Insights

Cyber Essentials Plus: What Does Internal Vulnerability Scanning Actually Involve?

Learn how internal vulnerability scanning works during a Cyber Essentials Plus audit, including device sampling, patch checks and remediation.

Cyber Essentials Plus assessor checking sampled business devices for missing updates and vulnerabilities.

Cyber Essentials is often thought of as a questionnaire and a checklist of security controls. That is broadly true for the basic Cyber Essentials assessment, but Cyber Essentials Plus goes considerably further.

Cyber Essentials Plus adds independent technical verification. Rather than relying entirely on an organisation's answers, an assessor tests the environment to verify that the required controls are actually working.

One of the important parts of that technical assessment is checking whether devices have vulnerabilities that should have been addressed.

For organisations, this can raise an important question: what does internal vulnerability scanning actually involve, and how can it be carried out without disrupting the business?

Cyber Essentials Plus goes beyond the questionnaire

Cyber Essentials establishes whether an organisation meets the scheme's requirements through self-assessment.

Cyber Essentials Plus provides a higher level of assurance by adding an independent technical audit. The assessor tests the organisation's systems to verify that the controls described in the assessment are present and operating as required.

That distinction is important.

An organisation might have a patching policy stating that security updates are installed within the required timeframe. That is useful, but a policy does not prove that every relevant device is actually patched.

Technical testing provides another layer of evidence.

As part of the Cyber Essentials Plus process, sampled devices are subjected to vulnerability checking. This helps establish whether relevant vulnerabilities and security updates have been addressed in accordance with the requirements of the scheme.

Why vulnerability scanning matters

It is easy for an organisation to say:

"We patch everything."

The more useful question is:

"Can you demonstrate that the devices are actually patched?"

Vulnerability assessment helps answer that question.

Depending on the technology and scope, vulnerability assessment can identify things such as:

  • Missing security updates
  • Unsupported operating systems or software
  • Vulnerable applications
  • Operating-system vulnerabilities
  • Other vulnerabilities relevant to the assessment

IASME's Cyber Essentials Plus requirements include checking sampled devices for vulnerabilities and verifying that installed software is supported and that relevant high and critical vulnerability patches have been applied within the required timeframe.

This is an important distinction between having a security process and demonstrating that the process is working.

Why internal scanning is different from an external scan

A vulnerability scanner operating from outside an organisation sees the environment from an external perspective.

For example, an external scan might establish:

Port 443 is open on this IP address.

That tells you something useful about the attack surface, but it does not necessarily tell you what is installed on the system behind that port.

An internal assessment can provide considerably more information about the endpoint itself.

For example:

This Windows workstation is running version X of application Y and is missing security update Z.

This type of visibility is particularly useful when assessing endpoint and server patch status.

The two approaches therefore answer different questions.

An external assessment asks, in effect, "What can I see from outside?"

An internal assessment can ask, "What is actually installed and running on this device?"

Both have value, but they are not interchangeable.

The traditional problem with internal vulnerability scanning

Traditional internal vulnerability scanning can sometimes be operationally awkward.

Depending on the technology being used, organisations may need to consider:

  • Scan windows
  • Network access
  • Firewall rules
  • Scanner credentials
  • VPN connectivity
  • Remote workers
  • Laptops that are rarely connected to the corporate network
  • Devices moving between networks

This can become particularly challenging in modern organisations where the traditional concept of a corporate network has largely disappeared.

A laptop might spend Monday in the office, Tuesday at home and Wednesday working from a coffee shop. A cloud-hosted server may never actually sit on the organisation's internal network.

This is where agent-based vulnerability assessment can offer an alternative approach.

Using Qualys Cloud Agent for the assessment

For CE+ assessments, Qualys Cloud Agent can be used to perform vulnerability assessment on appropriate in-scope systems.

Qualys describes Cloud Agent as a lightweight agent that collects information from the host and sends it to the Qualys Cloud Platform, where the assessment takes place.

Rather than requiring a traditional network scanner to connect to each device, the agent operates on the endpoint and provides information about that system to the Qualys platform.

This can be particularly useful for organisations with a mixture of office-based, remote and cloud-based systems.

It also means the assessment does not have to rely entirely on the traditional model of putting a scanner on the corporate network and attempting to reach every device from that location.

