External Security Posture Assessment

External Security Assessment

See What Attackers See

A non-intrusive review of your public attack surface — and how to close it.

Prepared for your organization  ·  —

My Computer Guy logo
Email
DNS
Website
Encryption
Hosting
Reporting

What you can't see, you can't defend

How an attacker sees you today

Find your domain

name, email, DNS

Read your setup

how mail is configured

Probe DNS & site

look for weak spots

Walk the weak door

before you notice

What no one is checking from the outside

Email that can be spoofed — SPF, DKIM & DMARC left unenforced

DNS that can be forged — DNSSEC never switched on

An exposed origin server — no shield against direct attack or floods

Forgotten logins & old pages — unmonitored doors left open

Attackers map all of this before they ever touch you — quietly, and for free.

Why it matters now

The ground shifted under small business

Attacks are automated, email is the front door, and insurers now expect real controls.

9 in 10

breaches begin with a phishing email

Minutes

to spoof an unprotected domain — no hacking

~3 weeks

typical downtime after a ransomware incident

MFA · EDR · Backups

the baseline insurers now expect

None of this requires being “a target.” It only requires being reachable.

Representative industry figures — current sources available on request.

Your stack at a glance

Six views into your exposure

The same surface an attacker sees first — examined and rated, one layer at a time.

Click any layer to jump to the details.

Email authentication

Can criminals send email as you?

SPF, DKIM and DMARC — the records that prove your mail is really yours.

Answers the question

“Anyone can send a fake invoice as you. Can you prove they can't?”

In plain English

The behind-the-scenes records that let the world verify a message truly came from your domain.

What we check — whether SPF, DKIM and DMARC exist, and whether DMARC is actually enforced or just watching.

The risk — an unprotected domain is spoofed in minutes; customers can't tell the fake invoice from the real one.

How we secure it — publish and align the records, then move DMARC to reject safely — without breaking real mail.

You keep visibility — reporting is switched on so you can see everyone sending as your domain.

Email protection & visibility

Is your mail encrypted — and watched?

Transport security, abuse reporting, and trusted-logo branding.

Answers the question

“If your name were being abused, would you even know?”

In plain English

Controls that keep mail encrypted in transit, surface abuse of your domain, and can display your verified logo.

What we check — MTA-STS and TLS-RPT for encrypted delivery, your inbound filtering, and any BIMI setup.

The risk — mail can be silently downgraded or intercepted, and domain abuse goes unseen for months.

How we secure it — enforce encrypted delivery and switch on reporting so threats become visible.

Bonus — where it helps your brand, qualify to show your verified logo beside authenticated mail.

DNS integrity

Can your DNS be forged?

DNSSEC signs your DNS so it can't be faked; CAA controls who may issue your certificates.

Answers the question

“What if visitors and email were quietly sent somewhere else?”

In plain English

DNS is the internet's address book that points people to your site and routes your mail.

What we check — whether DNSSEC is enabled and validating, and whether CAA restricts certificate issuance.

The risk — tampered DNS can redirect visitors and mail to attacker systems with no visible sign.

How we secure it — enable DNSSEC end-to-end and publish CAA to lock down who can issue certificates.

We also review — your DNS provider and registrar safeguards against domain hijacking.

Website & application

What's exposed on your website?

The platform you run on, and anything old or forgotten still reachable online.

Answers the question

“Is there a forgotten login still open to the internet?”

In plain English

The software your website runs on, plus any legacy pages, logins or test sites still public.

What we check — your CMS and its components, and any legacy pages, logins or test sites still reachable.

The risk — outdated website software is the most exploited way in; a forgotten page is an unmonitored door.

How we secure it — flag outdated components and needless exposure, and help you patch and retire them.

Web encryption

Is every visit actually secure?

Modern TLS encryption plus the browser protections that block common web attacks.

Answers the question

“Does the padlock really mean what people think it means?”

In plain English

The encryption on your site, plus behind-the-scenes browser instructions that stop common attacks.

What we check — your TLS configuration and certificate, plus security headers like HSTS and CSP.

The risk — weak encryption lets data be intercepted; missing headers enable clickjacking and injection.

How we secure it — verify strong, modern encryption and implement the full set of recommended protections.

Hosting & infrastructure

Is your infrastructure shielded?

Where your site lives, and whether it's protected from direct attack and floods.

Answers the question

“Could a single flood knock you offline for a week?”

In plain English

The servers and network your site runs on, and whether they sit behind protective services.

What we check — your hosting, whether the origin server is exposed, and any CDN, WAF or DDoS protection.

The risk — an exposed origin can be attacked directly or taken offline, bypassing your other defenses.

How we secure it — recommend protective layers that hide and shield your systems while improving speed.

How we prioritize

We tell you what to fix first

Every finding is rated by real business risk — then sequenced by impact against effort.

Critical

Fix immediately — directly enables impersonation, interception, or takeover.

High

Fix soon — a core protection is missing or materially weakened.

Medium

Plan to fix — raises your risk and should be closed on a reasonable timeline.

Low

Hardening — worth doing to reach a strong, resilient posture.

Many of the highest-impact fixes are also the quickest and cheapest.

Let's talk it through

Fair questions, straight answers

“Isn't a security scan risky or disruptive?”

No — we read only publicly available information. Nothing is logged into, nothing is attacked, and there is no impact on your systems or uptime.

“We're too small to be worth assessing.”

Attackers scan by opportunity, not headcount. Most small-business domains have gaps that take minutes to exploit — this finds them before someone else does.

“Doesn't Microsoft 365 or Google already handle this?”

These protections ship mostly switched off. Turning them on, aligning them and monitoring them is the actual work — and it rarely gets done without someone checking from outside.

What you get

A clear picture, safely obtained

HOW WE WORKSafe by design

Publicly available data only — we look at what anyone can see; nothing private is touched.

Zero access without authorization — nothing is logged into or probed beyond public records.

No downtime, no disruption — your systems and your team never feel it happen.

WHAT YOU RECEIVEYours to keep

Executive summary — the business-level picture, in plain language for leadership.

Rated findings with evidence — each issue, why it matters, and how to fix it.

Prioritized remediation roadmap — what to do first, next and later.

Scorecard & optional benchmark — an at-a-glance grade, and how you compare to peers.

Getting started

A short, low-lift engagement

STEP 1

Scope & authorize

  • Confirm the domains in scope
  • Sign a short authorization
STEP 2

Assess

  • Non-intrusive external review
  • All six areas covered
STEP 3

Findings review

  • Rated results and priorities
  • Walked through together
STEP 4

Remediate & verify

  • We help close the gaps
  • Re-test to confirm
THEN, ONGOINGQuarterly re-assessmentContinuous monitoring optionsA plain-English report each time

Next steps

Find your gaps first

1
A free external assessment

We map your public exposure — no obligation, no pressure.

2
A plain-English findings review

Ranked risks and what to fix first. Yours to keep either way.

3
A clear remediation plan

We help you close what matters — and verify it's done.

Find your gaps before someone else does.

My Computer Guy logo
My Computer Guy Industry figures are representative averages; current sources available on request. This overview describes our standard external assessment; scope is confirmed per engagement. © My Computer Guy — Managed IT & Security.