Vulnerability Assessments
Part of Security Operations, alongside Cyber Security Solutions, Network Operations Center (NOC) Services, Security Awareness Training, and Penetration Testing.
TTS Cyber’s Vulnerability Assessments are offered on their own or together with managed IT. TTS Cyber staff run the scans and review your cloud and Microsoft 365 settings. You receive a prioritized findings report, an executive summary and a fix plan.
What does a TTS Cyber vulnerability assessment cover?
A TTS Cyber Vulnerability Assessment has four parts. Three are scans: outside-facing (external), inside-network (internal) and logged-in (credentialed). The fourth is a review of your cloud and Microsoft 365 settings.
The assessment is a one-time engagement that is repeated yearly.
How outside, inside and logged-in scans work
A vulnerability is a weakness in a system, such as out-of-date software, a missing security update or an unsafe setting. NIST, the U.S. National Institute of Standards and Technology, says a scanner finds the systems on a network and notes their operating systems and applications. It then matches them against a database of known vulnerabilities.
The three kinds of scan differ in where they look from:
- An external scan looks at your systems from outside your network, usually the way the internet sees them.
- An internal scan looks at them from inside your network.
- A credentialed scan logs in. NIST notes that some scanners hold administrator-level credentials on hosts and use them to pull vulnerability information from each one. Others do not, and scan the hosts over the network.
These points come from NIST’s 2008 guide to security testing. The guide is technical guidance written for federal use, not a legal requirement.
What a scan can and cannot tell you
A clean scan shows only what the scanner could find. It does not mean nobody can get in. NIST’s glossary defines a vulnerability assessment as a systematic examination of an information system. Its purposes include finding security deficiencies. The definition does not mention exploiting the weaknesses. NIST puts exploitation under penetration testing, in which assessors mimic real-world attacks. Most such tests look for combinations of weaknesses that give more access than any single one.
The same NIST guide lists limits of scanning:
- Scanners can report weaknesses that do not exist. NIST says someone with networking and operating-system security expertise should interpret the results.
- A scanner’s risk rating may not match the real risk to your organization. NIST says assessors should set the risk level themselves rather than simply accepting the scanner’s rating.
- NIST says the scanner’s database of known weaknesses must be updated before each run.
Deciding what to fix first
Start by checking that a finding is real. Then weigh three things: whether attackers are exploiting the weakness, how exposed the system is and how important it is. The sources below and the FAQ on CVSS scores each cover part of this.
CISA, the U.S. Cybersecurity and Infrastructure Security Agency, keeps the Known Exploited Vulnerabilities (KEV) catalog, a public list of weaknesses known to be exploited. CISA says organizations should use it as an input to prioritization. A 2026 CISA directive covers federal civilian executive branch agencies and their systems. It bases remediation urgency on four variables: asset exposure, KEV status, exploit automation and technical impact.
NIST’s 2022 patching guide plans patching around four cases:
- Routine patching.
- Emergency patching for a severe or actively exploited weakness.
- Emergency mitigation, such as isolating a system until a fix exists.
- Systems that cannot be patched, such as products that have reached end of life.
The 2008 guide adds that fixes should be tested on test systems before production systems change.
Which rules set a scanning schedule?
Some rules set scan schedules for certain groups.
- The Federal Trade Commission (FTC) Safeguards Rule covers financial institutions under FTC jurisdiction. That means businesses that carry out certain financial activities. Unless they have effective continuous monitoring or other systems that detect ongoing changes that may create vulnerabilities, covered institutions must do two things. They must do penetration testing every year. They must also do vulnerability assessments at least every six months and whenever there are material changes to operations or business arrangements. Institutions with customer information on fewer than 5,000 consumers are exempt from these requirements.
- PCI DSS v4.0.1, the Payment Card Industry Data Security Standard, covers organizations that accept payment cards or affect card data security. It is an industry standard, not a law. It calls for internal and external scans at least every three months. External scans must come from a PCI Approved Scanning Vendor, a company approved by the PCI Security Standards Council.
TTS Cyber is not a law firm, and this is general information, not legal advice. Ask your own counsel which rules apply to you.
What’s included
- Outside-facing (external) scans
- Inside-network (internal) scans
- Logged-in (credentialed) scans
- Cloud and Microsoft 365 settings review
- Prioritized findings report
- Executive summary
- Fix plan
What it’s for
- A view of your systems from outside your network and from inside it
- Prioritized findings, so you can see where to start
- An executive summary you can share with leaders
- A fix plan to work from
Frequently Asked Questions
Will a scan slow down our network?
It can. NIST says scanning generates network traffic and may take up bandwidth and slow response times. Some scanner tests, called denial-of-service tests, can harm systems if misused, and can usually be turned off. Because a scan can affect a network, ask how and when it will run before it starts.
What should an assessment report contain?
NIST’s 2008 testing guide says a report should identify weaknesses along with recommended actions. It should work as a reference point for corrective action and a benchmark for tracking progress. It should also suit its readers, so several formats may be needed. NIST sets no required report template for private organizations.
Does a Critical CVSS score mean a breach is about to happen?
Not necessarily. CVSS, the Common Vulnerability Scoring System, rates how severe a weakness is. In version 4.0, the Base score, which vendors and public databases typically publish, assumes a reasonable worst case. Whoever uses a score can adjust it for active exploitation and for their own environment, such as how critical a system is. If a vulnerability report shows CVSS scores, check which version they use. A low score is not safe to ignore if attackers are exploiting the weakness.
Does HIPAA require vulnerability scans?
The Health Insurance Portability and Accountability Act (HIPAA) Security Rule’s evaluation standard, section 164.308(a)(8), does not name vulnerability scanning or set an interval. It requires organizations covered by HIPAA, and their business associates, to run periodic evaluations of how well their security policies and procedures meet the rule. A rule proposed in January 2025 would add automated scans at least every six months. It is only a proposal, so check the Federal Register for its status.
Does Ohio’s cybersecurity law protect us if we run a scan?
Not by itself. Ohio’s Data Protection Act gives businesses a voluntary defense to certain lawsuits brought under Ohio law or in Ohio courts. The lawsuits must claim that a failure to use reasonable security controls caused a breach of personal information. To qualify, a business must create, maintain and follow a written cybersecurity program that reasonably conforms to a recognized framework, such as the NIST Cybersecurity Framework. An assessment alone does not meet that.
Related services
Penetration Testing
Penetration testing by a partner firm that TTS Cyber manages. You get a written report with findings ranked by risk and a one-page executive summary.
Cyber Security Solutions
Security in layers, so a threat one control misses can still be caught by the next. It covers your data, systems and network, and aims to prevent, detect and respond to threats.
Virtual CISO (vCISO) Services
A Virtual CISO for teams without a security executive: SOC 2, ISO 27001 and CMMC work, vendor risk, incident response ownership, and reporting.
Further reading
From our blog
Industries