forumNew topic

Scanning tools (Nessus, Qualys, OpenVAS) which is good, should I scan daily

YYavuz D***7 months ago·32 messages·9.2K viewsClosed#scanning#openness
YYavuz D***Member
Job title
Field sales representative
Sector
Consulting
Organization type
family business
Joined
May 2025
Message
206
#1

There's Nessus, Qualys, OpenVAS. Which is good?

There's a false positive issue.

Network slows down if I scan every day.

ÖÖzgür K***Member
Job title
System support specialist
Sector
Furniture manufacturing
Organization type
8-person team
Joined
May 2025
Message
79

Doki · Mobile app · 2023

Most Helpful#2

Nessus is best practice. False positives: 10-30% is normal. Scan once a week.

UUğur V***MemberCommunity member
Joined
Aug 2023
Message
282
#3

we use openvas we scan on friday eveenings

GGürkan K***Member
Job title
Production planning
Sector
Packaging
Organization type
early-stage startup
Joined
May 2024
Message
109

Doki · Penetration test · 2026

#4

Same here.

HHilal Y***Expert
Job title
Accounting Manager
Sector
Catering
Organization type
chain store
Joined
Aug 2025
Message
66
#5

To get into the details: Processes without records never improve, because you don't know what to fix.

Your time to detect an issue directly determines its cost. Correct me if I'm wrong.

ZZeynep O***New member
Job title
Business Owner
Sector
Furniture manufacturing
Organization type
family business
Joined
May 2026
Message
1
#6

Absolutely. If I were to add anything: Forgotten test environments are more often the entry point than live systems.

This is my opinion, I'm not claiming it's absolute truth.

KKaan O***MemberCommunity member
Joined
Feb 2023
Message
16
#7

Timely topic.

LLevent Ş***ExpertCommunity member
Joined
Apr 2025
Message
14
#8

Let me clarify the technical side. When making a decision first look at what data you have on hand.

Mistakes made on the security vulnerability scanning side are usually reversible but expensive. Just leaving this note, it might be useful.

RRecep B***ExpertCommunity member
Joined
Jun 2024
Message
111
#9

Let's separate the concepts, they're getting mixed up. Your time to detect an issue directly determines its cost.

The answer varies greatly by industry; there is no one-size-fits-all rule. Good luck with that.

İİlknur A***MemberCommunity member
Joined
Jan 2024
Message
220
#10

Exactly, and not many people know this. Your time to detect an issue directly determines its cost.

This is my opinion, I'm not claiming it's absolute truth.

OOnur Y***Member
Job title
Social media manager
Sector
Leather
Organization type
regional distributor
Joined
Aug 2025
Message
120
#11

Exactly and not many people know this. Start with a small trial; don't commit to everything at once.

Good luck with that.

TTülay A***Member
Job title
Store associate
Sector
Packaging
Organization type
8-person team
Joined
Dec 2023
Message
64
#12

Good call starting this thread.

LLevent E***Member
Job title
Warehouse Manager
Sector
Healthcare services
Organization type
120-person company
Joined
Jul 2024
Message
108
#13

We got stuck at the same point for a while. Having backups accessible on the same network and with the same identity makes them part of the target.

VVahide K***Member
Job title
Content Editor
Sector
Advertising and promotion
Organization type
workshop
Joined
Apr 2023
Message
148
#14

The discussion got scattered let me summarize. btw forgotten test environments are more often the entry point than live systems.

If I were you Id go this route.

FFiliz S***MemberCommunity member
Joined
Jun 2023
Message
3
#15

Thanks, this was very helpful.

OOğuzMember
Job title
Former founder
Organization type
early-stage startup
Joined
Aug 2023
Message
76
#16

Three different views emerged, they all complement each other. The real issue isn't the number, but what it's based on.

Payment information changes are never verified through the channel they came from. This is my opinion, I'm not claiming it's absolute truth.

YYağmur S***MemberCommunity member
Joined
Jun 2023
Message
13
#17

Let me summarize what's been said so far. Trying to do this alone is the most expensive way.

This is my opinion, I'm not claiming it's absolute truth.

HHande T***Member
Job title
Data entry clerk
Sector
Food wholesale
Organization type
workshop
Joined
Apr 2025
Message
62
#18

We need to make a distinction here. Processes without records never improve, because you don't know what to fix.

If you have questions write them; I'll answer as best I can.

CCeren E***MemberCommunity member
Joined
Apr 2025
Message
95
#19

Thanks for writing this, that's the right way. Any unwritten clause becomes a point of disagreement later, as both sides remember it differently.

HHüseyin Ş***Member
Job title
Network Administrator
Sector
Packaging
Organization type
a company within a holding
Joined
Jul 2023
Message
81

Doki · Brand identity · 2025

#20

i'm a small business let me explain from my side but tbh the biggest time-waster for us was not knowing who had the final say.

security isn't absolute; it's about makign attacks not worth the effort.

This topic has been closed.The moderator marked the topic as resolved. If you have a similar issue, you can open a new topic.
New topic