Skip to content
  • There are no suggestions because the search field is empty.

What are the best practices for scan scheduling and asset coverage?

This article describes recommended scan scheduling settings and how to confirm your assets are fully covered once scanning is underway. A well-designed schedule gives you continuous visibility without impacting production systems, and checking coverage afterward confirms the setup is actually working as intended. 

Default weekly schedule framework

The goal is full coverage on a weekly cadence, with scans staggered to match your operational rhythm.

Scan type: Recommended window: Frequency: Notes:
Network scan, internal Tue-Thu, 02:00-05:00 Weekly Avoid Monday (post-weekend changes) and Friday (no one available to respond to alerts).
Network scan, external Sat-Sun, 01:00-04:00 Weekly A weekend window reduces the risk of disrupting your externally facing services.
Web application scan Sat, 22:00-03:00 Weekly Web application scans are intrusive. Always run them outside business hours and coordinate with your development or operations teams.
Cloud Security assessment (via API integration) Daily, 06:00 Daily API integrations are lightweight. Daily assessments are recommended for fast-changing environments.
Network scan, Operational Technology Off-peak Weekly or bi-weekly Always agree scan windows explicitly with your operational technology team.

Scan profile options

Assign an appropriate scan option profile to each schedule. Using a single profile for all assets is a common mistake that either misses vulnerabilities, if the profile is too light, or causes load issues, if it is too aggressive.

  • Initial or discovery scan: Use a lightweight profile to build your asset inventory. This avoids performance impact on the first scan of an unknown environment.
  • Standard vulnerability scan: Works in 95% of all cases. Not authenticated unless manually added.
  • Sensitive or operational technology profile: A reduced port range, no exploit checks, and a low test count. This is mandatory for operational technology, industrial control systems, or any legacy system you have flagged as fragile.
  • Web application profile: OWASP-aligned checks, including cross-site scripting, SQL injection, cross-site request forgery, and authentication testing. Configure crawl depth and excluded paths before running. This profile performs dynamic testing on the application interface.

Use full port coverage on external assets
Use a Full TCP & UDP port profile on external assets to ensure no ports are open without your knowledge.

Avoiding scan overlap & conflicts

  • Stagger scan start times by at least 30 minutes when multiple schedules target overlapping IP ranges.
  • Use tag-based scoping on each schedule to ensure clean separation. Do not rely on IP range exclusions alone.
  • If you have change freeze windows, add a blackout window under scans setup.
  • After your first full scan cycle, review scan duration in your scan history and adjust windows if scans are overrunning.

What ports are covered?
Read more about what ports are covered in different scan levels. 

Checking asset coverage

  • Expected vs. discovered assets: Compare your original asset list against the assets that appeared in your first scan. A gap of more than 10% requires investigation before you proceed.
  • Common reasons for gaps: Firewall rules not yet applied, assets in excluded IP ranges, credentials not working on a subnet, or the Scanner Appliance not being reachable from an isolated VLAN.
  • Assets discovered but not in scope: Flag any new assets found during scanning that were not on your original list. Agree with your account team whether to add them to your license before your next scan.
  • Device Agent vs. scanner coverage: For endpoints that are offline during scan windows, such as laptops and remote workers, consider deploying a Device Agent for continuous coverage.
  • Scope vs. coverage: If you started with a smaller scope to grow into over time, make sure you feel comfortable proceeding with your entire intended scope, and address potential blockers immediately.