GuideCyber Essentials PlusPDF · 3.7 MB

Vulnerability Assessment Guide for SMEs

Practical guide to understanding vulnerability scanning, interpreting CVSS scores, prioritising remediation, and meeting Cyber Essentials Plus scanning requirements.

About This Resource

Vulnerability scanning is a critical component of the Cyber Essentials Plus examination — and a fundamental security practice that every business should perform regularly. This guide explains what vulnerability scanning is, how it differs from penetration testing, what common vulnerabilities are typically found in SME environments, and how to interpret and prioritise scan results using the CVSS scoring system. It also covers recommended scanning tools, frequency best practices, and specifically how vulnerability assessment relates to Cyber Essentials Plus certification requirements.

What's Included

  • What is vulnerability scanning: definition, internal vs external, scanning vs pen testing
  • Common SME vulnerabilities: outdated software, weak passwords, missing patches, open ports
  • CVSS scoring explained: how to interpret Critical, High, Medium, and Low severity ratings
  • Remediation prioritisation: a practical framework for fixing vulnerabilities in the right order
  • Tools and frequency: recommended scanners and how often to run assessments
  • CE+ requirements: what assessors look for in vulnerability scanning results

Who Is This For?

IT managers, security teams, and business owners who need to understand vulnerability scanning fundamentals and how it relates to Cyber Essentials Plus certification.

Frequently asked questions

Vulnerability scanning is an automated process that identifies known weaknesses like missing patches or misconfigurations across your systems, typically run monthly or quarterly. Penetration testing involves a skilled tester actively attempting to exploit those weaknesses to assess real-world impact, usually conducted annually and at greater cost.

Most UK SMEs benefit from monthly internal and external scans as a baseline, with additional scans after major infrastructure changes such as new server deployments or firewall rule updates. Cyber Essentials Plus examination itself includes a vulnerability scan, so regular scanning beforehand helps avoid surprises on assessment day.

CVSS scores range from 0 to 10 and rate vulnerability severity, with Critical typically 9.0 and above, High 7.0 to 8.9, Medium 4.0 to 6.9, and Low below 4.0. Remediation priority should generally follow severity, but exploitability and whether a system is internet-facing also matter when deciding what to fix first.

Yes, this guide specifically covers how vulnerability scanning results are assessed during Cyber Essentials Plus examination, including which severity thresholds typically cause a fail and how to prioritise remediation in the run-up to certification.

Technology Stack

Powered by industry-leading technologies including SolarWinds, Cloudflare, BitDefender, AWS, Microsoft Azure, and Cisco Meraki to deliver secure, scalable, and reliable IT solutions.

SolarWinds
Cloudflare
BitDefender
AWS
Hono
Opus
Office 365
Microsoft
Cisco Meraki
Microsoft Azure

Latest Articles

4
  • Network Admin

Network Monitoring for UK Businesses: A Practical Guide to Spotting Problems Before Your Users Do in 2026

4 Sep, 2026

Most UK businesses do not discover a network problem from their monitoring platform. They discover it when the third person walks over to the IT desk and says...

Read more
3
  • IT Office Moves

The Hidden Costs of an Office Move: A UK Business Guide to Budgeting for IT Relocation in 2026

3 Sep, 2026

Almost every office move IT budget we see arrives at the same shape: a removals quote, a furniture allowance, a signage line, a contingency of ten per cent,...

Read more
2
  • IT Support

IT Support Response Times: A UK Business Guide to Setting SLAs That Actually Match Your Risk in 2026

2 Sep, 2026

An IT support SLA is the only part of a managed service contract that tells you what happens on the worst day of your year, and it is routinely the least...

Read more

Enquiry Received!

Thank you for getting in touch. A member of our team will review your enquiry and get back to you within 24 hours.