What makes the Cloud Agent approach useful?

One of the advantages of an agent-based approach is that it can reduce some of the practical challenges associated with traditional internal scanning.

Lightweight

Qualys describes Cloud Agent as having a minimal footprint and being designed to minimise system and network impact.

For an assessment that involves potentially large numbers of endpoints, avoiding unnecessary disruption is important.

No traditional scan window

A conventional network scan is generally scheduled for a particular period.

An agent-based approach is different. The agent collects information from the host and communicates that information to the Qualys Cloud Platform.

This can make the process considerably more flexible.

Useful for remote devices

Agent-based assessment can be particularly useful for organisations with:

  • Remote workers
  • Hybrid working
  • Laptops
  • Cloud systems
  • Distributed environments

A laptop does not necessarily have to be physically connected to the corporate LAN for the agent to provide information about the device.

No inbound network access required

The Cloud Agent communicates with the Qualys platform rather than requiring the organisation to provide direct inbound access to the endpoint from a vulnerability scanner.

That can simplify deployment in environments where firewall rules, VPN access and network segmentation would otherwise complicate the assessment.

What does the agent actually look at?

The important point is that an agent-based vulnerability assessment is not simply checking whether a particular network port is open.

The agent can collect information about the host, including areas such as:

  • Operating system
  • Installed software
  • Patch information
  • Network posture
  • Open ports
  • Registry information on supported systems
  • Other relevant host metadata

Qualys describes Cloud Agent as performing authenticated, on-asset assessment and using the same vulnerability signatures as its traditional scanners.

This provides a useful distinction:

The agent is gathering information from the host itself to support vulnerability assessment, rather than simply looking at the system from across the network.

For vulnerability management, that host-level visibility can be extremely valuable.

What happens during the CE+ assessment?

The process can be thought of as a relatively straightforward lifecycle.

Scope is identified

↓

Appropriate devices are selected

↓

Cloud Agents are deployed

↓

Agents collect host information

↓

Qualys assesses the collected data

↓

Vulnerabilities are identified

↓

Remediation is performed where required

↓

Assessment evidence is reviewed

↓

CE+ technical testing is completed

The important caveat is that the scanning technology does not define the Cyber Essentials Plus assessment.

The assessment itself is governed by the current Cyber Essentials Plus Test Specification and associated scheme requirements. The vulnerability-scanning technology is simply one means of obtaining the technical evidence required by the assessment.

What happens when vulnerabilities are found?

Finding a vulnerability does not mean the purpose of the assessment has failed.

The purpose of the technical assessment is to determine whether the organisation meets the requirements of Cyber Essentials Plus and, where it does not, identify what needs to be corrected.

The practical process is therefore:

Identify → Investigate → Remediate → Reassess → Verify

That final step is particularly important.

If an issue is discovered during testing and the organisation subsequently fixes it, it is necessary to establish that the remediation has actually been effective.

Where possible, a second sample should now be taken to confirm that the issue has been resolved across the wider estate, rather than simply assuming that fixing one device means the underlying problem has disappeared everywhere.

This is one reason why deploying scanning agents across the estate from the outset can be particularly useful.

Instead of having visibility of only the devices selected for the initial assessment, the organisation can potentially have visibility across its wider estate. That makes it easier to investigate whether a vulnerability is isolated or exists across multiple systems.

It also naturally leads into the next question:

What happens to the agents after the CE+ assessment?

Don't necessarily remove the agent afterwards

The vulnerability assessment does not have to be the end of the technology's usefulness.

With the customer's agreement, Cloud Agents can potentially remain installed after the assessment and become part of an ongoing vulnerability-management programme.

This is an interesting opportunity because the technology used to support the CE+ assessment can also provide continuing visibility of the environment.

The model becomes:

CE+ assessment → remediation → ongoing vulnerability management

Rather than treating vulnerability assessment as something that happens once a year, the organisation can continue monitoring its systems as they change.

From annual assessment to continuous visibility

Consider a simple example.

April:
A CE+ assessment identifies a vulnerability and it is remediated.

May:
A new vulnerability is disclosed.

June:
A new application is installed on several laptops.

July:
Another vulnerability affects that application.

