Service — security assessment
An online shop, a customer portal, an ERP login: the more a company puts online, the larger the attack surface becomes — often without anyone in-house having an overview of it. VERLON defence tests your systems the way an attacker would, documents every finding traceably and tells you what to tackle first.
Your own IT team knows the systems too well to see their blind spots. An attacker, on the other hand, tries exactly what nobody questions in day-to-day work.
Most incidents do not begin with a sophisticated attack, but with a forgotten setting: a missing security header, a login with no lockout after too many attempts, an access that should have been removed long ago. A structured assessment finds these points while they are still unexploited.
We record in writing which systems are tested, in which time window and who authorises the assessment. Only what is expressly authorised is tested.
We work through the OWASP Testing Guide — access control, authentication, input validation, configuration, transport security — manually and with tools. Every finding is confirmed before it goes into the report.
Every vulnerability is given a traceable severity rating under CVSS 3.1. So you see what matters now and what can wait, rather than a list with no order of priority.
You receive a report with a summary for management and concrete recommendations. After remediation we check specifically whether the gap has really been closed.
Management summary, distribution by severity and every finding individually: target, description, impact, recommendation. Also usable for customers, insurers or audits.
Not thirty equally loud warnings, but the order in which you should proceed — with the approximate effort each point involves.
For every finding, the supporting evidence: the affected response, the status code, the configuration state. Traceable for your IT team or your service provider.
Something is only fixed once we can no longer trigger it after the correction. The retest is part of the assessment, not of the next quotation.
Every finding in one sentence that management can understand as well — and below it the technical details for those who implement the fix.
We answer questions after the assessment. You are not left alone with the report when it is time to implement.
From your public website to the systems behind it — within the scope you authorise.
Websites and online shops Customer portals and login areas ERP and administration access Interfaces and APIs Email and DNS configuration Transport and certificate security
No assessment can certify that a system is secure — it can only show what was vulnerable at the time of the assessment. We therefore do not promise invulnerability, but an honest picture and an order of priority you can work through.
We only test what has been authorised in writing, and we cause no damage in doing so: no denial-of-service attacks, no changes to data, no deletion. We do not carry out assessments outside such an authorisation.
Tell us your address and who authorises the assessment. We propose a scope and record what will be tested — before the first request is made.