Continuous vulnerability scanning for your internet-facing assets

Vulnerability scanning is the automated discovery and ranking of weaknesses in the systems attackers can reach from the internet. Defensio runs it continuously from the cloud for your domains, IPs, web applications and APIs, with nothing to install, and turns each finding into a prioritised action plan and an audit-ready PDF report that a customer, insurer or NIS2 auditor can accept as evidence. Plans start at EUR 59/month and every record stays in Italian datacentres.

What is vulnerability scanning (and a vulnerability assessment)

A vulnerability scan is an automated check of a system for known weaknesses: open ports and forgotten services, unpatched software with published CVEs, web application flaws, weak encryption, misconfigured DNS and mail records, default credentials. A vulnerability assessment is the wider exercise built around those scans: deciding what to test, running the scan, confirming and ranking what it finds, and producing a report with remediation steps.

External vulnerability scanning looks only at what is reachable from the public internet, which is the same view an attacker has. Continuous vulnerability assessment repeats that external scan on a schedule, so the picture is never older than the last cycle.

The Defensio cloud plan delivers exactly this: continuous external vulnerability scanning and assessment for any asset with a public IP or a DNS record. You add targets, the platform scans them from Fidem's own infrastructure, and you receive findings ranked by severity, exploitability and asset context, each with evidence and step-by-step remediation. One login, no software: a vulnerability scanner online in the literal sense.

It is not a manual penetration test: the scan finds and ranks issues across the external perimeter, it does not replace a professional attacking your systems by hand. How the two fit together is covered below.

Why continuous, not one-off

A vulnerability assessment every six months is a photograph of yesterday's risks. New vulnerabilities are published every day, and a forgotten staging host or an expired certificate can appear between two annual checks without anyone noticing. Continuous vulnerability scanning keeps pace with that rate of change.

For an SME selling into the EU the pressure is no longer only technical. NIS2 Article 21(2) requires measures including policies on risk analysis (a), vulnerability handling and disclosure (e), assessment of the effectiveness of those measures (f) and asset management (i), as ongoing obligations, not as a once-a-year deliverable. Customers send questionnaires asking how often the perimeter is scanned, insurers ask for evidence of vulnerability management before renewal, and ISO 27001 auditors want findings tracked to closure.

A vulnerability scanning subscription answers all of those with the same data. Because the scan runs on a daily, weekly or monthly cadence, you always have a current report, a dated history of what was found and fixed, and a posture trend. That is managed vulnerability scanning in practice: the scanning runs without you operating it, and your team spends its time on remediation.

What the scan covers

Every scanning capability is included on every plan. You pay for the number of targets and email addresses covered by credential breach monitoring, not for features.

External perimeter and network vulnerability scanning

Discovery of open ports, exposed services and unexpected access paths across your public IPs: remote desktop and SSH left reachable, database consoles, admin panels and other services that should never face the internet. Technology fingerprinting and HTTP probing identify what is actually running behind each port.

Web application and API vulnerability scanning

Dynamic application vulnerability scanning of websites, web applications and APIs for the OWASP Top 10 categories and beyond: injection, cross-site scripting, broken authentication, insecure APIs and further weakness classes. Active tests run only against assets you own and have authorised.

Infrastructure vulnerability assessment

Known CVEs, missing patches, outdated software and weak configurations across servers, VPS instances, cloud-hosted services, mail servers, load balancers, firewalls and IoT gateways. Detection checks target specific CVEs, misconfigurations and exposure patterns.

Credential breach monitoring

Monitoring of credentials linked to your domain that surface in breach datasets, so a leaked password becomes a finding in your dashboard rather than an incident.

Subdomain and shadow IT discovery

Continuous enumeration of subdomains surfaces forgotten hosts, staging and test environments and orphaned assets, and catches new exposures as they appear, so the external attack surface scan keeps pace with your organisation.

SSL/TLS, DNS and email configuration

Cipher suites, protocol versions and certificate chains; SPF, DKIM and DMARC records and zone transfer exposure; missing security headers, insecure cookies and default credentials. These are the misconfigurations most often flagged in a customer questionnaire and the quickest to fix.

AI-assisted correlation and validation

Findings are correlated and prioritised by weighing severity, exploitability and asset context together, not the score alone. On demand, AI-augmented offensive testing actively validates vulnerabilities, bridging the gap between scanning and penetration testing. All AI processing runs on Fidem-owned infrastructure in Italy with no external API calls, and, across the Defensio ecosystem, AI recommends while identifiable professionals decide.

