Product details

Vulnerability diagnosis service

Do you have any problems like this?

Focus Systems will solve that problem!

I am concerned about the security of my website and want to understand the risks and take countermeasures.

Because the web system is delivered and provided to customers, it is necessary to undergo periodic third-party vulnerability assessments.

01: We provide vulnerability diagnosis services that are ideal for requests such as ``first-time users,'' ``wanting to compare and consider,'' and ``wanting to reduce costs.''

Because we have many years of experience and are affiliated with various diagnostic companies, we are able to respond flexibly to customer requests. We use a combination of tools and manual diagnostics to uncover previously unknown vulnerabilities.

02: Vulnerability diagnosis can be performed from various perspectives.

By conducting diagnostics based on the latest cybersecurity trends, you can always check system vulnerabilities from a third-party perspective. Additionally, by periodically changing the provider, it becomes possible to diagnose from a variety of perspectives.

Why vulnerability assessment is necessary

If vulnerabilities are left unaddressed, the risk of external attacks increases.
In order to prevent leaks of confidential information and security incidents from cyber attacks that are evolving day by day, it is essential to continually improve security, and for this reason, we conduct vulnerability assessments not just once but regularly. It is important to do so.

Vulnerability diagnosis service content

■Web application diagnosis

・Perform manual manual diagnosis We discover vulnerabilities that cannot be discovered with tool diagnosis alone, and determine the overall risk level due to the combination of multiple vulnerabilities. You can also discover specific exploit steps and design-level vulnerabilities.
・Tool diagnosis can be used for confirmation purposes to prevent human errors (diagnosis omissions) and improve diagnostic efficiency (comprehensiveness).

 

■Network diagnosis

・Conducted mainly through tool diagnosis We investigate whether there are any known vulnerabilities or configuration deficiencies that have been investigated and published by developers, security research institutes, etc.
・Implement manual manual diagnosis. Perform a thorough examination of false positives to improve the accuracy of reports.

 

■Penetration test

Based on the vulnerability diagnosis results, engineers conduct mock attacks against vulnerabilities, conduct password guessing surveys, etc., and attempt to manually infiltrate the server.

 

■Options

Add server network (host)

Added server/network diagnosis target (IP)

breaking news

Highly urgent matters should be reported on the same day.
If a vulnerability of high severity is discovered, we will notify you with a report by noon on the next business day.

Holiday/night diagnosis

Diagnosis available outside of weekdays (10:00-17:00)

On-site diagnosis

Diagnosis at customer site (on-site)

Source code analysis

After diagnosis, verify the discovered vulnerabilities at the source code level.

Debriefing session

Engineers explain comprehensive evaluation, details of discovered vulnerabilities, and countermeasures

Re-diagnosis

Re-diagnosis only for vulnerabilities discovered by the diagnosis

(Confirmation of implementation of measures)

delivery slip

[Deliveries] Report, diagnosis details

Deliver the report electronically as an email attachment.

support

You can contact us by e-mail for one month after submitting your report. (During business hours)

Diagnosis method/environment

We will select the most suitable vulnerability diagnosis from two types: remote diagnosis conducted via the Internet and on-site diagnosis conducted within the customer's environment.


FAQ

How long does it take from estimate to diagnosis?

Approximately 2 to 3 months. (Depends on the number of dynamic screens of the web application.)

inquiry

Achievements left behind

48 years since its establishment.
We have a proven track record because we have focused on what is important.
It has a long track record in both the public and private sectors.

Number of projects per year

500 PJ

Annual number of business partners/customers

200 companies

Maximum number of trading years

47 years

Total number of qualified persons

1,870 people