One-off
from CHF 5'000
Initial inventory, ideal for ISO 27001 preparation or ahead of a pentest.
- External and/or internal view
- Manual review of findings
- Prioritised report
Regular automated scans of your systems uncover known vulnerabilities before attackers exploit them. SIDD sets this up one-off, quarterly or monthly, with a prioritised report and concrete remediation recommendations.
Working for regulated industries and SMEs
Vulnerability scans are your IT early-warning system, they uncover known CVEs before attackers do.
Important: vulnerability scans are just one building block. They complement pentests, training, incident-response plans and audits.
Both identify vulnerabilities, but at very different levels of depth.
| Criterion | Vulnerability Scan | Penetration test |
|---|---|---|
| Method | Automated (scanner) | Manual, by certified testers |
| Focus | Known CVEs, configuration errors | Business logic, auth/authZ, zero-days |
| Frequency | Quarterly or monthly | Annually or per release |
| Effort | Hours | Days to weeks |
| Price from | CHF 5'000 | CHF 8'000 (small web app) |
Many customers combine both: a quarterly scan plus an annual Penetration test.
Three typical models.
One-off
from CHF 5'000
Initial inventory, ideal for ISO 27001 preparation or ahead of a pentest.
Quarterly
from CHF 18'000 / year
The standard for SMEs with an online presence and cloud workloads.
Monthly (subscription)
On request
For regulated industries with high processing intensity (FINMA, EPDG, NIS2).
To an ongoing scan setup in five steps.
Digital service agreement with scope of services.
Definition of the systems to be tested, methods, do's and don'ts.
We draw up the testing plan and agree it with you.
Run the scan once or set it up as a recurring scan.
Prioritised findings report with CVSS scores, remediation recommendations and lessons learned.
Optional: ongoing support as Information Security Officer.
An automated scan only delivers value if someone contextualises the results, prioritises them and tracks them over time, and that is exactly what SIDD takes on with its own InfoSec team rather than raw tool output.
Certified testers (OWASP/PTES/OSSTMM) manually verify every finding, weed out false positives and assess the real-world exploitability. You receive a curated report, not an unfiltered list of hundreds of raw findings.
The scan is supported by software engineers and InfoSec specialists under CTO Oliver Stutz, not an outsourced tool licence. Remediation recommendations are therefore technically concrete and tailored to your system landscape.
Using our own Priverion Platform, we record vulnerabilities, remediation status and repeat scans as a maintained, auditable history. This lets you see on a quarterly basis whether measures are working, rather than just a snapshot.
As ISO/IEC 27001 Lead Auditors (BSI-trained), we deliver the report in a form usable as evidence for Annex A.12.6.1 (management of technical vulnerabilities). The scan contributes directly to your certification.
We assess independently of any implementation consulting, so the findings remain audit-credible and free of any vested interest in follow-up work. Where a scan reaches its limits, we say so openly instead of selling.
With the quarterly or monthly cadence, the same named person looks after you across all cycles, with an initial response within 24 hours. Active since 2017 with a high renewal rate, you do not have to explain your environment anew each time.
For web applications and APIs we test specifically against the OWASP Top 10: injection, broken access control, faulty authentication and configuration weaknesses. Application security testing combines the automated scan with manual validation, so you receive actionable findings instead of false positives.
Findings are prioritised by CVSS score and mapped to CVE references, so critical gaps are immediately visible. You receive the report within one week, with concrete remediation recommendations and an included retest after remediation.
Our report is accepted by the bodies that matter to you:
Our tool: LexCommand
LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.
The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.
Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.
LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.
We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.
For the vulnerability scan, concretely: LexCommand links each prioritised finding to the relevant duty under ISO 27001 A.12.6.1, DORA, NIS2 or the revised FADP, and backs every regulatory statement in the report with the exact location in the primary source.
Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.
From CHF 5'000 for a one-off scan with a moderate scope. Quarterly subscriptions from CHF 18'000/year. The final price depends on the number of hosts, the desired depth and whether agents need to be installed.
Depending on the mandate, Tenable Nessus, Qualys, Greenbone (OpenVAS) or cloud-specific tools (e.g. Wiz for cloud workloads). We choose the scanner that fits the scope.
Only for authenticated or internal scans. External scans run from the internet without any local installation. We discuss the best architecture in the kick-off.
Executive summary with the top risks for executive management, plus a technical detail section with CVSS scores, affected hosts, reproduction steps and concrete remediation recommendations.
Scans for broad coverage of known CVEs. Pen tests for in-depth validation of individual applications or authentication logic. Ideal combination: monthly scan + annual pen test. See Penetration test.
Yes. Findings are shared exclusively with the persons you designate. Enquiries are subject to professional secrecy under Art. 321 SCC.
Send us your desired scope. We will provide the price and timeframe within 24 hours.