WebScan and VA scan:
Your systems
from an attacker's perspective
Analysis of your publicly accessible systems from an attacker’s perspective using WebScan the VA-Scan to systematically identify technical security vulnerabilities in your internal systems and networks.
Non-binding · 15 minutes · Free






From outside and inside

Marvin Süß

Consultant, mip Consult GmbH
Regular checks are essential to ensure the effectiveness of your measures. Many companies only identify vulnerabilities during external audits or after security incidents.
WebScan and VA scan in comparison
WebScan – from the outside |
VA scan – from the inside |
|
|---|---|---|
Point of view |
From the outside, from the perspective of an attacker without access |
From within, from your own network |
What is being tested |
Publicly accessible domains and web applications |
Internal systems and networks: accessible services and open ports |
How it is tested |
Over the Internet, without installation at your place |
Through a scan computer provided by your network |
Typical finds |
Outdated software, unsafe configurations, weak encryption and protocols |
Missing updates, unsafe configurations, unnecessary open services |
Answering the question |
What does someone who looks at us from the outside see? |
How far would someone who is already online go? |
Both scans provide a technical report for IT and a management report for the executive management – unique, recurring, or permanent, with a follow-up scan if required to verify effectiveness. The combination of web and network scan covers both aspects.
WebScan – who is an attacker
from the outside looks
The external analyst WebScan analyzes your publicly accessible systems from an attacker's perspective, that is, what is visible from the outside.
Choose the appropriate one WebScan
for your company
Basic
Up to 3 publicly accessible systems
99€
*
Premium
Popular
Up to 5 publicly accessible systems
129€
*
Excellence
6 Scans – up to 5 publicly accessible systems
599€
*
* One-time fixed price, plus 19 % % VAT.
VA-scan – how far someone would go,
which is already on the web.
The internal VA scan systematically identifies technical security vulnerabilities in your internal systems and networks. The scan is performed from within, using a provided scan computer.
VA Scan
Internal network scan using a provided scan computer
Price on request
Two scans, one clear picture of your situation
The combination of web and VA scanning covers both sides. Regardless of which scan you choose, you get the same results:
„ WebScan mip Consult GmbH He gave us a clear overview of our security situation – which was long overdue. What was particularly helpful was the structured and transparent overview of our publicly visible systems and potential risks.
This way, we can targetly evaluate our attack surface and further prioritize measures – as a basis for the continuous improvement of our security architecture.“
Michael Schröer
Managing Partner
M2. technology & project consulting GmbH

What an attacker finds about you,
We find it first.
Non-binding · 15 minutes · Free
Frequently asked questions
What is the difference between WebScan and VA Scan?
The external WebScan analysis of your publicly accessible systems from an attacker’s perspective – that is, what is visible from the outside. The internal VA scan systematically identifies technical security vulnerabilities in your internal systems and networks. Both perspectives combined provide a complete picture.
Are vulnerability scans legally required?
Not as a scan, but as a result. Article 32(1)(d) of the GDPR requires a procedure for regular review, assessment, and evaluation of the effectiveness of your technical and organizational measures. For organizations under the BSIG, vulnerability management and the evaluation of the effectiveness of the measures are additional mandatory points. A scan is the most practical way to fulfill both of these requirements.
How often should we scan?
There is no legally prescribed frequency – neither the GDPR nor the BSIG mentions an interval. „Regularly“ means risk-based: depending on how exposed your systems are and how frequently they change. After major changes to the infrastructure, a scan is advisable in any case.
Do we need permission before scanning?
For your own systems, your engagement is sufficient. As soon as external systems are involved, such as hosting, cloud, or service providers, we require the express written consent of the persons authorized to act, with a defined scope, period, and method. This is not a formality: Without an order, scans fall within the scope of §§ 202a ff. of the StGB. Therefore, we clarify the scope in writing before the first scan.
What happens with the vulnerabilities found?
You receive clear, understandable reports with prioritized action recommendations, that is, not just a list of findings, but a sequence. To ensure sustainable protection, we establish processes for continuous monitoring upon request.
Is a scan enough to meet NIS-2?
No. The BSIG requires a whole package of measures, ranging from risk analysis to emergency management and supply chain security, to training and multi-factor authentication. Vulnerability management and effectiveness assessment are two of them. The scan is an important component, but not a substitute for a management system.






