Service — security assessment

Know where your websites and systems are vulnerable — before someone else finds out.

An online shop, a customer portal, an ERP login: the more a company puts online, the larger the attack surface becomes — often without anyone in-house having an overview of it. VERLON defence tests your systems the way an attacker would, documents every finding traceably and tells you what to tackle first.

Why an external assessment

Your own IT team knows the systems too well to see their blind spots. An attacker, on the other hand, tries exactly what nobody questions in day-to-day work.

Most incidents do not begin with a sophisticated attack, but with a forgotten setting: a missing security header, a login with no lockout after too many attempts, an access that should have been removed long ago. A structured assessment finds these points while they are still unexploited.

How it works

Scope and authorisation

We record in writing which systems are tested, in which time window and who authorises the assessment. Only what is expressly authorised is tested.

Testing to a recognised guide

We work through the OWASP Testing Guide — access control, authentication, input validation, configuration, transport security — manually and with tools. Every finding is confirmed before it goes into the report.

Rating by CVSS

Every vulnerability is given a traceable severity rating under CVSS 3.1. So you see what matters now and what can wait, rather than a list with no order of priority.

Report and retest

You receive a report with a summary for management and concrete recommendations. After remediation we check specifically whether the gap has really been closed.

What you have at the end

A report that stands up to scrutiny

Management summary, distribution by severity and every finding individually: target, description, impact, recommendation. Also usable for customers, insurers or audits.

A clear order of priority

Not thirty equally loud warnings, but the order in which you should proceed — with the approximate effort each point involves.

Evidence, not assertions

For every finding, the supporting evidence: the affected response, the status code, the configuration state. Traceable for your IT team or your service provider.

A retest included

Something is only fixed once we can no longer trigger it after the correction. The retest is part of the assessment, not of the next quotation.

Clearly explained

Every finding in one sentence that management can understand as well — and below it the technical details for those who implement the fix.

One point of contact

We answer questions after the assessment. You are not left alone with the report when it is time to implement.

What we test

From your public website to the systems behind it — within the scope you authorise.

Websites and online shops Customer portals and login areas ERP and administration access Interfaces and APIs Email and DNS configuration Transport and certificate security

A limit we state openly

No assessment can certify that a system is secure — it can only show what was vulnerable at the time of the assessment. We therefore do not promise invulnerability, but an honest picture and an order of priority you can work through.

We only test what has been authorised in writing, and we cause no damage in doing so: no denial-of-service attacks, no changes to data, no deletion. We do not carry out assessments outside such an authorisation.

Have your own website assessed

Tell us your address and who authorises the assessment. We propose a scope and record what will be tested — before the first request is made.