Managed IT and Managed Security · Leesburg, VA

Vulnerability Assessment and Penetration Testing

Find the Weak Points First, Fix Them, Then Prove They Are Fixed.

A vulnerability assessment shows what is exposed. A penetration test shows what an attacker could actually do with it. We do both, write the fix list for business leaders and IT, and retest.

For businesses that need evidence for a client, an insurer, an auditor or themselves.

What Is the Difference Between a Vulnerability Assessment and a Penetration Test?

A managed vulnerability assessment is automated discovery across your network, systems and applications, with every finding classified by severity and a plan to fix what matters most. It is broad and it repeats.

A penetration test is security experts simulating a real attack against your systems, networks or applications, to show which weaknesses can actually be used and how far an attacker gets. It is deep and it is scoped.

How Does a Penetration Test Run?

Four steps, every time. We define the scope in writing and sign a Confidentiality Agreement: infrastructure, domains, servers, devices with IP addresses, and exclusions. We execute the test and document the results in a vulnerability assessment delivered as a PDF. We write an initial report with practical remediation guidance for business leaders and IT teams. After your team makes the fixes, we retest every finding, and the final report states patched or unpatched for each.

What Do I Get at the End?

Reports you can use for audit and insurance, a remediation plan ordered by risk, and a retest that proves which findings are closed. External, internet facing resources can also be scanned on a regular schedule, so new exposure is found between tests.

Internal Gray Box Testing

What a Trusted Insider Could Reach.

Gray box testing sits between black box, with no prior knowledge, and white box, with full access. It simulates someone with limited internal access, such as a trusted insider or an attacker holding stolen credentials.

We run it over a live Microsoft Teams session so your team can watch the process in real time. If we find vulnerabilities, we write a tailored Remediation Plan. After the test, a confidential 60-minute Readout Meeting reviews the findings and the plan with your key people.

What Is Included

6 PARTS

Managed Vulnerability Assessment

Automated discovery, severity classification and a fix plan, on a schedule.

External Penetration Testing

A simulated attack on what faces the internet.

Internal Gray Box Testing

What an insider or stolen credentials could reach, watched live over Teams.

Remediation Plan

Practical guidance written for business leaders and IT.

Retest of Every Finding

A final report that marks each finding patched or unpatched.

Readout Meeting

A confidential 60-minute review with your key people.

Frequently Asked Questions

4 QUESTIONS
How often should we test?

Vulnerability scanning should run on a schedule, and many clients do a penetration test once a year or after a major change. Clients, insurers and frameworks may set their own cadence.

Will testing disrupt our business?

Scope, timing and exclusions are agreed in writing before anything starts, so testing avoids the systems and hours you name.

Is a penetration test the same as a CMMC or NIST SP 800-171 assessment?

No. A penetration test measures security. A CMMC or NIST SP 800-171 gap assessment scores your controls against the framework, and that is delivered by our Compliance Division, Capital Cyber Compliance.

Do you fix what you find?

Yes, if you want us to. Many clients have us remediate the findings and then retest; others hand the plan to their own IT team.

Related Services and Industries

Managed Security Monitoring (MDR and SOC)

Round the clock monitoring, detection and response from a security operations center.

Virtual CISO (vCISO)

Senior security leadership, a roadmap and governance, without a full-time hire.

Cyber Insurance Readiness

Know what your insurer requires, prove the controls are in place, and have the documents ready.

Network and Wi-Fi Management

Firewalls, switches and Wi-Fi configured, segmented and monitored, at one site or many.

For Accounting and CPA Firms

Managed IT and security for CPA firms, with the WISP and FTC Safeguards Rule in view.

For Government Contractors

IT support, managed security and CMMC experience for defense and federal suppliers.

For Dental Practices

Managed IT, managed security and HIPAA compliance management for dental practices and DSOs.

For Auto Repair Shops and Auto Groups

Managed IT, networks and security for repair shops and multi-location auto groups.

Scope a Test in 30 Minutes.

Pick a time. Tell us what you want tested and who will read the report.

Looking for CMMC? Our Compliance Division, Capital Cyber Compliance, delivers it.

Book a 30-Minute Call