Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security & Compliance Glossary

Vulnerability Assessment

A vulnerability assessment is a systematic review that identifies, classifies, and prioritizes known security weaknesses across systems, usually using automated scanning tools. It produces a broad inventory of issues ranked by severity. Unlike a penetration test, it does not attempt to exploit the weaknesses it finds.

In practice

A vulnerability assessment gives you breadth: a prioritized list of missing patches, misconfigurations, and known CVEs across your estate. It is fast, repeatable, and well suited to running on a recurring schedule.

The trade-off is depth. Scanners report potential issues without confirming whether they are truly exploitable in your environment, which produces false positives that a human still has to triage.

// how traztech helps

traztech delivers vulnerability assessment and remediation for startups and growth-stage companies, led by a published security researcher.

Book a call

For a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.

Where it comes up

A vulnerability assessment is the wide, shallow pass: what is exposed, what is out of date, what is misconfigured. It is what tells you the size of the problem before anybody decides how deep to go.

It becomes a compliance artefact when it runs on a schedule and produces evidence that findings were triaged and remediated within a stated timeframe. A one-off scan with no remediation record evidences very little.

Vulnerability Assessment: common questions

Is a vulnerability assessment enough for SOC 2?

It contributes, but auditors generally want to see the whole cycle: scanning on a defined cadence, triage, remediation inside your stated SLA, and evidence of all three across the observation period.

How is this different from vulnerability management?

The assessment is the point-in-time activity. Vulnerability management is the ongoing programme around it, including who triages, who fixes and how you prove the loop closed.

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.

Before you go

Want the practical version by email?

Definitions only get you so far. I send a few short notes on how this plays out in practice. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.