Vulnerability scanning is the automated discovery and ranking of weaknesses in the systems attackers can reach from the internet. Defensio runs it continuously from the cloud for your domains, IPs, web applications and APIs, with nothing to install, and turns each finding into a prioritised action plan and an audit-ready PDF report that a customer, insurer or NIS2 auditor can accept as evidence. Plans start at EUR 59/month and every record stays in Italian datacentres.
A vulnerability scan is an automated check of a system for known weaknesses: open ports and forgotten services, unpatched software with published CVEs, web application flaws, weak encryption, misconfigured DNS and mail records, default credentials. A vulnerability assessment is the wider exercise built around those scans: deciding what to test, running the scan, confirming and ranking what it finds, and producing a report with remediation steps.
External vulnerability scanning looks only at what is reachable from the public internet, which is the same view an attacker has. Continuous vulnerability assessment repeats that external scan on a schedule, so the picture is never older than the last cycle.
The Defensio cloud plan delivers exactly this: continuous external vulnerability scanning and assessment for any asset with a public IP or a DNS record. You add targets, the platform scans them from Fidem's own infrastructure, and you receive findings ranked by severity, exploitability and asset context, each with evidence and step-by-step remediation. One login, no software: a vulnerability scanner online in the literal sense.
It is not a manual penetration test: the scan finds and ranks issues across the external perimeter, it does not replace a professional attacking your systems by hand. How the two fit together is covered below.
A vulnerability assessment every six months is a photograph of yesterday's risks. New vulnerabilities are published every day, and a forgotten staging host or an expired certificate can appear between two annual checks without anyone noticing. Continuous vulnerability scanning keeps pace with that rate of change.
For an SME selling into the EU the pressure is no longer only technical. NIS2 Article 21(2) requires measures including policies on risk analysis (a), vulnerability handling and disclosure (e), assessment of the effectiveness of those measures (f) and asset management (i), as ongoing obligations, not as a once-a-year deliverable. Customers send questionnaires asking how often the perimeter is scanned, insurers ask for evidence of vulnerability management before renewal, and ISO 27001 auditors want findings tracked to closure.
A vulnerability scanning subscription answers all of those with the same data. Because the scan runs on a daily, weekly or monthly cadence, you always have a current report, a dated history of what was found and fixed, and a posture trend. That is managed vulnerability scanning in practice: the scanning runs without you operating it, and your team spends its time on remediation.
Every scanning capability is included on every plan. You pay for the number of targets and email addresses covered by credential breach monitoring, not for features.
Discovery of open ports, exposed services and unexpected access paths across your public IPs: remote desktop and SSH left reachable, database consoles, admin panels and other services that should never face the internet. Technology fingerprinting and HTTP probing identify what is actually running behind each port.
Dynamic application vulnerability scanning of websites, web applications and APIs for the OWASP Top 10 categories and beyond: injection, cross-site scripting, broken authentication, insecure APIs and further weakness classes. Active tests run only against assets you own and have authorised.
Known CVEs, missing patches, outdated software and weak configurations across servers, VPS instances, cloud-hosted services, mail servers, load balancers, firewalls and IoT gateways. Detection checks target specific CVEs, misconfigurations and exposure patterns.
Monitoring of credentials linked to your domain that surface in breach datasets, so a leaked password becomes a finding in your dashboard rather than an incident.
Continuous enumeration of subdomains surfaces forgotten hosts, staging and test environments and orphaned assets, and catches new exposures as they appear, so the external attack surface scan keeps pace with your organisation.
Cipher suites, protocol versions and certificate chains; SPF, DKIM and DMARC records and zone transfer exposure; missing security headers, insecure cookies and default credentials. These are the misconfigurations most often flagged in a customer questionnaire and the quickest to fix.
Findings are correlated and prioritised by weighing severity, exploitability and asset context together, not the score alone. On demand, AI-augmented offensive testing actively validates vulnerabilities, bridging the gap between scanning and penetration testing. All AI processing runs on Fidem-owned infrastructure in Italy with no external API calls, and, across the Defensio ecosystem, AI recommends while identifiable professionals decide.
The dashboard, database and scan results are hosted on ACN-certified Italian datacentres with ISO 27001, 27017 and 27018 certifications. No agent, no appliance, no software to maintain. Sign up online and start your first scan immediately.
The report is the reason most SMEs buy a vulnerability scan in the first place. Somebody asked for proof, and a screenshot of a dashboard is not proof.
Every finding in a Defensio report carries three things an assessor looks for: the severity, the evidence that produced it, and the remediation step that closes it. Reports are produced by Defensio Report, the reporting engine included with every plan: Executive, Technical and Custom documents, automatically generated, data-validated and delivered on schedule, or exported as PDF in one click whenever someone asks.
Who accepts it? A NIS2 auditor checking risk analysis and vulnerability handling under Article 21. An ISO 27001 auditor who wants a vulnerability scan for ISO 27001 controls with dated evidence of closure. An insurer asking for the last external scan. A customer's procurement team. Each gets a dated, evidence-backed document; whether it satisfies a specific policy or audit scope depends on that policy, and no scan alone can promise otherwise.
On the MSP plan, reports are white-labelled, so a provider can deliver them under its own name from a multi-tenant dashboard. The vendor behind the platform, Fidem S.r.l., is certified to ISO/IEC 27001, 27017, 27018 and ISO 9001, and Defensio is registered at CSA STAR Level 1; details, certifications and the answers to common security questionnaires are on the security and trust page.
Vulnerability assessment vs penetration testing is the question most buyers ask; they are different instruments. Continuous vulnerability scanning is automated, repeatable and always current: it tells you, every cycle, what is exposed and how badly. A penetration test is a manual, point-in-time exercise in which security professionals chain weaknesses together the way a real attacker would, including logic flaws no scanner can reason about.
