Securious scanning services – Frequently Asked Questions

If you’re considering vulnerability scanning, you’ll quickly discover there are several different services available, each designed for a different purpose.

You may need an ASV scan to meet PCI DSS requirements. You may be looking for regular internal or external vulnerability scanning to improve your security posture. Or you may be exploring Cyber Essentials Scanning to help maintain visibility between annual assessments.

While the objectives of these services are different, many of the questions organisations ask are the same:

  • What systems are included?
  • How is the scanning performed?
  • Do we need to install anything?
  • What will we need to do?
  • What will we receive afterwards?

To help answer these questions, we’ve compiled the most common questions we receive about each of our scanning services, along with straightforward explanations of how they work and what to expect.

PCI ASV Scanning

What is an ASV scan?

An ASV (Approved Scanning Vendor) scan is a specific type of external vulnerability scan required for many organisations that must comply with PCI DSS. It assesses internet-facing systems for known vulnerabilities that could put cardholder data at risk.

Which systems are included?

ASV scans typically cover internet-facing systems that fall within PCI DSS scope. This may include websites, payment gateways, public IP addresses, firewalls and other externally accessible services.

How is the scan performed?

The scan is performed externally, from outside your network, in a similar way to how an attacker would view your systems from the internet.

Do I need to install any software?

No. ASV scans do not typically require software or agents to be installed on your systems.

What do we need to provide?

You will need to provide details of the IP addresses, domains or internet-facing systems that require scanning.

How often are scans required?

PCI DSS generally requires ASV scans to be completed quarterly, as well as after significant changes to in-scope systems.

What happens if vulnerabilities are identified?

A remediation report is supplied for you to fix any of the initial findings. The scan will not be moved to an attested scan/report until any findings have been remediated or reviewed.

What does the report contain?

The report details all of the targets scanned, and any findings discovered during the scan. Both a technical report and executive report are provided which can then be used for ongoing compliance.

Who is this service best suited for?

Organisations that process, store or transmit payment card data and need to meet PCI DSS requirements.

Internal Vulnerability Scanning

What is internal vulnerability scanning?

Internal vulnerability scanning identifies known vulnerabilities and security weaknesses within your internal environment before they can be exploited.

Which systems are included?

Internal scans can cover endpoints, servers, network infrastructure and other internal systems within the agreed scope.

How is the scan performed?

Scanning is performed from within your environment to identify vulnerabilities that would typically only be visible to someone with internal access.

Do I need to install any software?

This will depend on the scanning approach used. Some deployments may require agents or authenticated access to systems. Technical requirements should be confirmed during setup.

How long does setup take?

Setup requirements vary depending on the size and complexity of the environment being scanned.

Will the scan impact performance?

Vulnerability scanning is designed to minimise disruption, although some systems may experience a small increase in activity while scans are running.

What do we need to do?

You may need to assist with access, credentials, deployment of scanning components and confirmation of the systems that should be included within scope.

What happens after the scan?

You will receive a report highlighting identified vulnerabilities and recommendations for remediation.

What does the report contain?

The report typically includes affected assets, vulnerability details, severity ratings and recommended remediation actions.

Who is this service best suited for?

Organisations that want ongoing visibility of vulnerabilities across their internal infrastructure.

External Vulnerability Scanning

What is external vulnerability scanning?

External vulnerability scanning identifies vulnerabilities that are visible from the internet and could potentially be discovered by attackers.

Which systems are included?

Websites, public IP addresses, externally accessible servers, cloud-hosted services and other internet-facing systems can typically be included.

How is the scan performed?

The scan is conducted externally, assessing your systems from the perspective of someone outside your organisation.

Is this the same as a penetration test?

No. Vulnerability scanning is an automated process designed to identify known vulnerabilities. A penetration test involves manual testing by security professionals to assess how vulnerabilities could be exploited.

Do I need to install any software?

No. External vulnerability scanning does not typically require software or agents to be installed.

What do we need to provide?

You will need to provide the domains, IP addresses or internet-facing systems that you would like scanned.

Will the scan disrupt services?

External vulnerability scanning is designed to be non-disruptive and should not impact normal operations.

What happens after the scan?

You will receive a report detailing any vulnerabilities identified and recommended remediation actions.

What does the report contain?

The report includes identified vulnerabilities, severity ratings, affected systems and remediation guidance.

Who is this service best suited for?

Organisations that want visibility of vulnerabilities that could be identified by external attackers.

Cyber Essentials Quarterly Scanning

What is Cyber Essentials Quarterly Scanning?

Cyber Essentials Quarterly Scanning is an ongoing vulnerability monitoring service designed to help organisations maintain visibility of vulnerabilities throughout the year and support Cyber Essentials Plus readiness.

Which systems are included?

Any devices and systems that fall within your Cyber Essentials scope can be included, subject to the technical requirements of the scanning platform.

How are remote or home-working devices handled?

Remote devices can typically be included provided they have the required scanning agent installed.

How is the scan performed?

A lightweight agent is installed on in-scope devices. This agent regularly checks for vulnerabilities and reports findings back to the scanning platform.

Do I need to install any software?

Yes. A Qualys agent is deployed to the devices that you want included within the service.

Who installs the agent?

Your IT team is responsible for deploying the agent. Securious will provide guidance and support during setup.

How long does setup take?

Provisioning is typically straightforward. Deployment time depends on the number of devices being covered and the tools available for software deployment.

How much ongoing maintenance is required?

Very little. The agent is updated automatically, and ongoing administration is minimal. New devices simply need the agent deployed if they are to be included within scope.

What do we need to do?

Deploy the agent to in-scope devices, review reports and remediate identified vulnerabilities.

What does the report contain?

The report provides visibility of vulnerabilities across in-scope devices, including severity information and remediation recommendations.

How often will we receive reports?

Reports are provided quarterly.

Who is this service best suited for?

Organisations that want to maintain visibility of vulnerabilities throughout the year and reduce the risk of unexpected findings during Cyber Essentials Plus assessments.