Answers to your questions

Quickly find answers to your questions about cybersecurity, CVE Find, standards, vulnerabilities and Bexxo services in our comprehensive FAQ.

FAQ

What is the difference between a pentest and a vulnerability scan?

A vulnerability scan is an automated analysis performed by a tool that examines a system or application for known vulnerabilities, typically by comparing software versions or testing configurations. It is fast and inexpensive, but often produces raw or incomplete results, with false positives.

A pentest, on the other hand, goes beyond detection: it seeks to actually exploit vulnerabilities to demonstrate their concrete impact. It is a manual and methodical process that validates detected vulnerabilities, identifies new ones, and provides realistic attack scenarios. The pentest is therefore much more thorough and contextual, but requires time, expertise, and planning.

  • Tags:  
What is the difference between Bexxo Academy online training and in-person sessions?
Online training (academy.bexxo.ch) is available 24/7, individual and self-paced — ideal for regular awareness, ongoing tracking and geographically dispersed teams. In-person sessions in Ins (BE) are recommended when you wish to train 5 to 20 people simultaneously, run interactive workshops with real-life scenarios, or anchor a security culture during a company event (seminar, thematic day). For teams of more than 10 people, we generally recommend a combination: initial online awareness, then an in-person session to consolidate learning and address issues specific to your organisation.
  • Tags:  
What is the difference between Bexxo and Tesweb SA?
Tesweb SA is the legal entity founded in 2006, which operates two areas of expertise: SOS Data Recovery (data recovery, leading Swiss service) and Bexxo (cybersecurity, brand launched in 2023). Bexxo is a registered and protected brand dedicated exclusively to digital protection for businesses. This dual expertise — data recovery and protection — represents a unique positioning in Switzerland.
  • Tags:  
What is the difference between consulting and a security audit?
A security audit is a one-off technical assessment (vulnerabilities, penetration tests, report). Consulting is a continuous strategic support service: it often starts with an audit, but goes further by defining the security policy, training teams and overseeing improvements over the long term.
  • Tags:  
What is the difference between CVE Find and the NIST NVD database?
The NVD (National Vulnerability Database) from NIST is the official US source. CVE Find aggregates this data and adds a layer of personalised alerts, product filtering and EPSS scoring (real-world exploitation probability) that the NVD does not offer natively. The interface is available in English.
  • Tags:  
What is the difference between CVE Find and the official cve.org website?

The cve.org website, managed by MITRE, is the official source of CVE identifiers. It is essential for ensuring the uniqueness and structure of entries. However, cve.org focuses on the administrative aspect and does not provide EPSS scores, exploitation indicators, or advanced sorting functionalities.

Our CVE Find service takes this official data, enriches it with complementary metrics (KEV, EPSS, CVSS), and presents it in a more modern, faster, and filterable interface. It is therefore a practical monitoring tool, designed for operational and decision-making use on a daily basis.

  • Tags:  
What is the difference between ISO 27001 and ISO 27002?
ISO 27001 defines the requirements for an information security management system (ISMS) and enables certification. ISO 27002 is a guide to best practices that details the implementation of the 93 controls in Annex A. In short: 27001 says 'what to do', 27002 says 'how to do it'.
  • Tags:  
What is the difference between PhishTrainer and Bexxo Academy?
PhishTrainer and Bexxo Academy are two complementary tools: PhishTrainer tests (attack simulation, vulnerability identification, click rate measurement), Bexxo Academy trains (e-learning modules, quizzes, videos, in-person sessions). They work in synergy: PhishTrainer results identify at-risk teams or profiles, Bexxo Academy provides the adapted training paths. For effective protection, Bexxo recommends using both tools together following the Simulate → Train → Measure method.
  • Tags:  
What is the difference between PhishTrainer and Bexxo Academy?

They are two complementary tools:

  • PhishTrainer works through practice: it sends fake phishing emails to your employees and measures who clicks and who reports the attack. This is the behavioural approach — learning by experience. The dashboard shows the click rate, the reporting rate and the trend over time.
  • Bexxo Academy works through knowledge: video modules, interactive quizzes, educational games on cyber threats. Available 24/7 online, complemented by in-person sessions in Ins (BE). Ideal for onboarding new employees and updating knowledge.

Both tools together cover the complete loop: raise awareness → test → measure → improve.

  • Tags:  
What is the difference between security awareness and technical training?

Security awareness aims to spread a general security culture, accessible to all employees, regardless of their profession or technical level. It covers concrete topics: phishing, passwords, mobility, social networks, vigilance in teleworking, etc. The goal is to make everyone an actor in security in their daily uses.

Technical training, on the other hand, is aimed at more specialized profiles (IT teams, devs, admins) and focuses on specific skills such as system hardening, secure development, or incident management. It often requires prerequisites and aims to strengthen security through technical mastery.

  • Tags:  
What is the difference between the Essentiel, Avancé and Premium packages?

The three packages differ in their depth of analysis:

  • Essentiel: 10 control points, automated scan, simplified report — for small sites or first audits.
  • Avancé: 15 control points, manual testing of common vulnerabilities, authentication analysis, detailed report with prioritised action plan.
  • Premium: 20 control points, in-depth penetration tests, API and database audit, full OWASP Top 10 verification, presentation session included.

All packages include post-audit follow-up and implementation assistance.

  • Tags:  
What is the difference between the Essentiel, Avancé and Premium packages?

The three packages differ in their depth of analysis:

  • Essentiel: 10 control points, basic network mapping, automated scan for common vulnerabilities, simplified report — for SMEs beginning their security journey.
  • Avancé: 15 control points, manual intrusion tests, configuration analysis of active devices, detailed report with prioritised action plan.
  • Premium: 20 control points, internal and external penetration tests, attack simulation, full analysis of segmentation and access, presentation of results to management.

All packages include post-audit follow-up and implementation assistance.

  • Tags:  
What is the difference between White Box, Grey Box and Black Box for a network?
White Box provides access to network diagrams and configurations (most comprehensive, ideal before ISO certification). Grey Box simulates an employee or contractor with partial VPN access (most balanced for SMEs). Black Box tests from the outside with no prior knowledge, like a real attacker. Bexxo recommends Grey Box as the standard for SMEs.
  • Tags:  
What is the difference between White Box, Grey Box and Black Box?
White Box analyses the source code and internal architecture (most comprehensive). Grey Box simulates a user with partial access (most balanced for SMEs). Black Box tests from the outside with no prior knowledge, like an attacker (most realistic). Bexxo recommends Grey Box as the standard for SMEs.
  • Tags:  
What is the first thing to do in the event of a cyberattack?
Immediately isolate the compromised systems from the network, do not pay a ransom, document the incident and contact a cybersecurity specialist. Bexxo offers an incident response service for Swiss businesses.
  • Tags: