vulnerability scan

WebScan and VA scan:
Your systems
from an attacker's perspective

Analysis of your publicly accessible systems from an attacker’s perspective using WebScan the VA-Scan to systematically identify technical security vulnerabilities in your internal systems and networks.

  • Certified experts and lawyers
  • Recognize your IT risks
  • For every size of company – from start-ups to conglomerates
WebScan - ISO 9001 Certified
ISO 9001
BvD member
GDD member
Made in Germany
20 years of experience
  • Federal Office for Information Security
  • Compliant with GDPR
  • BvD member
  • GDD member
  • Made in Germany
✓ Interdisciplinary team ✓ certified experts ✓ pragmatic implementation
Two perspectives

From outside and inside

Consultant

Marvin Süß

Signature Asmus Eggert

Consultant, mip Consult GmbH

Regular checks are essential to ensure the effectiveness of your measures. Many companies only identify vulnerabilities during external audits or after security incidents.

  • WebScan – the view from the outside on everything that is publicly accessible
  • VA Scan – the view from the inside on systems, services, and open ports
  • Both perspectives combined give a complete picture

WebScan and VA scan in comparison

WebScan – from the outside
VA scan – from the inside
Point of view

From the outside, from the perspective of an attacker without access

From within, from your own network

What is being tested

Publicly accessible domains and web applications

Internal systems and networks: accessible services and open ports

How it is tested

Over the Internet, without installation at your place

Through a scan computer provided by your network

Typical finds

Outdated software, unsafe configurations, weak encryption and protocols

Missing updates, unsafe configurations, unnecessary open services

Answering the question

What does someone who looks at us from the outside see?

How far would someone who is already online go?

Both scans provide a technical report for IT and a management report for the executive management – unique, recurring, or permanent, with a follow-up scan if required to verify effectiveness. The combination of web and network scan covers both aspects.

Product 1 · webscan

WebScan – who is an attacker
from the outside looks

The external analyst WebScan analyzes your publicly accessible systems from an attacker's perspective, that is, what is visible from the outside.

  • External web scan of publicly accessible domains and web applications
  • Examination of the encryption and the protocols used
Prices & Packages

Choose the appropriate one WebScan
for your company

Basic

Up to 3 publicly accessible systems

99€

*

  • Quick results
  • One-time payment
  • Detailed + understandable report
  • Prioritized list of measures
  • Personal results discussion

Premium

Popular

Up to 5 publicly accessible systems

129€

*

  • Quick results
  • One-time payment
  • Detailed + understandable report
  • Prioritized list of measures
  • Personal results discussion

Excellence

6 Scans – up to 5 publicly accessible systems

599€

*

  • 2-month scans
    (total 6 scans per month)
  • Quick results
  • One-time (annual) payment
  • No automatic renewal
  • Detailed, understandable reports
  • Prioritized action list with progress control
  • Personal results discussions

* One-time fixed price, plus 19 % % VAT.

Product 2 · va-scan

VA-scan – how far someone would go,
which is already on the web.

The internal VA scan systematically identifies technical security vulnerabilities in your internal systems and networks. The scan is performed from within, using a provided scan computer.

  • internal network scan via a provided scan computer
  • Identification of available systems, services, and open ports
  • missing updates, unsafe configurations, and unnecessary open services

VA Scan

Internal network scan using a provided scan computer

Price on request

both together

Two scans, one clear picture of your situation

The combination of web and VA scanning covers both sides. Regardless of which scan you choose, you get the same results:

  • Detecting outdated software, missing updates, and unsafe configurations
  • Evaluation and prioritization of findings according to risk
  • Management report with security status at a glance

„ WebScan mip Consult GmbH He gave us a clear overview of our security situation – which was long overdue. What was particularly helpful was the structured and transparent overview of our publicly visible systems and potential risks.

This way, we can targetly evaluate our attack surface and further prioritize measures – as a basis for the continuous improvement of our security architecture.“

Michael Schröer
Managing Partner
M2. technology & project consulting GmbH

Consultant
Marvin Süß • Consultant

What an attacker finds about you,
We find it first.

Non-binding · 15 minutes · Free

Frequently asked questions

What is the difference between WebScan and VA Scan?

The external WebScan analysis of your publicly accessible systems from an attacker’s perspective – that is, what is visible from the outside. The internal VA scan systematically identifies technical security vulnerabilities in your internal systems and networks. Both perspectives combined provide a complete picture.


Are vulnerability scans legally required?

Not as a scan, but as a result. Article 32(1)(d) of the GDPR requires a procedure for regular review, assessment, and evaluation of the effectiveness of your technical and organizational measures. For organizations under the BSIG, vulnerability management and the evaluation of the effectiveness of the measures are additional mandatory points. A scan is the most practical way to fulfill both of these requirements.


How often should we scan?

There is no legally prescribed frequency – neither the GDPR nor the BSIG mentions an interval. „Regularly“ means risk-based: depending on how exposed your systems are and how frequently they change. After major changes to the infrastructure, a scan is advisable in any case.

Do we need permission before scanning?

For your own systems, your engagement is sufficient. As soon as external systems are involved, such as hosting, cloud, or service providers, we require the express written consent of the persons authorized to act, with a defined scope, period, and method. This is not a formality: Without an order, scans fall within the scope of §§ 202a ff. of the StGB. Therefore, we clarify the scope in writing before the first scan.


What happens with the vulnerabilities found?

You receive clear, understandable reports with prioritized action recommendations, that is, not just a list of findings, but a sequence. To ensure sustainable protection, we establish processes for continuous monitoring upon request.


Is a scan enough to meet NIS-2?

No. The BSIG requires a whole package of measures, ranging from risk analysis to emergency management and supply chain security, to training and multi-factor authentication. Vulnerability management and effectiveness assessment are two of them. The scan is an important component, but not a substitute for a management system.

Other services

Information security services,
that suits your company.