01 / Service CVSS v3.1 · NIST SP 800-115 · ISO 27001

Vulnerability Assessment that maps the whole estate

Professional & Certified Vulnerability Assessment Services in Indonesia

SkyCyber's Vulnerability Assessment service gives you a comprehensive view of your infrastructure's security posture.

SCAN SURFACE 04 SIDES
Network Vulnerability Assessment ROUTER · SWITCH · FIREWALL
Web Application VA OWASP TOP 10
Cloud Infrastructure VA AWS · AZURE · GCP
Database & Endpoint VA DATABASE · ENDPOINT
AUTHENTICATED UNAUTHENTICATED AGENT-BASED SCHEDULED
Critical 9.0 - 10.0 Direct impact on data or service. First in the remediation queue.
High 7.0 - 8.9 Exploitable without heavy preconditions. Scheduled right after critical.
Medium 4.0 - 6.9 Needs specific preconditions. Closed in the next remediation cycle.
Low 0.1 - 3.9 Small risk, logged as hardening and configuration cleanup.
02 / Scan surface

Everything connected, on the list

Automated scanning gives the coverage, manual verification gives the certainty. No critical or high finding reaches the report before a person has checked it.

Network Vulnerability Assessment

ROUTER · SWITCH · FIREWALL

Comprehensive scanning of network infrastructure — routers, switches, firewalls, and servers — to find misconfigurations and unpatched gaps.

PATCH LEVEL MISCONFIG PORT EXPOSURE SERVICE ENUM

Web Application VA

OWASP TOP 10

Identifying web application vulnerabilities per OWASP Top 10 — from input validation to weak session management.

INPUT VALIDATION SESSION ACCESS CONTROL TLS

Cloud Infrastructure VA

AWS · AZURE · GCP

Auditing AWS, Azure, or GCP configurations — detecting public buckets, overprivileged IAM, and loose security groups.

IAM PUBLIC BUCKET SECURITY GROUP KEY ROTATION

Database & Endpoint VA

DATABASE · ENDPOINT

Scanning databases and endpoints for vulnerabilities — patch level, default credentials, and unintended exposure.

DEFAULT CREDENTIAL PATCH LEVEL EXPOSURE HARDENING
03 / Methodology

Structured and proven approach

Four phases of industry-standard methodology to ensure optimal results.

PHASE 1 · SCOPING

Assessment

Thorough analysis of your business needs, system architecture, and specific risk profile.

PHASE 2 · SCANNING

Execution

Execution by certified team using OWASP, PTES, and OSSTMM methodologies.

PHASE 3 · REPORTING

Reporting

Comprehensive report: findings, risk analysis, remediation priorities, and technical recommendations.

PHASE 4 · RESCAN

Follow-up

Retesting, continuous monitoring, and technical support for long-term security.

Phase four returns to phase one Quarterly, or after any significant change
04 / Benefits

What you walk away with

Each benefit is designed to deliver direct impact on your security posture and business operational continuity.

Comprehensive vulnerability scanning

Servers, networks, endpoints, and web applications in one consolidated report

CVSS v3.1-based prioritization

Focus resources on the vulnerabilities that matter most to your business

False-positive elimination

Every finding is manually verified for accuracy and to reduce noise

Dual-format reporting

An executive summary for management and a technical remediation guide for your engineering team

Compliance mapping

Every vulnerability is mapped to ISO 27001, PCI DSS, or other relevant regulatory controls

Periodic rescanning

Verify that remediation succeeded and no new vulnerabilities have emerged

05 / Standards & tooling

Several engines, one cross-checked result

Several scanners are run side by side and cross-checked, so a gap one engine misses is still caught by another.

Frameworks 03
CVSS v3.1 A globally recognized vulnerability severity scoring standard, used to prioritize remediation.
NIST SP 800-115 A technical guide to information security testing from the National Institute of Standards and Technology.
ISO 27001 Annex A.12.6 Technical vulnerability management controls used as a reference for information security compliance audits.
Core tooling 06
Nessus Professional Comprehensive vulnerability scanning with an up-to-date CVE database
OpenVAS Open-source scanner for cross-validating findings
Qualys VMDR Cloud-based continuous vulnerability management
Nmap Network discovery & service enumeration
Nikto Web server vulnerability scanning
Burp Suite Manual verification of web application vulnerabilities
07 / Which one

When an assessment is enough, and when it is not

Both answer different questions. Reading them side by side is usually faster than asking which is better.

Vulnerability Assessment Penetration Testing
Goal Map and rank every vulnerability that exists. Prove that one vulnerability can actually be exploited.
Depth Broad coverage, manual verification on critical and high findings. Deep on selected attack paths, all the way to working proof.
Output A priority-ordered register of findings with CVSS scores. A report with a Proof of Concept for every finding.
Cadence Repeating, usually quarterly or after any significant change. Periodic, usually yearly or ahead of a major release.

Most clients run both: an assessment to keep coverage wide, a penetration test to prove depth where the risk is highest.

See Penetration Testing
08 / Transparent Results

Sample Vulnerability Assessment report

Every project concludes with a comprehensive report — covering findings, CVSS scoring, risk analysis, and actionable technical recommendations for your team.

Findings ordered by priority, not by scanner output order Critical and high findings verified by hand before publication Dual format: executive summary and technical remediation guide Every finding mapped to the control it belongs to
PDF Format · ~47 pages · Complete with CVSS scoring & technical recommendations
09 / Ready to Start?

Get a Vulnerability Assessment quote

Tell us about your cybersecurity needs. We will prepare a proposal tailored to your budget and priorities — no obligation.

Reply within one business day NDA available before scoping Verification rescan included
10 / Common Questions

Frequently asked questions about Vulnerability Assessment

Still unclear? Send your asset list and we will answer with a concrete estimate.

Ask Us
What is vulnerability assessment and how is it different from penetration testing?

Vulnerability assessment is the systematic process of identifying, classifying, and prioritizing vulnerabilities using automated scanning combined with manual verification — the result is a complete list of vulnerabilities with severity ratings (CVSS). Unlike penetration testing, which simulates real attacks to prove exploitation impact, vulnerability assessment focuses on broad, thorough coverage in a shorter timeframe — making it a good first step before a pentest or for routine checks.

How often should a company run a vulnerability assessment?

We recommend running a VA at least quarterly (every 3 months) for critical infrastructure, or whenever a significant change occurs — a new application deployment, added servers, or network configuration changes. For tightly regulated sectors like banking and healthcare, monthly assessments are often a compliance requirement.

How long does a vulnerability assessment take?

Duration depends on scope size — for small-to-medium infrastructure (1-50 assets), the process typically finishes in 3-5 business days, including scanning, manual verification, and report writing. For enterprises with hundreds of assets, it can take 2-3 weeks.

Are the results guaranteed free of false positives?

We don't rely on automated scanners alone — every critical and high finding is manually verified by our team to eliminate false positives before they reach the final report. This ensures your engineering team doesn't waste time remediating issues that aren't actually real.

What report format will we receive?

You'll receive a dual-format report: an executive summary covering overall risk levels for management, and a technical remediation guide with detailed fix steps per vulnerability for your engineering team — complete with CVSS scoring and CVE references.

Does SkyCyber’s vulnerability assessment help with regulatory compliance?

Yes. Every finding is mapped to ISO 27001 Annex A.12.6 controls, PCI DSS requirements for cardholder data, and data protection principles relevant to Indonesia's PDP Law — helping you prepare compliance evidence for both internal and external audits.

WHATSAPP