If the organisation only performs vulnerability assessment annually, there can be a substantial visibility gap between assessments.

The environment changes continuously. Software is installed and removed, operating systems are updated, new vulnerabilities are disclosed and devices are introduced.

Continuous vulnerability visibility helps organisations understand those changes as they happen.

This does not mean every vulnerability needs to be fixed immediately. It means the organisation has the information needed to make informed decisions about what needs attention.

CE+ isn't vulnerability management

There is an important distinction here.

Passing Cyber Essentials Plus does not mean an organisation has solved vulnerability management.

CE+ verifies that the organisation meets the requirements of the Cyber Essentials scheme at the time of the assessment.

A mature vulnerability-management programme goes considerably further.

It might include:

  • Asset discovery
  • Continuous vulnerability identification
  • CVSS assessment
  • EPSS
  • CISA KEV
  • Risk-based prioritisation
  • Remediation tracking
  • Verification
  • Reporting
  • Ongoing monitoring

This is where vulnerability scanning becomes much more than an audit activity.

The CE+ assessment provides a point-in-time assurance that the required controls are working. Vulnerability management is about maintaining that security posture afterwards.

Why this is particularly useful for SMEs

For a large enterprise with a dedicated security team, continuous vulnerability management may already be well established.

For a smaller organisation, it can be more difficult.

An SME may not have:

  • A dedicated vulnerability-management team
  • A full-time security analyst
  • Extensive security infrastructure
  • The resources to perform complex internal scans every week

An agent-based approach can provide a practical way of obtaining continuing visibility without requiring the organisation to build a large security operation around it.

The important thing is not the technology for its own sake.

The objective is to make it easier for the organisation to answer a fundamental security question:

"Do we know what vulnerabilities exist across our environment, and are we doing something about them?"

What does the customer get beyond the certificate?

The obvious outcome of Cyber Essentials Plus is the certificate.

But there can be a more valuable outcome.

Instead of simply saying:

"We passed CE+."

the organisation can potentially say:

"We now have an ongoing view of vulnerabilities across our environment."

That is a much stronger security outcome.

The assessment becomes the starting point for improving vulnerability management rather than simply an annual compliance exercise.

Important limitations

It is also important not to present vulnerability scanning as a replacement for other forms of security testing.

Vulnerability management does not replace:

  • Penetration testing
  • Web application testing
  • Configuration reviews
  • Security architecture assessments
  • Active Directory security assessments
  • Attack-path analysis

A vulnerability scanner might tell you:

"This system has a vulnerability."

A penetration test can investigate a different question:

"Can an attacker exploit this weakness and use it to compromise something more valuable?"

Both provide useful but different forms of assurance.

A vulnerability scanner is very good at providing broad visibility across an estate. A penetration tester can apply human judgement, chaining vulnerabilities and weaknesses together to understand how they could be exploited in a real attack.

The bigger picture

Cyber Essentials Plus provides valuable independent assurance that an organisation has implemented the required baseline security controls.

Internal vulnerability assessment is an important part of demonstrating that those controls are working in practice.

Using lightweight technology such as Qualys Cloud Agent can make vulnerability assessment less disruptive, particularly for organisations with remote and distributed devices.

But perhaps the biggest opportunity is what happens afterwards.

The same technology used to support the CE+ assessment can potentially remain in place and form part of an ongoing vulnerability-management programme.

That changes the conversation from:

"Are we compliant?"

to:

"How do we maintain our security posture?"

Passing the assessment is the milestone.

Maintaining the security posture is the goal.

Portrait of Plainsight Security's lead tester

Written by

Mark Tomlinson

Our lead penetration tester, Mark Tomlinson, holds The Cyber Scheme Team Leader qualification in infrastructure penetration testing, an advanced certification recognised by the National Cyber Security Centre (NCSC) and used by professionals testing government systems and UK critical national infrastructure. Mark is also registered with the UK Cyber Security Council as a Principal Cyber Security Professional (PriCSP) specialising in Security Testing and holds an MSc in Computer Science with Cyber Security.

More about how we work
Talk to a tester

Put this into practice.

Cyber Essentials, Cyber Essentials Plus, and penetration testing — fixed-price, plain English, and built to stay out of your way.

← All insights