whether or not you go on to buy anything.