Security scans

A finding that
leads to action

A scan that nobody evaluates improves nothing. That is why we manage the testing and deliver a report with a catalogue of measures – and, on request, technical support with the fixes and a re-test.

ISO 27001 based on BSI IT-GrundschutzData centres in Germany24/7/365 operation and support

Security testing

What we test

Raise the security of your IT environment with regular security scans and penetration tests. We manage your security testing and produce detailed reports with recommended actions. We offer the following services:

  • Vulnerability and compliance scans: our vulnerability management (VM) and policy compliance (PC) scans check server instances for vulnerabilities and for compliance with security standards. The results allow an assessment of the system configuration and the level of security.
  • Penetration tests: pentests check how well your infrastructure holds up against different attack vectors. Targeted attacks identify weaknesses, and concrete steps to fix them are initiated.
  • Reports and catalogue of measures: the results of the scans and pentests are summarised in a report, including a catalogue of measures for eliminating the security problems found. Once the measures are implemented, a repeat test is advisable.

We also offer technical support with fixing the vulnerabilities found. Regular testing is advisable because attack methods keep changing.

Managed Openshift - kyberio

What comes next

Dealing with findings

Firewall, WAF & NGF

Many findings can be intercepted further upstream until the application itself has been brought up to date.

To firewall, WAF & NGF

BaaS & DRaaS

A tested, immutable backup is the way back if something does get through.

To BaaS & DRaaS

Security concept

How we secure our own data centres and processes is set out in our security concept.

To the security concept

Frequently asked questions about security scans

What is the difference between a scan and a penetration test?

A scan tests automatically and across the board: it compares your systems with known vulnerabilities and with requirements from security standards. A penetration test goes into depth in a targeted way and tries to actually exploit the weak points found. The scan shows where there could be a problem; the pentest shows which of those really hold.

How often should testing be done?

Regularly – because attack methods change and because every change to your environment can open new gaps. A sensible rhythm depends on how often your systems change and which requirements you are subject to.

What happens to the findings?

They are listed in the report, ordered by urgency, together with a catalogue of measures. On request, we provide technical support with the fixes and test again afterwards.

Are production systems tested?

Only by agreement and within a set time window. We put scope, depth and exceptions in writing beforehand – a test without this agreement is a risk to operations.

Who does the testing — kyberio or a partner?

We run the vulnerability scans. A genuine penetration test is carried out by a specialist partner: it involves manual work, methodology and a report that will stand up to audit — a craft of its own, not a variation on a scan. We put you in touch.

What response times do you commit to?

We monitor around the clock, every day of the year. How quickly we intervene and through which escalation stages is set out in your contract — a time we have not committed to is not a time we state here.

Satisfied customers

HornetsecurityIT-PHACONWOLFFAutoDoELAINE technologiesZEDALMAJA.cloudSDV SystemeAucotecPARATFP SignHyperspaceAttinaTutaElectronic Arts

Sovereignty

Paving the way for digital sovereignty

ISO 27001 based on BSI IT-Grundschutz, BSI-IGZ-0552-2023
BSI-IGZ-0552-2023 ISO 27001 based on BSI IT-Grundschutz Scope: all data centers and all cloud services Security concept
  • Owner-managed since 1997

    As an owner-managed operator with our own data centers, we make our decisions independently and are subject exclusively to German / EU law.

  • 100% made in Germany

    Our data center, product development, and customer support are all based in Germany for your digital sovereignty.

  • 24/7 Customer Support

    We are here for you: 24/7/365 customer support, in English and German

Let us find the right solution together

We take the time to understand what you need and to develop solutions that fit. We explain complicated technical matters clearly and precisely as we go. Get in touch with me directly and we will work it out.

  • We will get back to you as soon as we can.
  • No obligation, free of charge.

How we process your details is explained in our privacy notice.