In short
Vulnerability scanning means checking the servers, endpoints, network devices and web services on a company network with a scanner such as Nessus, and reporting known security flaws and misconfigurations. It is not penetration testing: nothing is exploited. CybUp plans the scan, prioritises the findings, carries out the remediation and confirms the result with a verification scan.
What is vulnerability scanning and what does it do for a business?
Vulnerability scanning is an automated check of which ports the devices on your network expose, which software versions they run and whether those versions have publicly disclosed security flaws. For every finding you get the affected device, a description of the vulnerability, a risk rating and a recommended fix.
The benefit is concrete: you know what is exposed instead of guessing. In most companies the problem is not exotic attacks but forgotten things. A file server nobody has rebooted in years, a printer still on its default password, a NAS that has not been updated since the day it was installed, or an RDP port opened “temporarily” and never closed. A vulnerability scan puts each of these in front of you.
We do not see scanning as a matter of running a tool. The real work is turning a report hundreds of lines long into something that says “close these five this week, these three can wait for the next maintenance window”, and then doing the remediation as well.
Vulnerability scanning vs penetration testing: what is the difference?
A vulnerability scan finds and lists weaknesses; a penetration test tries to exploit them the way a real attacker would and shows how far into your systems someone could get. One does not replace the other. NIST’s security testing guide, SP 800-115, also treats vulnerability scanning and penetration testing as separate techniques.
CybUp carries out vulnerability scanning and the remediation that follows; we do not do penetration testing. If a regulation, an audit or a customer contract requires a penetration test report from a TSE-certified provider, that test is carried out by firms certified under the penetration testing authorisation programme of TSE, the Turkish Standards Institution. In that case we get the environment ready: we scan first and close the obvious holes, and afterwards we take on the technical fixes for whatever the test turns up.
In practice this order makes sense. Going into a certified penetration test with missing patches means spending much of an expensive test on things an automated scan would have found anyway.
“The purpose of this document is to assist organizations in planning and conducting technical information security tests and examinations, analyzing findings, and developing mitigation strategies.”
How does a Nessus vulnerability scan work?
The scan is run with Tenable’s Nessus scanner from a point that can reach your network. Usually the scanner sits on a virtual machine inside the network, and services you expose to the internet are scanned separately from the outside. The scan policy, the scope (IP ranges, VLANs, sensitive devices to exclude) and the time window are agreed with you.
There are two kinds of scan. An uncredentialed scan sees the device from the outside: open ports, service versions, certificate and protocol settings. A credentialed scan logs in to the server with an account and reads missing patches, installed software and local settings from the inside. As Tenable’s credentials documentation makes clear, the more privilege the scanner has, the more detailed the results. So we create a dedicated scan account for Windows servers and an SSH key-based account for Linux servers, and restrict their rights once the work is done.
Take an 80-user office on two floors: six physical and virtual servers, a firewall, four switches, a few camera recorders and some network printers. In an environment like this a full scan usually finishes in a few hours outside working hours. The first page of the report tends to show the same picture: services that still accept old TLS versions, one or two Windows servers that have gone months without patches, and devices whose management interface was left on default settings.
“Credentialed scans can perform any operation that a local user can perform. The level of scanning depends on the privileges granted to the user account.”
How should vulnerability scan results be prioritised?
Trying to close every finding with the same urgency means closing none of them on time. We set priority not only by risk score but by where the vulnerability sits. Findings arrive with a CVSS score, and we read that score against the reality of your environment.
- High and critical vulnerabilities on internet-facing services come first.
- Vulnerabilities with public exploit code move up the list, even when their score is lower.
- Servers holding personal or accounting data are dealt with before test machines with the same flaw.
- Updates that clear dozens of findings with a single patch are scheduled as quick wins.
- Findings that cannot be fixed get a compensating control (access restriction, segmentation) recorded in writing.
Does KVKK require regular vulnerability scanning?
Yes, the regulator’s guidance says so explicitly. KVKK, Türkiye’s Personal Data Protection Law (Law No. 6698), requires data controllers under Article 12 to take “all necessary technical and administrative measures to ensure an appropriate level of security”. The Personal Data Protection Authority’s Personal Data Security Guide (Technical and Administrative Measures) states that IT systems should be protected against known vulnerabilities through regular vulnerability scans and penetration tests, with the results assessed.
