Vulnerability assessment is the foundation layer of any credible security programme — it produces the prioritised list of known weaknesses an organisation is actually exposed to. For Johannesburg-based organisations, the discipline has to map to local operational realities (loadshedding-driven change windows, hybrid infrastructure, distributed branch operations) without losing the rigour of the underlying methodology. This article sets out what a useful assessment delivers.
The short answer
A credible vulnerability assessment covers external and internal attack surface, applies CVSS scoring with environmental context, prioritises findings by exploitability and business impact, and feeds a defined remediation programme. Findings are retested after remediation. The assessment is recurring, not a one-off deliverable.
Vulnerability management increasingly supports cyber insurance requirements, audit readiness, procurement assurance, and operational resilience — not just technical hygiene.
Discovery — knowing what you have before assessing it
Most assessments fail at discovery. The vulnerability scanner can only report on assets it knows about, and most organisations have more assets than the central inventory shows — shadow IT, forgotten hosts, decommissioned services that were never actually shut down. A defensible assessment starts with discovery — external attack-surface mapping, internal asset enumeration, cloud workload discovery — before any scanning.
CVSS scoring and the environmental context that matters
The Common Vulnerability Scoring System (CVSS) produces a base score from 0.0 to 10.0. The base score is necessary and insufficient — it does not know your environment. Environmental and temporal metrics adjust for exploitability in the wild, affected asset criticality, and existing compensating controls. A CVSS 9.8 on a decommissioned test box is not a 9.8 in practice; a CVSS 7.5 on the primary external-facing application may be. Prioritisation lives in the environmental layer.
External attack surface — what an attacker would see first
External assessment scans the perimeter as an attacker would — internet-facing applications, public APIs, VPN gateways, cloud workloads, and exposed developer infrastructure. For Johannesburg-headquartered organisations with branch operations across the country and the continent, the external perimeter is rarely cleanly defined. Continuous external attack-surface monitoring (rather than annual scanning) closes the gap.
Internal scanning — what an attacker would see next
Internal vulnerability scanning assumes initial access has been obtained and assesses what an attacker could escalate or move laterally towards. Internal scope covers servers, workstations, network infrastructure, Active Directory, and OT, where applicable. Findings here tend to be less dramatic than external CVE counts but more material — internal exposure determines how far an initial compromise spreads.
Modern assessments increasingly include cloud and SaaS exposure reviews, where misconfigurations and identity weaknesses often create externally exploitable attack paths.
Remediation, retest, and the recurring cycle
Vulnerability assessment without a remediation programme is theatre. A credible engagement delivers a prioritised remediation list with named owners and target dates, retests after remediation, and feeds findings into ongoing patch and vulnerability management. Most organisations benefit from quarterly external scanning, monthly internal scanning, and ad hoc rescans after material changes.
Mature vulnerability programmes prioritise remediation based on exploitability, business criticality, exposure, and operational impact rather than CVSS score alone.
Key Takeaways
- Most assessments fail at discovery — start with asset enumeration before scanning.
- CVSS base scores are necessary but insufficient — environmental context drives real prioritisation.
- External attack surface needs continuous monitoring, not annual scanning, for distributed organisations.
- Internal scope assesses lateral movement potential — typically more material than external CVE counts.
- Vulnerability assessment is part of a programme — discovery, scan, prioritise, remediate, retest, repeat.
How Cyber Resilience Can Help
Cyber Resilience helps organisations improve visibility, prioritisation, and remediation through structured vulnerability assessments aligned to operational risk and modern attack-surface realities.
Speak to our team to arrange a vulnerability assessment discussion.