Summary
Features
Our 24/7 scan technicians quickly help you remediate identified vulnerabilities
Achieve network security
We help our customers achieve external network security by keeping up with the most current list of vulnerabilities, finely tuning our scan engines to expose weakness, and providing extensive support.
Get PCI compliant
A SecurityMetrics Security Specialist helps identify your PCI requirements before scanning. You are given a Payment Card Industry validation type and then placed on an automated scanning schedule to ensure you meet PCI deadlines.
Know how to resolve issues with extensive support
Meeting compliance deadlines and knowing exactly how to fix discovered vulnerabilities can be difficult. SecurityMetrics employs a 24/7 technical support staff for its customers. The support department helps customers understand vulnerabilities and provides assistance to close the most threatening gaps.
Discover external vulnerabilities
If left unprotected, thousands of potential entry points on a business network are available for criminals to exploit. As new ways to access these entry points are invented daily, checking your external business network for vulnerabilities is crucial.
Rely on a reliable security partnership
A partnership with SecurityMetrics lends years of data security and compliance expertise to your business. Our extensive knowledge and comprehensive services relieve the stress of cyber security and compliance requirements.
Get simplified vulnerability reporting
SecurityMetrics reports on all discovered vulnerabilities including security holes that could enable backdoors, buffer overflows, denial of service, and other types of malicious attacks. It’s web application scanning even discovers SQL injection issues specific to your website programming.
Which vulnerability scan is right for you?
SecurityMetrics employs a 24/7 technical support staff for scan customers
Perimeter Scan
Perimeter Scan lets you swap scan targets according to your dynamically changing environment, making mass-IP management easy.
SecurityMetrics Perimeter Scan is credit based, so you can buy the amount of scan credits you need to use at your discretion and in your timeline.
PERIMETER SCAN (CREDIT-BASED)
- Ideal for Adding and Removing Targets
- Ideal for a Larger Organization/Multiple IPs
- More Flexibility and Customization for Your Scanning Needs
- Great For PCI, HIPAA, GDPR, and General Security
- Manual Scanning Option
- Detailed Scanning Reports
- Can Be Used For PCI Compliance
- 24/7 Support For False Positives with Help Within 48 Hours
ASV Scan
SecurityMetrics ASV scan, also known as a PCI approved scanning vendor scan, identifies top risks (such as misconfigured firewalls, malware hazards, remote access vulnerabilities) and can be used for cyber security, PCI DSS compliance, or other security mandates.
ASV Scan lets you perform unlimited rescans during your contract.
ASV SCAN (UNLIMITED SCANS):
- Manual Scanning Option
- Detailed Scanning Reports
- Can Be Used For PCI Compliance
- 24/7 Support For False Positives with Help Within 48 Hours
Get a comprehensive Vulnerability Assessment Scan
SecurityMetrics External Vulnerability Assessment Scan helps you stay ahead of cyber criminals. Our regularly updated scan engine identifies external network vulnerabilities so you can keep your data safe. External vulnerability scanning identifies top risks such as misconfigured firewalls, malware hazards, remote access vulnerabilities, and can be used for cyber security or compliance mandates like PCI DSS and HIPAA.
Keep your scans organized
For an organization with a high volume of scan targets, keeping port scans organized can be a challenge.
Our external vulnerability assessment tools allow you to group and label scan targets to make it easier to manage by location, network type, or unique circumstances at your organization.
Scan targets on our schedule
SecurityMetrics Perimeter Scan allows you to test the scan targets you want, when you want. Run port scans on your most sensitive targets more frequently, test in scope PCI targets quarterly, or test designated IPs after changes to your network with simplicity.
Perimeter Scan even provides the flexibility to create and manage your own schedule on a group level.
Review scan results
Each network scan produces a summary report with identified vulnerabilities. Vulnerability scanning reports list the target, vulnerability type, service (e.g., https, MySQL, etc.), and the severity of each vulnerability (low, medium, high).
Reports can be downloaded in PDF or an excel file that can be sorted by columns to help in remediation efforts.
Identify external network vulnerabilities, so you can keep your data safe.
Start scanning for vulnerabilities
Request A QuoteExternal Vulnerability Scanning (ASV) FAQs
What is an ASV Scan?
ASV stands for “Approved Scanning Vendor.” The Payment Card Industry Data Security Standard (PCI DSS) requirement 11.2.2 calls for regular vulnerability scanning from an ASV.
These are vendors with scanning solutions that have been tested, approved, and added to a list of approved solutions that can help fulfill this PCI compliance requirement. Learn about what qualities to look for in an ASV.
What does a vulnerability scan do?
An external vulnerability scan is performed outside of your network (e.g., at your network perimeter), identifying known exploitable weaknesses in a network.
When am I required to scan?
The PCI SSC requires a vulnerability scan to be performed minimally every three months or after any significant network change (i.e., add/remove network device, updates to segmentation rules).
What IP addresses or domains need to be scanned?
Any Internet-facing connection that processes, stores, or transmits cardholder data. This includes IP addresses that are used in the event of a failover or backup.
My vendor said my hardware was PCI compliant. Do I still need to validate compliance?
Yes, you will still need to validate compliance. There is more to PCI compliance than just the hardware you use. Using tested and secure hardware for credit card processing, viewing, and storing are important aspects of PCI Compliance, but those are only a few.
Credit card information is often compromised through the lack of secure connections and other misconfigured connections to that secure hardware. Scanning will help identify vulnerabilities to be fixed.
Resources
The following are related resources that we have prepared for you. Find more answers to your questions in our Learning Center.