Note that the guide lists the two measures together. Vulnerability scanning covers the ongoing part of that expectation; a penetration test has to be planned separately. We explain which services map to the other KVKK technical measures on our KVKK technical measures page.
How often should you run a vulnerability scan?
We recommend a full scan at least once a quarter, repeated after every major change. When a new server goes live, firewall rules change or your web application moves to a new version, your attack surface changes with it.
New vulnerabilities are published every week, so a server that came back clean three months ago can show a critical finding today. That is why it makes sense to scan your public IPs more often, monthly for example. To shrink what is visible from outside in the first place, a review of your firewall configuration and a WAF in front of web applications will often remove a large share of scan findings for good.
What happens after the findings are fixed?
Once remediation is complete we run a verification scan with the same policy. The difference between the first and the last report is concrete evidence you can show management and auditors: how many findings there were, how many were closed, and why the rest are still open and which compensating control covers them.
For companies that want this to continue, we put scanning on a schedule and deliver a short comparison report at the end of each cycle. Tying patch management into your Windows Server maintenance routine stops the same findings coming back in the next scan.
What you receive
- Scope and scan policy document (IP ranges, excluded devices, time window)
- Nessus scan report for the internal network and external IPs
- Findings list prioritised for your environment, with a remediation plan
- Patching, configuration changes and disabling of unneeded services
- Verification scan and before/after comparison report
- Compensating control records for findings that cannot be fixed
How we work
- 1
Free initial call
We discuss the size of your network, your critical systems and what you expect from the scan, agree the scope and send a written quote.
- 2
Scope and permissions
IP ranges, scan accounts and the time window are approved in writing; sensitive devices are excluded where needed.
- 3
Scanning
The internal and external scans run outside working hours, with settings that will not disrupt day-to-day work.
- 4
Analysis and prioritisation
The raw report is interpreted for your environment, false positives are weeded out and a remediation plan is drawn up.
- 5
Remediation and verification
Patches and configuration changes are applied, then a verification scan documents the result.
Frequently asked questions
Will a vulnerability scan slow down or crash our systems?
Under normal conditions, no. We set the scan policy to limit concurrent connections and run the scan outside working hours. Sensitive equipment such as older PLCs or medical devices is either left out of scope or scanned separately with a light policy.
Do you also do penetration testing?
No, we do not carry out penetration tests. We do vulnerability scanning and the technical remediation of the findings. If you need a certified penetration test, it is done by an authorised firm; we prepare the environment beforehand and take on the fixes afterwards.
Who buys the Nessus licence?
For one-off scans we can use our own tooling. If you want ongoing scanning in-house, we can buy the Tenable licence in your company’s name and install it. We decide which option fits during the initial call, based on the scope.
Can the scan be done remotely?
Yes. A secure VPN connection into your network, or a scanning virtual machine installed inside it, is enough; we work remotely with offices anywhere in Türkiye. If on-site work is needed in Istanbul, we come to your office.
How long does a vulnerability scan take?
The scan itself takes a few hours; analysis and reporting take a few days. Remediation time depends on the number of findings and your maintenance windows. In a mid-sized office the whole process, from the first scan to the verification scan, is usually complete within a few weeks.
Do you scan our website as well?
We scan the web server and the services running on it for known vulnerabilities. Logic flaws in the application’s own code are beyond what a vulnerability scan can find. To protect the application against common attacks, a WAF is worth considering as well.
Is a scan report useful in a KVKK audit?
Yes, as one piece of evidence that technical measures are in place. The legal side of KVKK compliance, and administrative measures such as the data inventory and policies, are outside our scope; for those you need to work with your legal adviser.
How is pricing worked out?
We send a written quote once we have reviewed the scope: the number of devices, whether you need internal and external scanning, and whether the remediation work falls to us. The initial review is free.
Sources and official documentation
- NIST SP 800-115: Technical Guide to Information Security Testing and Assessment
- Tenable Nessus documentation: Credentials
- FIRST: Common Vulnerability Scoring System (CVSS)
- Law No. 6698 on the Protection of Personal Data (KVKK), mevzuat.gov.tr, in Turkish
- KVKK: Personal Data Security Guide (Technical and Administrative Measures), April 2025, in Turkish
- TSE: Authorisation Programme for Penetration Testing Staff and Firms (USOM, in Turkish)