Orca IT Solutions

Vulnerability Testing & Assessment

Find the holes before someone else does

We scan what the internet can see, then we scan what a logged-in user can see, because those are two very different attack surfaces. Every finding gets ranked by how exploitable it actually is in your environment, not by a generic score. You end up with a short list of fixes in priority order and a re-scan that proves they closed.

🛡 Ranked Findings Re-scan Included💰 Never Outsourced Plain English Reports

Overview

A scan is only useful if it ends in a fix list

Most vulnerability reports die in a folder. Ours is built backward from the remediation work, so the output is a job list with owners and dates.

A vulnerability assessment answers a narrow, valuable question: what known weaknesses exist in your environment right now, and which of them could realistically be used against you. We answer it in two passes. The external pass looks at every public IP, published DNS record and open port you own, the firewall, the mail gateway, the VPN concentrator, the web server somebody stood up in 2019 and forgot. The internal pass runs from inside the LAN with credentials, because an attacker who phishes one user is already inside and sees a completely different picture.

What the external pass actually looks for

Exposed management interfaces are the first thing we hunt. RDP on 3389 forwarded straight to a server is still the single most common finding we make on a first assessment in the East Valley, usually left over from a pandemic-era port forward. After that: VPN appliances running firmware with published CVEs, TLS endpoints still offering deprecated ciphers or a certificate that expired last quarter, mail servers missing SPF, DKIM and DMARC records, and forgotten subdomains pointing at services nobody pays for anymore.

  • Full TCP port sweep and service fingerprinting on every public IP
  • Firmware and version checks against current CVE data for firewall, VPN and NAS
  • TLS, certificate and mail authentication review including DMARC alignment
  • Credential exposure checks against known breach corpora for your domain

What the internal pass finds that the external one cannot

Inside, we run credentialed scans so the tool reads actual patch levels instead of guessing from banners. That surfaces the unglamorous problems that do the real damage: third-party software nobody patches (Java runtimes, Adobe Reader, old Chrome builds), workstations missing two quarters of cumulative updates because the reboot never happened, SMB signing disabled, LLMNR and NBT-NS still answering and happily handing out hashes, local admin rights on every user account, and service accounts with passwords set in 2016 and never rotated.

We also review Active Directory hygiene in the same engagement: stale computer objects, accounts with Kerberos pre-authentication disabled, service principal names attached to weak-password accounts, domain admins who should be standard users, and a password policy that technically passes but practically does not. If you are running end-of-life software, Server 2012 R2, an old SQL instance, Windows 10 machines past their support date, it gets called out with a replacement path, not just a red row.

Every finding lands in a ranked list. Ranking is not raw CVSS. A critical on an isolated lab box that cannot reach the internet ranks below a medium on the terminal server your whole team logs into. We weight by exploitability, exposure and blast radius, then we tell you what it takes to fix each one in hours and parts. You can hand that list to us, to your existing IT person, or to a vendor. Thirty days later we re-scan and confirm what actually closed. That loop is the whole point.

If you want a rough read before committing to anything, our free risk score tool and dark web exposure check take a few minutes and cost nothing. A full assessment goes considerably deeper, and it pairs naturally with the layered controls described on our cyber security page.

We would rather hand you five things you will actually fix than five hundred you will not.Orca IT, Gilbert AZ

What We Test

The full surface, not just the firewall

A real assessment covers the places attacks actually start.

Perimeter

Public IPs and edge devices

Firewall rules, port forward, VPN firmware, remote access gateways and anything else answering from the open internet.

Endpoints

Workstations and laptops

Credentialed patch state for the OS and third-party apps, local admin sprawl, EDR coverage gaps and disk encryption status.

Servers

On-prem and virtual hosts

Hypervisor patch level, guest OS state, backup agent health, legacy protocols and services running under over-privileged accounts.

Identity

Active Directory and Entra ID

Privileged account review, stale objects, password policy, MFA coverage and conditional access gaps in Microsoft 365.

Network

Switching, Wi-Fi and IoT

Flat networks with no VLAN separation, default credentials on printers and cameras, rogue access points and guest Wi-Fi that touches production.

Cloud

Microsoft 365 tenant

Legacy authentication, mailbox forwarding rules, over-shared SharePoint links, OAuth app grants and audit logging that was never turned on.

Scan vs Pen Test

They are not the same thing, and you probably need one of them

People ask for a penetration test when what they need is an assessment. Here is the honest difference.

A vulnerability assessment is broad and mostly automated with human interpretation on top. It asks: where are the known weaknesses? It covers hundreds or thousands of hosts, runs in a day or two, and is designed to be repeated on a schedule so you can see the trend line. It is the right first move for almost every small and mid-size business, because until you have closed the easy findings, a penetration test just tells you what a scanner already knows.

A penetration test is narrow, manual and adversarial. A human tries to chain findings together into actual access, phish a user, capture a hash, crack it offline, use it to move laterally, escalate to domain admin. It answers a different question: given these weaknesses, how far can someone actually get? It is scoped, it costs more, and it produces a story rather than a list. It is genuinely valuable once your fundamentals are in place, or when a contract, cyber insurance application or client security questionnaire requires one.

