External Security Assessment
A non-intrusive review of your public attack surface — and how to close it.
Prepared for your organization · —
What you can't see, you can't defend
name, email, DNS
how mail is configured
look for weak spots
before you notice
Email that can be spoofed — SPF, DKIM & DMARC left unenforced
DNS that can be forged — DNSSEC never switched on
An exposed origin server — no shield against direct attack or floods
Forgotten logins & old pages — unmonitored doors left open
Attackers map all of this before they ever touch you — quietly, and for free.
Why it matters now
Attacks are automated, email is the front door, and insurers now expect real controls.
breaches begin with a phishing email
to spoof an unprotected domain — no hacking
typical downtime after a ransomware incident
the baseline insurers now expect
None of this requires being “a target.” It only requires being reachable.
Representative industry figures — current sources available on request.
Your stack at a glance
The same surface an attacker sees first — examined and rated, one layer at a time.
Click any layer to jump to the details.
Email authentication
SPF, DKIM and DMARC — the records that prove your mail is really yours.
Answers the question
“Anyone can send a fake invoice as you. Can you prove they can't?”
In plain English
The behind-the-scenes records that let the world verify a message truly came from your domain.
What we check — whether SPF, DKIM and DMARC exist, and whether DMARC is actually enforced or just watching.
The risk — an unprotected domain is spoofed in minutes; customers can't tell the fake invoice from the real one.
How we secure it — publish and align the records, then move DMARC to reject safely — without breaking real mail.
You keep visibility — reporting is switched on so you can see everyone sending as your domain.
Email protection & visibility
Transport security, abuse reporting, and trusted-logo branding.
Answers the question
“If your name were being abused, would you even know?”
In plain English
Controls that keep mail encrypted in transit, surface abuse of your domain, and can display your verified logo.
What we check — MTA-STS and TLS-RPT for encrypted delivery, your inbound filtering, and any BIMI setup.
The risk — mail can be silently downgraded or intercepted, and domain abuse goes unseen for months.
How we secure it — enforce encrypted delivery and switch on reporting so threats become visible.
Bonus — where it helps your brand, qualify to show your verified logo beside authenticated mail.
DNS integrity
DNSSEC signs your DNS so it can't be faked; CAA controls who may issue your certificates.
Answers the question
“What if visitors and email were quietly sent somewhere else?”
In plain English
DNS is the internet's address book that points people to your site and routes your mail.
What we check — whether DNSSEC is enabled and validating, and whether CAA restricts certificate issuance.
The risk — tampered DNS can redirect visitors and mail to attacker systems with no visible sign.
How we secure it — enable DNSSEC end-to-end and publish CAA to lock down who can issue certificates.
We also review — your DNS provider and registrar safeguards against domain hijacking.
Website & application
The platform you run on, and anything old or forgotten still reachable online.
Answers the question
“Is there a forgotten login still open to the internet?”
In plain English
The software your website runs on, plus any legacy pages, logins or test sites still public.
What we check — your CMS and its components, and any legacy pages, logins or test sites still reachable.
The risk — outdated website software is the most exploited way in; a forgotten page is an unmonitored door.
How we secure it — flag outdated components and needless exposure, and help you patch and retire them.
Web encryption
Modern TLS encryption plus the browser protections that block common web attacks.
Answers the question
“Does the padlock really mean what people think it means?”
In plain English
The encryption on your site, plus behind-the-scenes browser instructions that stop common attacks.
What we check — your TLS configuration and certificate, plus security headers like HSTS and CSP.
The risk — weak encryption lets data be intercepted; missing headers enable clickjacking and injection.
How we secure it — verify strong, modern encryption and implement the full set of recommended protections.
Hosting & infrastructure
Where your site lives, and whether it's protected from direct attack and floods.
Answers the question
“Could a single flood knock you offline for a week?”
In plain English
The servers and network your site runs on, and whether they sit behind protective services.
What we check — your hosting, whether the origin server is exposed, and any CDN, WAF or DDoS protection.
The risk — an exposed origin can be attacked directly or taken offline, bypassing your other defenses.
How we secure it — recommend protective layers that hide and shield your systems while improving speed.
How we prioritize
Every finding is rated by real business risk — then sequenced by impact against effort.
Fix immediately — directly enables impersonation, interception, or takeover.
Fix soon — a core protection is missing or materially weakened.
Plan to fix — raises your risk and should be closed on a reasonable timeline.
Hardening — worth doing to reach a strong, resilient posture.
Many of the highest-impact fixes are also the quickest and cheapest.
Let's talk it through
No — we read only publicly available information. Nothing is logged into, nothing is attacked, and there is no impact on your systems or uptime.
Attackers scan by opportunity, not headcount. Most small-business domains have gaps that take minutes to exploit — this finds them before someone else does.
These protections ship mostly switched off. Turning them on, aligning them and monitoring them is the actual work — and it rarely gets done without someone checking from outside.
What you get
Publicly available data only — we look at what anyone can see; nothing private is touched.
Zero access without authorization — nothing is logged into or probed beyond public records.
No downtime, no disruption — your systems and your team never feel it happen.
Executive summary — the business-level picture, in plain language for leadership.
Rated findings with evidence — each issue, why it matters, and how to fix it.
Prioritized remediation roadmap — what to do first, next and later.
Scorecard & optional benchmark — an at-a-glance grade, and how you compare to peers.
Getting started
Next steps
We map your public exposure — no obligation, no pressure.
Ranked risks and what to fix first. Yours to keep either way.
We help you close what matters — and verify it's done.
Find your gaps before someone else does.