Vulnerability scan · automated · from CHF 5'000

Vulnerability Assessment & Security Testing · Switzerland

Regular automated scans of your systems uncover known vulnerabilities before attackers exploit them. SIDD sets this up one-off, quarterly or monthly, with a prioritised report and concrete remediation recommendations.

from CHF 5'000 Retest included Report in 1 week Leading scanners
Vulnerability Scan Switzerland - Vulnerability Scan
Tenable · Qualys · Greenbone Partner
Swiss provider, Zurich
Fixed fee
Free 30-min consultation
Quote within 24h
Active since 2017

Working for regulated industries and SMEs

CIPP/E · CIPM IAPP certified
ISO 27001 Lead Auditor (BSI)
Aligned with the FDPIC Revised FADP · Art. 10
HQ Baar, ZG Swiss brand
CH · EU · UK · US Mandates worldwide
Dr. Dominic Staiger

Responsible for this mandate

Dr. Dominic Staiger

LL.M., Dr. iur., CIPP/E · Attorney at Law (New York) · Solicitor (UK)

Supports vulnerability-management mandates from setup through reporting to remediation sign-off. Interface to audit, ISMS and data protection.

LinkedIn profile

Why regular vulnerability scans?

Vulnerability scans are your IT early-warning system, they uncover known CVEs before attackers do.

  • Early detection of security gaps in servers, endpoints, applications and cloud workloads
  • Risk reduction through patch management, configuration changes and compensating measures
  • Compliance with industry-specific requirements (ISO 27001 A.12.6, PCI DSS 11.2, DORA, NIS2)
  • Protection of confidential data against unauthorised access
  • Avoidance of downtime through identified patch gaps
  • Reputation protection and a signal of trust towards customers
  • Resource optimisation by prioritising remediation of the most critical gaps first

Important: vulnerability scans are just one building block. They complement pentests, training, incident-response plans and audits.

Vulnerability scan vs. penetration test, what is the difference?

Both identify vulnerabilities, but at very different levels of depth.

CriterionVulnerability ScanPenetration test
MethodAutomated (scanner)Manual, by certified testers
FocusKnown CVEs, configuration errorsBusiness logic, auth/authZ, zero-days
FrequencyQuarterly or monthlyAnnually or per release
EffortHoursDays to weeks
Price fromCHF 5'000CHF 8'000 (small web app)

Many customers combine both: a quarterly scan plus an annual Penetration test.

How often should you scan?

Three typical models.

One-off

from CHF 5'000

Initial inventory, ideal for ISO 27001 preparation or ahead of a pentest.

  • External and/or internal view
  • Manual review of findings
  • Prioritised report

Monthly (subscription)

On request

For regulated industries with high processing intensity (FINMA, EPDG, NIS2).

  • 12 scans per year
  • Continuous CVE trends
  • Dedicated reporting

What happens after the engagement is awarded?

To an ongoing scan setup in five steps.

Contract

Digital service agreement with scope of services.

Scope

Definition of the systems to be tested, methods, do's and don'ts.

Testing plan

We draw up the testing plan and agree it with you.

Execution

Run the scan once or set it up as a recurring scan.

Report

Prioritised findings report with CVSS scores, remediation recommendations and lessons learned.

Optional: ongoing support as Information Security Officer.

Why SIDD?

An automated scan only delivers value if someone contextualises the results, prioritises them and tracks them over time, and that is exactly what SIDD takes on with its own InfoSec team rather than raw tool output.

Triage instead of raw output

Certified testers (OWASP/PTES/OSSTMM) manually verify every finding, weed out false positives and assess the real-world exploitability. You receive a curated report, not an unfiltered list of hundreds of raw findings.

In-house engineering team

The scan is supported by software engineers and InfoSec specialists under CTO Oliver Stutz, not an outsourced tool licence. Remediation recommendations are therefore technically concrete and tailored to your system landscape.

Findings tracked

Using our own Priverion Platform, we record vulnerabilities, remediation status and repeat scans as a maintained, auditable history. This lets you see on a quarterly basis whether measures are working, rather than just a snapshot.

Evidence for your ISMS

As ISO/IEC 27001 Lead Auditors (BSI-trained), we deliver the report in a form usable as evidence for Annex A.12.6.1 (management of technical vulnerabilities). The scan contributes directly to your certification.

Advisory and audit kept separate

We assess independently of any implementation consulting, so the findings remain audit-credible and free of any vested interest in follow-up work. Where a scan reaches its limits, we say so openly instead of selling.

The same person each cycle

With the quarterly or monthly cadence, the same named person looks after you across all cycles, with an initial response within 24 hours. Active since 2017 with a high renewal rate, you do not have to explain your environment anew each time.

Application Security Testing & OWASP Top 10

For web applications and APIs we test specifically against the OWASP Top 10: injection, broken access control, faulty authentication and configuration weaknesses. Application security testing combines the automated scan with manual validation, so you receive actionable findings instead of false positives.

Prioritised report by CVSS and CVE

Findings are prioritised by CVSS score and mapped to CVE references, so critical gaps are immediately visible. You receive the report within one week, with concrete remediation recommendations and an included retest after remediation.

Report accepted for ISO, FINMA and FADP

Our report is accepted by the bodies that matter to you:

ISO 27001
FINMA
FADP / revised DSG
Cyber insurance

Our tool: LexCommand

Why we work with LexCommand, our own Swiss legal AI

LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.

Sovereign in Switzerland

The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.

No citation, no claim

Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.

From effort to judgement

LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.

Three disciplines, one picture

We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.

For the vulnerability scan, concretely: LexCommand links each prioritised finding to the relevant duty under ISO 27001 A.12.6.1, DORA, NIS2 or the revised FADP, and backs every regulatory statement in the report with the exact location in the primary source.

Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.

Frequently asked questions before engaging us

What does a vulnerability scan cost?

From CHF 5'000 for a one-off scan with a moderate scope. Quarterly subscriptions from CHF 18'000/year. The final price depends on the number of hosts, the desired depth and whether agents need to be installed.

Which scanners do you use?

Depending on the mandate, Tenable Nessus, Qualys, Greenbone (OpenVAS) or cloud-specific tools (e.g. Wiz for cloud workloads). We choose the scanner that fits the scope.

Do I need an agent on my systems?

Only for authenticated or internal scans. External scans run from the internet without any local installation. We discuss the best architecture in the kick-off.

What is included in the report?

Executive summary with the top risks for executive management, plus a technical detail section with CVSS scores, affected hosts, reproduction steps and concrete remediation recommendations.

Vulnerability scan or pen test?

Scans for broad coverage of known CVEs. Pen tests for in-depth validation of individual applications or authentication logic. Ideal combination: monthly scan + annual pen test. See Penetration test.

Are findings subject to professional secrecy?

Yes. Findings are shared exclusively with the persons you designate. Enquiries are subject to professional secrecy under Art. 321 SCC.

Ready for your first vulnerability scan?

Send us your desired scope. We will provide the price and timeframe within 24 hours.