Our advice is unglamorous. Run assessments quarterly. Run a penetration test once your quarterly assessments have stopped surfacing new criticals, or when someone external is asking for one in writing. Doing it the other way round means paying human hourly rates to discover an unpatched VPN.

Cadence matters more than depth. A single perfect assessment ages badly, new CVEs publish weekly, someone adds a firewall rule, a laptop gets rebuilt without EDR. We recommend quarterly scanning for most businesses, monthly for anyone handling regulated data such as our healthcare and financial clients, and an out-of-band scan after any significant change: an office move, a new firewall, a server migration or an acquisition. Pod Care clients get this folded in and tracked between reviews rather than billed as an event.

How It Works

Four steps, roughly two weeks end to end

01

Scope

We agree what is in and out: IP ranges, domains, subnets, cloud tenants. No surprise scanning, no disruption to production during business hours.

02

Scan

External scanning runs first, then a credentialed internal scan from a temporary collector on your LAN. Most environments finish inside 48 hours.

03

Review

We sit down with you and walk the ranked list in plain language, with effort and cost against each item so you can decide what to do.

04

Re-scan

After remediation we scan again and show you the before and after. Closed findings get marked closed with evidence, not with a promise.

Not sure where you stand?

The first assessment is free and there is no obligation attached to it.

Get a Free Assessment

Why Orca

Why businesses have us do this instead of a scan vendor

A report is easy to sell. Fixing the findings is the hard part, and it is the part we do.

01

We remediate too

Most scan vendors hand you a PDF and leave. We can close the findings ourselves, which means the report is written by people who have to do the work.

02

Ranked by your risk

Findings are weighted by exposure and blast radius in your environment, not by a generic severity number copied out of a database.

03

No scare tactics

We will tell you when something is theoretical and low priority. Inflating severity to sell services is a fast way to lose a client we intend to keep for a decade.

04

Same engineers each time

Your pod knows what was open last quarter, what you decided to accept, and why. Trend lines only mean something when the same people read them.

05

Local and remote

Onsite collectors and hands-on remediation across Gilbert, Chandler and the East Valley; fully remote assessments for clients in all 50 states.

06

Evidence for third parties

Insurers, auditors and enterprise clients increasingly ask for proof of scanning. We produce documentation you can hand over without embarrassment.

See your network the way an attacker sees it.

Free first assessment for Arizona businesses, remote or onsite.

Talk to Your Pod

Vulnerability testing questions

Will scanning knock anything offline?

It is rare but not impossible, which is why we scope carefully. Fragile devices such as older industrial controllers, some VoIP handsets and legacy medical equipment get excluded or scanned with safe checks only. Anything intensive runs outside business hours by arrangement.

How is this different from a penetration test?

An assessment finds known weaknesses broadly and repeatably. A penetration test has a human try to exploit and chain them to prove real-world impact. Most small businesses should be running assessments quarterly and consider a pen test once the easy findings are consistently closed.

How often should we scan?

Quarterly is the right baseline for most businesses. Monthly makes sense if you handle regulated data or process card payments. Always run an extra scan after a firewall change, a server migration, an office move or an acquisition, because those are exactly when new exposure appears.

Do you need domain admin credentials?

For the internal credentialed scan we need an account with read access to endpoints, and we prefer a dedicated scanning account created for the engagement and disabled afterward. The external scan needs no credentials at all.

What do we actually receive at the end?

A ranked findings list with plain-English descriptions, an executive summary for leadership, effort estimates against each item, and a remediation plan with a suggested sequence. After you fix things we re-scan and issue a closure report showing what changed.

Can you fix the findings for us?

Yes, and most clients ask us to. We can take the whole list, work through it in priority order and re-scan to prove closure. If you have internal IT we are equally happy to hand them the list and stay out of the way.

Does this help with cyber insurance?

It usually helps materially. Insurers increasingly ask about MFA coverage, patch cadence, EDR deployment and whether you scan. Having documented quarterly assessments and a remediation record makes those application questions much easier to answer honestly.

We are outside Arizona. Can you still do this?

Yes. External assessment is entirely remote, and internal scanning runs from a small collector we ship to you or a virtual appliance we deploy on your hypervisor. We support remote clients in all 50 states.

Talk to Your Pod

Let’s see what your network looks like from the outside.

A first assessment is free. We scan, we sit down with you, and we tell you which three things to fix first.

(602) 677-0779

Family owned in Gilbert, AZ since 2015 · onsite across the Phoenix metro · remote support nationwide · never outsourced

Same-day response No long contracts Flat, honest pricing Five-star service

Get your free IT consultation

A few details and your pod gets right back to you, usually the same business day.

Spam-protected with a quick CAPTCHA. Your message goes straight to our team in Gilbert. We only use your details to help with your request. Never sold, never shared.