Vulnerability Assessment

It is critical to assess the risks within your organization's IT infrastructure. Despite an organization's best efforts, IT systems are often released with bugs and installed with misconfigurations, or the underlying technology is changing so rapidly that it's hard for system administrators to keep pace. Schneider Downs understands that the process for installing security updates can be confusing and time-consuming, and that, in reality, security updates can sometimes be overlooked.

The goal of the Vulnerability Assessment is to provide our clients with a comprehensive view of potential security flaws in their environment by looking for misconfigurations, unpatched services, open ports and other architectural mistakes. The results of this assessment will be a detailed report of vulnerabilities uncovered during the assessment, ranked by criticality, along with an agreed-upon remediation plan with detailed steps to assist in remediating noted vulnerabilities that create a security risk.

Detailed Approach to a Vulnerability Assessment

We begin by identifying the scope of the assessment through mapping the client's IP address ranges. This approach will help identify the active devices on the organization's network. From here, a port scan will be performed on each of the active devices identified. This will determine which services are running on each active device and the associated ports. From the device discovery, we will scan each IP address with our automated security assessment tools to identify misconfigurations, vacant patches, and service vulnerabilities that may exist within the host. We will then analyze the results to eliminate any false positives that may have been identified and determine the actual threat and risk to the organization.

Our Vulnerability Assessment works in conjunction with our automated tools and the application of our industry experience. We determine the impact of potential security exposures and the risk they may or may not pose depending on your organization's overall security posture and risk appetite.

Regardless of your organization's size, Schneider Downs will work with you to determine the most effective approach when determining the scope of the assessment. Our team will work closely with you to analyze the results and take a collaborative approach in issue identification and building action plans to remediate identified vulnerabilities. We also consider any other security components and mitigating factors to determine the overall risk to the security posture of the organization's IT infrastructure. We believe that it is essential to take this holistic strategic view during a vulnerability assessment to accurately identify the risk to the organization.

The results of our assessment will be a detailed report of vulnerabilities uncovered during the assessment, ranked by criticality, along with an agreed-upon remediation plan with detailed steps to assist in remediating the noted vulnerabilities.

case studies

 
big problem:
Ransomware attack halted a global manufacturer's operations.
big thinking:
Recover and secure the system – fast – save $1 million in ransom.
 
big problem:
High tax burden for family-owned franchisor.
big thinking:
Comprehensive planning for a 15% tax reduction.

our thoughts on

Seeing is Believing. The Benefits of Data Visualization.

Every day, companies collect massive amounts of data, including information regarding website traffic, customer inquiries, or sales data. With all this

read more >

Recertification of PA Act 153 Clearances

It’s quickly approaching the time for the recertification of Pennsylvania Act 153 clearances. Clearances are valid for 5 years. Act 153 took effect

read more >

Conducting an ERM Evaluation

Institutions of higher education face a number of challenges in today’s highly competitive business and social climate: reputational risk, obsolescence,

read more >

Operation Varsity Blues and Internal Audit

When news broke regarding the college admissions scandal back in March, I couldn’t help but think: where were the internal auditors? Thirty-three

read more >

Top Risks to Keep On Your Radar for 2020

We live in a disruptive world where the risks companies face are constantly evolving. Risks not on your radar today could easily be brought to light within

read more >

Have a question? Ask us!

We’d love to hear from you. Drop us a note, and we’ll respond to you as quickly as possible.

Ask us

contact us

Map of Pittsburgh Office
Pittsburgh

One PPG Place, Suite 1700
Pittsburgh, PA 15222

contactsd@schneiderdowns.com
p:412.261.3644     f:412.261.4876

Map of Columbus Office
Columbus

65 East State Street, Suite 2000
Columbus, OH 43215

contactsd@schneiderdowns.com
p:614.621.4060     f:614.621.4062

Map of Washington Office
Washington, D.C.

1660 International Drive, Suite 600
McLean, VA 22102