Skip to content

Vulnerability Scanning Done Properly

Credentialed scans, asset coverage, tuning out noise, and why scan counts are a bad metric.

Editorial team 2 min read

Scanners are the cheapest security coverage available and the easiest to run badly.

Credentialed beats uncredentialed

An unauthenticated scan sees what a stranger sees: open ports and banner guesses, with false positives in both directions. A credentialed scan reads installed package versions and configuration, and is dramatically more accurate. If you run only one, run the credentialed one — and treat the scanning account as the privileged credential it is.

Coverage is the real problem

Most programmes do not have a scanner accuracy problem; they have an asset problem. The host that gets compromised is usually the one nobody knew about, which no scan covered. Reconcile scan coverage against the asset inventory, the cloud provider's API and DNS, and investigate the gap.

Tuning

A scanner that reports forty thousand findings is reporting nothing. Suppress by reason, with an owner and a review date — never silently. Group by patch and by image, since one base image update often closes thousands of findings at once.

Metrics worth keeping

Not "findings closed", which rewards closing easy ones. Better: time to remediate by severity, the proportion of assets scanned in the last 30 days, and the age of the oldest unremediated critical. Those three say more about a programme than any count.

More in Cyber security

All Cyber security guides →
Cyber security Guide · 2 min

What a Penetration Test Is, and Is Not

A penetration test is a time-boxed, authorised attempt to reach a defined objective — not a full inventory of every weakness you have.

Cyber security 2 min read 25 May 2025

Cyber security Guide · 2 min

Rules of Engagement and Authorisation

What to agree before any testing starts: scope, timing, data handling, escalation and the single document that makes the work lawful.

Cyber security 2 min read 24 May 2025

Cyber security Guide · 2 min

Writing a Finding People Will Fix

Severity, evidence, reproduction, impact in business terms, and a fix the team can actually make.

Cyber security 2 min read 23 May 2025

Cyber security Guide · 2 min

The OWASP Web Security Testing Guide

A shared checklist for testing web applications, and how to use it without turning testing into box-ticking.

Cyber security 2 min read 21 May 2025