EN

Why continuous vulnerability management now belongs in every business

New vulnerabilities are published every week in software that businesses use every day: firewalls, VPN gateways, web applications, mail servers and cloud services. Attackers look specifically for systems that have not been updated yet. If you do not know your own weaknesses, you often find out when it is too late.

The veyrisk console: findings sorted by risk, actively exploited vulnerabilities flagged
01

The problem: the picture changes every week

In calendar week 38 alone, our sources recorded 108 new security advisories, 26 of them critical. That is from our weekly report, which summarizes advisories from agencies such as CERT-Bund and the German BSI. A penetration test once a year shows the state of one day. Anything published afterwards, or introduced by a new configuration, stays undetected until the next test.

On top of that, many systems are simply forgotten: an old test environment, an unused subdomain, a Microsoft 365 account without multi-factor sign-in. Attackers like exactly these places, because nobody is looking.

02

Not just a problem for large companies

Automated attacks do not care about company size. They scan the whole internet for known vulnerabilities and strike wherever they find one. Small and mid-sized businesses often have no security team of their own that follows new advisories and checks whether their systems are affected.

Pressure is also growing from outside: customers, insurers and auditors increasingly ask for evidence. ISO 27001 and NIS2 require a structured vulnerability management process, and large customers pass these requirements on to their suppliers.

03

What continuous vulnerability management does

  • Check regularly instead of once a year: servers, web applications, cloud accounts and Microsoft 365 are scanned on a fixed schedule.
  • Sort by risk: not every finding is equally urgent. Actively exploited vulnerabilities and critical findings come first.
  • Track remediation: every finding has a history, from new to fixed to reopened. Follow-up scans confirm that a gap is really closed.
  • Provide evidence: reports show management, customers and auditors that vulnerabilities are handled systematically.
04

Vulnerability scan or penetration test?

The two terms are often confused, but the methods complement each other.

  • Vulnerability scan: automated, regular and broad. It checks many systems for known vulnerabilities and misconfigurations and shows where the picture has changed since the last run.
  • Penetration test: manual, at a point in time and in depth. Experienced testers act like an attacker, chain individual weaknesses together and also find flaws in an application's logic that no scanner detects.

For most companies the combination makes sense: continuous scans for the overview and, at intervals, a penetration test for the most important systems.

05

From finding to fix: an example

Suppose a scan finds a version with a known, actively exploited vulnerability on a company's VPN gateway. A structured process looks like this:

  • Assess: the finding is rated critical because the vulnerability is already being exploited and the system is reachable from the internet.
  • Assign: the finding goes to the person responsible for the system, with a concrete recommendation, such as updating to a specific version.
  • Fix: the update is installed, or the system is disconnected from the internet until then.
  • Confirm: a follow-up scan checks whether the vulnerability is really closed. Only then is the finding marked as fixed.
  • Document: the history is kept and later serves as evidence for management, customers and auditors.

Fixed remediation targets help, for example 7 days for critical, 30 days for high, 90 days for medium and 180 days for low findings. If a finding deliberately cannot be fixed, the risk is accepted with a documented reason instead of being quietly ignored.

06

How veyrisk helps

veyrisk is our continuous vulnerability management service. It checks your domains, servers, web applications, cloud accounts and Microsoft 365 on a fixed schedule and sorts the findings by risk, each with a clear recommendation. Active checks, such as port scans, only run for domains whose ownership you have verified.

Management gets a summary report, and there is a dedicated evidence report for NIS2. Operation and hosting are in Germany. veyrisk does not replace a penetration test, it complements it: the test goes deep at one point in time, veyrisk provides the broad, continuous checks in between.

Plans start at EUR 149 per month (net). If you would like to see what this looks like for your company, we are happy to show you in a demo. Just send us a message through the contact form.

FAQ

Frequently asked questions

How often should you scan?

Neither ISO 27001 nor NIS2 specifies a fixed frequency. What is required is a regular approach appropriate to the risk. For systems reachable from the internet, weekly or more frequent scans have proven useful.

Does veyrisk replace a penetration test?

No. veyrisk provides the broad, continuous checks. A penetration test goes deep at one point in time. For ISO 27001 and NIS2, the combination of both is common practice.

Does veyrisk need access to our internal network?

No. veyrisk checks what is reachable from outside and, for cloud accounts and Microsoft 365, reviews the configuration through read-only access. Active checks such as port scans only run for domains whose ownership you have verified.

What does veyrisk cost?

Plans start at EUR 149 per month (net). Which services are included in which plan is listed on veyrisk.com.

Where is the data processed?

Operation and hosting are in Germany. The contracting party is neonotu GmbH in Munich.

Contact

Reputation takes years. Destruction takes seconds.

Talk to us before somebody else does. The first conversation is free and we reply the same business day.