How it works in four steps

  1. Add targets. Enter domains, IP addresses and web applications in the dashboard and group them by business unit, client or region. Nothing is installed on the systems being scanned; you only need to own the assets or hold explicit authorisation to test them.
  2. Run scans. Launch an on-demand scan or set a daily, weekly or monthly schedule. Scans run in the cloud on Fidem's ISO 27001:2022 and ISO 9001:2015 certified infrastructure and push results securely to the hosted platform. From the Professional plan, scans can also be triggered from a CI/CD pipeline through the API.
  3. Remediate. Work through the prioritised action plan. Each finding carries its evidence and step-by-step remediation; assign it to a colleague, track ownership and re-scan to verify the fix.
  4. Track progress. Watch posture over time, export the report and hand it to whoever asked for it: the auditor, the insurer, the customer's procurement team or your own board.

The dashboard, database and scan results are hosted on ACN-certified Italian datacentres with ISO 27001, 27017 and 27018 certifications. No agent, no appliance, no software to maintain. Sign up online and start your first scan immediately.

The report: what auditors, insurers and customers accept

The report is the reason most SMEs buy a vulnerability scan in the first place. Somebody asked for proof, and a screenshot of a dashboard is not proof.

Every finding in a Defensio report carries three things an assessor looks for: the severity, the evidence that produced it, and the remediation step that closes it. Reports are produced by Defensio Report, the reporting engine included with every plan: Executive, Technical and Custom documents, automatically generated, data-validated and delivered on schedule, or exported as PDF in one click whenever someone asks.

Who accepts it? A NIS2 auditor checking risk analysis and vulnerability handling under Article 21. An ISO 27001 auditor who wants a vulnerability scan for ISO 27001 controls with dated evidence of closure. An insurer asking for the last external scan. A customer's procurement team. Each gets a dated, evidence-backed document; whether it satisfies a specific policy or audit scope depends on that policy, and no scan alone can promise otherwise.

On the MSP plan, reports are white-labelled, so a provider can deliver them under its own name from a multi-tenant dashboard. The vendor behind the platform, Fidem S.r.l., is certified to ISO/IEC 27001, 27017, 27018 and ISO 9001, and Defensio is registered at CSA STAR Level 1; details, certifications and the answers to common security questionnaires are on the security and trust page.

Vulnerability scanning vs penetration testing

Vulnerability assessment vs penetration testing is the question most buyers ask; they are different instruments. Continuous vulnerability scanning is automated, repeatable and always current: it tells you, every cycle, what is exposed and how badly. A penetration test is a manual, point-in-time exercise in which security professionals chain weaknesses together the way a real attacker would, including logic flaws no scanner can reason about.

Defensio is the always-on baseline. It does not replace a manual penetration test; it makes the test more useful, because the obvious findings are already closed before the professionals start, and it fills the months between tests with current evidence. The table below summarises the difference, including the one-off vulnerability assessment many SMEs buy today.

CriterionContinuous vulnerability scanning (Defensio)One-off vulnerability assessmentManual penetration test
MethodAutomated, with AI-assisted correlation and on-demand validation of findingsAutomated scan run once, ranked by handManual, performed by security professionals
FrequencyDaily, weekly or monthly, plus on demandPoint in time, typically annual or six-monthlyPoint in time, typically annual
CoverageEverything with a public IP or DNS record, including newly discovered subdomainsThe asset list agreed at the startThe scope agreed in the engagement
InstallationNone, works from the outsideNoneNone, may include credentials or on-site access
OutputPrioritised action plan, audit-ready PDF on schedule, posture over timeSingle reportSingle report with exploited findings
Best forOngoing evidence for NIS2, ISO 27001, insurers and customersA snapshot before a specific deadlineDepth on critical systems, logic flaws
PriceFrom EUR 59/month, VAT excludedPer engagementPer engagement

Pricing

Three plans, VAT excluded, all with every scanning capability included: Starter at EUR 59/month, Professional at EUR 149/month, and MSP from EUR 299/month. What changes between plans is scale and integration, not what the scan can find.

Add-on packs extend targets and email addresses on any plan without an upgrade. Custom deployment, volume licensing and an on-premise option are available if you contact us.

Simple, transparent pricing

All scanning capabilities included on every plan. No feature gates. Pay for scale, not capability.

Monthly Annual 2 months included

Starter

€59/mo
  • 5 targets (domains & IPs)
  • 5 email addresses
  • Scheduled scans & email alerts
  • Audit-ready reports
Subscribe Now

MSP

€299+/mo

Everything in Professional, plus:

  • 20–250 targets (domains & IPs)
  • 50–500 email addresses
  • White-label reports
  • Multi-tenant dashboard
Configure Plan

Need more targets?

Add capacity to any plan — no upgrade required. Click a plan above to select it.

+5 Targets (domains or IPs) €12/mo per pack
0
+10 Email addresses €10/mo per pack
0

Need a custom deployment, volume licensing, or on-premise option? Contact us.

