GuideCyber Essentials PlusPDF · 3.7 MB

Vulnerability Assessment Guide for SMEs

Practical guide to understanding vulnerability scanning, interpreting CVSS scores, prioritising remediation, and meeting Cyber Essentials Plus scanning requirements.

About This Resource

Vulnerability scanning is a critical component of the Cyber Essentials Plus examination — and a fundamental security practice that every business should perform regularly. This guide explains what vulnerability scanning is, how it differs from penetration testing, what common vulnerabilities are typically found in SME environments, and how to interpret and prioritise scan results using the CVSS scoring system. It also covers recommended scanning tools, frequency best practices, and specifically how vulnerability assessment relates to Cyber Essentials Plus certification requirements.

What's Included

  • What is vulnerability scanning: definition, internal vs external, scanning vs pen testing
  • Common SME vulnerabilities: outdated software, weak passwords, missing patches, open ports
  • CVSS scoring explained: how to interpret Critical, High, Medium, and Low severity ratings
  • Remediation prioritisation: a practical framework for fixing vulnerabilities in the right order
  • Tools and frequency: recommended scanners and how often to run assessments
  • CE+ requirements: what assessors look for in vulnerability scanning results

Who Is This For?

IT managers, security teams, and business owners who need to understand vulnerability scanning fundamentals and how it relates to Cyber Essentials Plus certification.

Frequently asked questions

Vulnerability scanning is an automated process that identifies known weaknesses like missing patches or misconfigurations across your systems, typically run monthly or quarterly. Penetration testing involves a skilled tester actively attempting to exploit those weaknesses to assess real-world impact, usually conducted annually and at greater cost.

Most UK SMEs benefit from monthly internal and external scans as a baseline, with additional scans after major infrastructure changes such as new server deployments or firewall rule updates. Cyber Essentials Plus examination itself includes a vulnerability scan, so regular scanning beforehand helps avoid surprises on assessment day.

CVSS scores range from 0 to 10 and rate vulnerability severity, with Critical typically 9.0 and above, High 7.0 to 8.9, Medium 4.0 to 6.9, and Low below 4.0. Remediation priority should generally follow severity, but exploitability and whether a system is internet-facing also matter when deciding what to fix first.

Yes, this guide specifically covers how vulnerability scanning results are assessed during Cyber Essentials Plus examination, including which severity thresholds typically cause a fail and how to prioritise remediation in the run-up to certification.

Technology Stack

Powered by industry-leading technologies including SolarWinds, Cloudflare, BitDefender, AWS, Microsoft Azure, and Cisco Meraki to deliver secure, scalable, and reliable IT solutions.

SolarWinds
Cloudflare
BitDefender
AWS
Hono
Opus
Office 365
Microsoft
Cisco Meraki
Microsoft Azure

Latest Articles

9
  • Google Ads & PPC

Google Ads Attribution: A UK Business Guide to Understanding Which Campaigns Actually Drive Sales in 2026

9 Sep, 2026

Every UK business running paid search eventually has the same meeting. Someone opens the Google Ads interface, sorts the campaign list by conversions, points...

Read more
8
  • SEO

Technical SEO Audit: A UK Business Guide to Finding and Fixing the Issues Killing Your Rankings in 2026

8 Sep, 2026

There is a particular kind of frustration that shows up in UK marketing meetings about eighteen months into a content programme. The blog is publishing...

Read more
7
  • Web Development

Website Accessibility Compliance: A UK Business Guide to Meeting WCAG 2.2 and Avoiding Legal Risk in 2026

7 Sep, 2026

Most UK businesses discover the state of their website accessibility in one of three ways: a customer complaint, a procurement questionnaire they cannot answer...

Read more

Enquiry Received!

Thank you for getting in touch. A member of our team will review your enquiry and get back to you within 24 hours.