Where exactly is your business vulnerable?
Find out with our IT security check for SMEs before an attacker does.
Related topics
The Light Pen-Test: practical, quick, easy to understand
A targeted vulnerability assessment of your externally accessible IT systems. Carried out in just a few days and documented in a report.
Most companies do not know where their vulnerabilities lie
A comprehensive manual penetration test is thorough – but for many medium-sized companies, it is too expensive, too time-consuming or simply too complex for the issue at hand. At the same time, an automated scanner is often not enough to really understand where the critical vulnerabilities lie and which of them actually take priority.
Recon Scan – The Light Pentest for a Quick Security Overview
Recon Scan is our compact solution for providing a clear overview of your network’s IT security status in a short space of time. The name stands for Reconnaissance (Enlightenment) and Scan – because we’ll come directly to your premises with a specially configured device, connect it to your network and carry out a brief technical check tailored specifically to your environment.
The result: many companies operate on the basis of assumptions rather than facts. At the very latest when NIS2 or if a client requests specific evidence as part of an audit, this becomes a problem. With our report, you’ll know exactly where the vulnerabilities in your system lie.
We assess your internal and external systems, web applications, IP ranges and exposed services – specifically looking for known vulnerabilities, misconfigurations and attack surfaces that an attacker would be the first to find.
Unlike an automated scan report, we do not simply provide a list of CVE numbers, but rather a prioritised, clear assessment: what is critical, what can wait, and what this means in practical terms for your business.
IMPORTANT: Before the actual audit, we will work with you to determine which areas of your network are to be examined and which systems – such as particularly sensitive production facilities or medical equipment – are to be deliberately excluded.
What our IT security check covers:
We identify all active systems within the pre-agreed audit scope – including those that are unknown to your IT department or have not been documented. This so-called ‘shadow IT’ (e.g. devices connected independently, obsolete test systems or unofficial access points) often poses an underestimated risk in practice.
We assess your Active Directory environment for configuration vulnerabilities and attack vectors, such as those exploited by real-world attackers – including, amongst others:
- Vulnerable name resolution, which attackers on the network can use to steal credentials unnoticed
- High-risk authorisation structures, positions of trust and attack vectors within the domain that could be exploited to gradually escalate privileges (up to and including domain administration)
- Fundamental misconfigurations in services and shares that provide attackers with initial points of entry for deeper access
Detected systems are checked against up-to-date vulnerability databases to identify known security vulnerabilities (CVEs) and high-risk configurations.
Accessible web applications and servers are scanned for technologies, TLS/encryption settings and known vulnerabilities, including a check for publicly accessible, undocumented paths and endpoints.
Your domain will be checked for safeguards against email spoofing and phishing (SPF, DKIM, DMARC).
On request, we can also check what information about your company is publicly available and could be exploited by attackers.
What you get in the end
- A prioritised findings report, sorted by actual risk
- Concrete, actionable recommendations rather than raw technical data
- A brief explanation during the conversation, if desired
The Recon Scan/Light penetration test is ideal for Introduction, in order to get an initial realistic holistic Security status their IT infrastructure to obtain – and as a basis for further action.
The benefits for you
- Practical: We are thoroughly examining the vulnerabilities and attack paths that real attackers would exploit first – from insecure name resolution to risky permission structures within your domain.
- Completeness: Even undocumented systems (shadow IT) are identified and made visible
- Quick: Results in a short space of time rather than weeks of testing
- On-site The scan runs directly on your network – no complicated remote access setup is required
- Understood You’ll receive an executive summary written in plain language – for decision-makers, not just for IT experts
- Designed with safety in mind: Sensible systems (e.g. production facilities or medical devices) are specifically excluded in advance; release tests are low-risk by default
- Scalable: With a level of scrutiny tailored to your needs – from a quick check to a more in-depth brief analysis
And this is how it works
Scope clarification
We’ll have a brief discussion to clarify which systems are relevant and what needs to be checked.
Execution
The analysis will be carried out within the agreed timeframe, without disrupting your day-to-day operations.
Report on Findings
You will receive a clearly structured, prioritised report with concrete recommendations.
Context | Explanation
In a brief discussion, we’ll analyse the results and outline the next steps that make sense.
The Recon Scan is ideally suited as Introduction, in order to get an initial realistic holistic Security status their IT infrastructure to obtain – and as a basis for further action.
Clarity rather than speculation
You don't need to guess where your vulnerabilities lie. Let's clarify in a brief, no-obligation conversation whether and how a Recon Scan makes sense for your business.
RALPH DÖRFLER
Head of IT Security

