Vulnerability scanning — find the holes before someone else does.
Sometimes called light pen testing. Regular automated scans of your servers, public IPs, and websites for open ports, known CVEs, misconfigurations, and SSL issues. Detailed reports with severity ratings, delivered monthly. From $29/mo for the base package.
You don't know what you don't scan.
Attackers scan the entire internet constantly, looking for exposed systems with known vulnerabilities. If your firewall has a service exposed that shouldn't be, or your web server is running an unpatched version of Apache, or your SSL certificate uses a cipher suite that was deprecated in 2019, somebody's automated scanner already knows. The only question is whether you know first.
Vulnerability scanning is the defender's version of what attackers are already doing to you. We run the same categories of scan — from outside your network, looking at your public-facing infrastructure — and give you a plain-language report of what an opportunistic attacker would find.
Then you fix it before they find it too.
Everything an attacker checks in the first 15 minutes.
Open ports
Known CVEs
Outdated software
SSL/TLS misconfigurations
Missing security headers
Common web-app weaknesses
Reports designed for humans, not spreadsheets.
Most vulnerability scanning outputs are 400-page PDFs full of "informational" findings that mean nothing to a business owner. Ours are short, prioritized, plain-language documents you can actually act on.
- Severity ratings: Critical / High / Medium / Low
- Plain-English description of what each finding means
- Specific remediation recommendation per finding
- Month-over-month comparison chart (what's fixed, what's new)
- Executive summary for management, technical detail for IT
- Delivered by email + downloadable PDF
Your mail server is running Exchange 2019 CU12, which has a published unauthenticated remote-code-execution vulnerability. Attackers can execute code as SYSTEM without credentials.
Recommendation:
Apply Exchange CU13 or later, published by Microsoft on 2025-XX-XX. Estimated downtime: 30 minutes for patch + reboot.
One finding, one page. Not a wall of noise.
Priced by scan frequency and target count.
Base package covers one server/IP + one website domain. Additional targets (extra sites, IPs, web apps) are billed per-target at the rate for your chosen scan frequency.
| Scan frequency | Base package | Per additional target | Typical small-biz total |
|---|---|---|---|
| 1 Scan / Month | $29 / mo | $20 / target / mo | $49 / mo(base + 1 extra target) |
| 2 Scans / Month | $39 / mo | $25 / target / mo | $64 / mo(base + 1 extra target) |
| Weekly Scans | $59 / mo | $35 / target / mo | $94 / mo(base + 1 extra target) |
Base package covers 1 server/IP + 1 website domain. Not sure what counts as a "target" for your setup? Give us a call and we'll work through it — usually a 5-minute conversation. No long-term contract. Cancel at any month boundary.
Vulnerability scanning FAQ
Is this the same as pen testing?+
Related, but different. True penetration testing is manual work by a human security professional who actively tries to break into your systems — usually $5,000-$25,000+ per engagement. Vulnerability scanning is the automated tool-based cousin: scheduled scans that look for known vulnerabilities, open ports, and misconfigurations at a small fraction of the cost. Most Cape Breton businesses should start with vulnerability scanning for ongoing coverage, then step up to a one-time Comprehensive Security Assessment ($2,500+, see /services/security-assessment) which covers configurations, cloud posture, policies, and physical security in addition to scanning. Full manual pen testing is available via our partner network for regulated industries or specific compliance needs.
What does the scan actually check?+
Open ports (what's listening on the internet, what shouldn't be), known CVEs (published vulnerabilities in the software you're running), outdated software versions, SSL/TLS misconfigurations, weak cipher suites, missing security headers on web servers, exposed admin interfaces, default credentials, and common web-application weaknesses. Everything an opportunistic attacker would find in the first 15 minutes of poking at your infrastructure.
What's "1 server/IP + 1 website domain" cover in the base package?+
One public-facing IP address (your firewall / router / server) plus one website domain (say, chantsit.com). That covers most small businesses with a simple setup. If you have multiple offices, multiple servers, or multiple websites, each extra target is $20-35/month depending on scan frequency.
Do the scans cause any disruption?+
External scans are generally non-disruptive — we're checking your public-facing infrastructure the same way an attacker would, from outside your network. You may see extra traffic in your firewall logs during scan windows. For particularly noisy or aggressive scan modes we schedule off-hours or coordinate with you. In eight years of running these scans for clients, we've never taken a system offline with one.
What do the reports look like?+
Detailed but readable — designed for a business owner or IT manager, not just a security specialist. Each finding gets a severity rating (Critical / High / Medium / Low), a plain-English description of what it is and why it matters, and a specific remediation recommendation. Month-over-month comparison shows what's been fixed and what's new. Delivered by email; also downloadable as PDF for your files.
Who acts on the findings — you or my team?+
Depends on your setup. If you're a managed IT client, we fix the findings as part of your ongoing support. If you're not, you get the report and hand it to your own IT staff (or hire us hourly for the remediation work). We can also do a fixed-fee "scan + remediation" bundle for common findings — ask us during setup.
How is this different from just running Nessus / OpenVAS ourselves?+
The tools are similar under the hood — but running them, interpreting the noise, filtering false positives, and turning results into a plain-language report takes real time and expertise. Most in-house teams try it once, get a 400-page PDF full of "informational" findings that mean nothing, and give up. We handle the whole cycle so you get a short, actionable report instead of a wall of noise.
Is there a minimum contract?+
No. Month-to-month. Cancel at any month boundary. Most clients start with 1 scan/month at the base tier ($29 for base package), and add extra targets or bump to 2 scans/month once they see the value.
Start monthly scans.
One phone call, we identify your targets, we run the first scan the same week, you get a plain-language report by email. From $29/month for the base package.