Included in every plan:

✓ External Perimeter Scanning ✓ Web App Scanning (DAST) ✓ CVE Vulnerability Scanning ✓ Data Leak Monitoring ✓ Subdomain Enumeration ✓ HTTP Fingerprinting ✓ TLS/SSL Auditing ✓ DNS & Email Security ✓ Template-Based Detection ✓ Proprietary Testing Tools ✓ AI-Powered Correlation ✓ AI-Augmented Offensive Testing ✓ Continuous Threat Monitoring ✓ Remediation Guidance ✓ Instant Setup (No Agents) ✓ Unlimited Scans ✓ AI-Powered Risk Prioritization ✓ Add-On Packs to Scale

Who it is for

IT managers and owners of SMEs

Vulnerability scanning for small business used to mean an annual consultant's report. With a monthly plan you get continuous coverage of the public perimeter, a current report whenever a customer, insurer or auditor asks, and a remediation list your IT team or provider can act on. For NIS2 vulnerability-handling obligations (Art. 21(2)(e)), the scan covers the external technical side and the report documents it.

Managed service providers

Vulnerability assessment for MSPs has to scale across clients without scaling headcount. The MSP plan groups targets by client, separates tenants in one dashboard, delivers white-label reports and exposes the API and webhooks so scan results feed your existing workflows. Providers who prefer to run the engine on their own servers and bill it on can choose on-premise external attack surface management with Defensio XT instead.

Web agencies, software houses and DevOps teams

Trigger a scan from the pipeline and consume the results programmatically through the API and webhooks, so a new critical finding reaches your own release process. Application vulnerability scanning and network vulnerability scanning share the same targets, so an accidentally exposed staging host shows up alongside the web application flaw.

Organisations building a wider programme

External scanning is one layer. For visibility inside the network, the passive network sensor works from a mirrored copy of traffic; for analysts watching the alerts, SOC as a service; for the domain and mail side of the perimeter, email spoofing protection. Each is a separate product and none is required to run the scan.

Author

Team Fidem S.r.l.

Frequently asked questions

What is continuous external vulnerability scanning?

An automated vulnerability scan of everything reachable from the public internet, domains, IPs, web applications and APIs, repeated on a schedule instead of once a year. Defensio runs it from the cloud, ranks each finding by severity, exploitability and asset context, and keeps a dated history, so the report you hand over is never older than the last cycle.

Do I need to install agents?

No. The scan works entirely from the outside, the way an attacker sees you. Nothing is installed on the systems being scanned and there is no software to maintain; you only need to own the assets or hold explicit authorisation to test them. Setup is a login and a list of targets.

How often are assets scanned?

You choose the cadence: daily, weekly or monthly, plus on-demand scans whenever you need a current result, for example after a deployment or before an audit. Scans are unlimited on every plan, and from Professional they can be triggered from a CI/CD pipeline through the API.

Is a vulnerability scan enough for cyber insurance or ISO 27001?

It provides the evidence auditors and insurers ask for: a dated PDF report with severity, evidence and remediation for each finding, plus a history showing findings tracked to closure. Whether that satisfies a particular policy or audit scope depends on the policy and the scope; the scan documents your external vulnerability management, it does not certify you.

Vulnerability scanning vs penetration testing: which do I need?

Usually both, at different frequencies. Continuous vulnerability scanning is the always-on baseline that finds and ranks exposed weaknesses every cycle. A penetration test is a manual, point-in-time exercise by security professionals who chain weaknesses together and find logic flaws no scanner reasons about. Defensio does not replace a manual pentest; it closes the obvious findings first and covers the months between tests.

How much does continuous vulnerability scanning cost?

Starter is EUR 59/month, Professional EUR 149/month and MSP from EUR 299/month, VAT excluded. Every scanning capability is on every plan; what changes is the number of targets and email addresses, API and CI/CD access from Professional, and white-label reports with a multi-tenant dashboard on MSP.

Where is my data stored?

Exclusively in the EU. Dashboard, database and scan results are hosted on ACN-certified Italian datacentres (ISO 9001, 27001, 27017, 27018); the scanning engines run on Fidem's ISO 27001:2022 certified infrastructure in Italy. AI processing runs on Fidem-owned infrastructure with no external API calls, and no customer data is shared with third parties.

Can I run the scanning engine on my own infrastructure?

Yes. Defensio XT is the same external scanning delivered as a standalone engine on your own VPS, dedicated server or cloud node, with full operational and data control and no cloud platform required. Choose the hosted platform for monitoring immediately with nothing to run; choose XT when you manage security internally or bill it on as a provider.

Prove your perimeter is under control

Add your domains and IPs, start scanning and export a dated, evidence-backed report as soon as the first scan completes. Plans from EUR 59/month, VAT excluded, every capability included, data in Italian datacentres. You can start your first scan now, or contact us for MSP volumes, custom deployment or the on-premise engine.