Small Network Vulnerability Assessment
Budget: $15 – $25 USD
I have a small office network—fewer than twenty endpoints—that I want thoroughly examined for weaknesses. The immediate focus is a vulnerability assessment combined with a full network-security audit. Pen-testing isn’t required right now, but I would like the audit to be detailed enough that we could progress smoothly to active exploitation tests later if needed.
Scope
– Map every device and service, then scan using industry-standard tools such as Nmap, Nessus or OpenVAS.
– Analyse configurations (firewall rules, router settings, shared resources, OS hardening) and identify misconfigurations or outdated software.
– Provide a clear, prioritized remediation plan. Critical issues first, followed by medium and low-risk findings.
– Conclude with a concise executive summary for management and a technical appendix for my IT team.
Acceptance criteria
• All devices in the 1-20 range are discovered and included in the report.
• Findings are reproducible using the documented steps and tool versions.
• Recommendations match the CVSS ratings or equivalent risk scoring you apply.
Deliver the draft report within one week of access; final version two days after feedback. Secure, encrypted communication is mandatory throughout.
Scope
– Map every device and service, then scan using industry-standard tools such as Nmap, Nessus or OpenVAS.
– Analyse configurations (firewall rules, router settings, shared resources, OS hardening) and identify misconfigurations or outdated software.
– Provide a clear, prioritized remediation plan. Critical issues first, followed by medium and low-risk findings.
– Conclude with a concise executive summary for management and a technical appendix for my IT team.
Acceptance criteria
• All devices in the 1-20 range are discovered and included in the report.
• Findings are reproducible using the documented steps and tool versions.
• Recommendations match the CVSS ratings or equivalent risk scoring you apply.
Deliver the draft report within one week of access; final version two days after feedback. Secure, encrypted communication is mandatory throughout.