Defensio is the always-on baseline. It does not replace a manual penetration test; it makes the test more useful, because the obvious findings are already closed before the professionals start, and it fills the months between tests with current evidence. The table below summarises the difference, including the one-off vulnerability assessment many SMEs buy today.
| Criterion | Continuous vulnerability scanning (Defensio) | One-off vulnerability assessment | Manual penetration test |
|---|---|---|---|
| Method | Automated, with AI-assisted correlation and on-demand validation of findings | Automated scan run once, ranked by hand | Manual, performed by security professionals |
| Frequency | Daily, weekly or monthly, plus on demand | Point in time, typically annual or six-monthly | Point in time, typically annual |
| Coverage | Everything with a public IP or DNS record, including newly discovered subdomains | The asset list agreed at the start | The scope agreed in the engagement |
| Installation | None, works from the outside | None | None, may include credentials or on-site access |
| Output | Prioritised action plan, audit-ready PDF on schedule, posture over time | Single report | Single report with exploited findings |
| Best for | Ongoing evidence for NIS2, ISO 27001, insurers and customers | A snapshot before a specific deadline | Depth on critical systems, logic flaws |
| Price | From EUR 59/month, VAT excluded | Per engagement | Per engagement |
Three plans, VAT excluded, all with every scanning capability included: Starter at EUR 59/month, Professional at EUR 149/month, and MSP from EUR 299/month. What changes between plans is scale and integration, not what the scan can find.
Add-on packs extend targets and email addresses on any plan without an upgrade. Custom deployment, volume licensing and an on-premise option are available if you contact us.
All scanning capabilities included on every plan. No feature gates. Pay for scale, not capability.
Everything in Starter, plus:
Everything in Professional, plus:
Add capacity to any plan — no upgrade required. Click a plan above to select it.
Need a custom deployment, volume licensing, or on-premise option? Contact us.
Vulnerability scanning for small business used to mean an annual consultant's report. With a monthly plan you get continuous coverage of the public perimeter, a current report whenever a customer, insurer or auditor asks, and a remediation list your IT team or provider can act on. For NIS2 vulnerability-handling obligations (Art. 21(2)(e)), the scan covers the external technical side and the report documents it.
Vulnerability assessment for MSPs has to scale across clients without scaling headcount. The MSP plan groups targets by client, separates tenants in one dashboard, delivers white-label reports and exposes the API and webhooks so scan results feed your existing workflows. Providers who prefer to run the engine on their own servers and bill it on can choose on-premise external attack surface management with Defensio XT instead.
Trigger a scan from the pipeline and consume the results programmatically through the API and webhooks, so a new critical finding reaches your own release process. Application vulnerability scanning and network vulnerability scanning share the same targets, so an accidentally exposed staging host shows up alongside the web application flaw.
External scanning is one layer. For visibility inside the network, the passive network sensor works from a mirrored copy of traffic; for analysts watching the alerts, SOC as a service; for the domain and mail side of the perimeter, email spoofing protection. Each is a separate product and none is required to run the scan.
Team Fidem S.r.l.
An automated vulnerability scan of everything reachable from the public internet, domains, IPs, web applications and APIs, repeated on a schedule instead of once a year. Defensio runs it from the cloud, ranks each finding by severity, exploitability and asset context, and keeps a dated history, so the report you hand over is never older than the last cycle.
No. The scan works entirely from the outside, the way an attacker sees you. Nothing is installed on the systems being scanned and there is no software to maintain; you only need to own the assets or hold explicit authorisation to test them. Setup is a login and a list of targets.
You choose the cadence: daily, weekly or monthly, plus on-demand scans whenever you need a current result, for example after a deployment or before an audit. Scans are unlimited on every plan, and from Professional they can be triggered from a CI/CD pipeline through the API.
It provides the evidence auditors and insurers ask for: a dated PDF report with severity, evidence and remediation for each finding, plus a history showing findings tracked to closure. Whether that satisfies a particular policy or audit scope depends on the policy and the scope; the scan documents your external vulnerability management, it does not certify you.
Usually both, at different frequencies. Continuous vulnerability scanning is the always-on baseline that finds and ranks exposed weaknesses every cycle. A penetration test is a manual, point-in-time exercise by security professionals who chain weaknesses together and find logic flaws no scanner reasons about. Defensio does not replace a manual pentest; it closes the obvious findings first and covers the months between tests.
Starter is EUR 59/month, Professional EUR 149/month and MSP from EUR 299/month, VAT excluded. Every scanning capability is on every plan; what changes is the number of targets and email addresses, API and CI/CD access from Professional, and white-label reports with a multi-tenant dashboard on MSP.
Exclusively in the EU. Dashboard, database and scan results are hosted on ACN-certified Italian datacentres (ISO 9001, 27001, 27017, 27018); the scanning engines run on Fidem's ISO 27001:2022 certified infrastructure in Italy. AI processing runs on Fidem-owned infrastructure with no external API calls, and no customer data is shared with third parties.
Yes. Defensio XT is the same external scanning delivered as a standalone engine on your own VPS, dedicated server or cloud node, with full operational and data control and no cloud platform required. Choose the hosted platform for monitoring immediately with nothing to run; choose XT when you manage security internally or bill it on as a provider.
Add your domains and IPs, start scanning and export a dated, evidence-backed report as soon as the first scan completes. Plans from EUR 59/month, VAT excluded, every capability included, data in Italian datacentres. You can start your first scan now, or contact us for MSP volumes, custom deployment or the on-premise engine.