Security check from the outside

External Security Analysis

We scan your systems and search the net with the same methods an attacker uses: open access points, spoofable senders, leaked passwords. You get a report in plain language and know what to do.

34 checks on your domain and site IP No access to your systems Report in 5 working days

399 € excl. VAT · fixed price

Before someone attacks a company, they look around. Which systems are reachable from the internet? Is an old test server still running somewhere? Can emails be faked in the company's name? Are employee passwords sitting in data leaks?

To do that, they scan your addresses, try out what answers and collect everything about the company that sits on the net. They need no access to your systems for this, and you notice nothing.

The external security analysis does exactly that, with your written permission. The same scans, the same sources, the same tools an attacker uses. The difference: we stop where an attack would begin, and you get the report.

What we check

34 checks across seven areas: active scans of your systems and research in public sources. Each area unfolds for the detail.

6Email & DNS Can someone send emails in your name?
  • SPF: is it defined which servers may send for you
  • DKIM: are your mails signed and is the key published validly
  • DMARC: is there a policy against spoofed senders and does anyone read the reports
  • MTA-STS and TLS-RPT: is encrypted delivery enforced
  • DNSSEC: are your DNS answers signed against manipulation
  • Name servers: zone transfer to the outside, redundancy and stale records
10Reachable services What answers from the internet? Forgotten systems, open admin access.
  • Open ports on your site IP, reviewed in full
  • Admin access from the internet: SSH, remote maintenance, interfaces of firewall, NAS and printers
  • Databases and file shares that answer to the outside
  • VPN endpoints and their version status
  • Service banners and product versions visible to the outside
  • Subdomains: full enumeration, including the forgotten ones
  • Test, staging and legacy systems that are still online
  • Orphaned DNS records pointing at third party cloud resources that can be taken over
  • Connected devices on the line: cameras, building technology, controllers
  • Cloud storage and shares without access protection
4Web configuration Is your website configured cleanly to the outside?
  • Security headers: enforced encryption, protection against injected content and framing by third party sites
  • Cookies: are they protected against reading and interception
  • Exposed paths and files: version control, configuration files, backups, open directory listings
  • Login and admin interfaces as well as recognisable system versions
4Reputation & credentials Are passwords for your domain sitting in leak collections? Do lookalike domains exist?
  • Company addresses in known leak collections, with source and date
  • Your domain and mail servers on block lists that cost you deliverability
  • Typo and lookalike domains suitable for fraud mail in your name
  • Certificates issued in your name, including ones you never ordered
1OSINT What is already in search engines and archives?
  • Indexed content that should not be public: documents and directories in search engines, old versions of your site in web archives, credentials and internal names in public code repositories, usable details in the metadata of your PDF and Office files
3Encryption Is your encryption up to date?
  • TLS versions and cipher suites: are outdated, attackable variants still offered
  • Certificates: chain, issuer, remaining validity and coverage of all names
  • Encryption of mail transport at your mail servers
6Vulnerabilities Are there known gaps in your reachable systems?
  • Known vulnerabilities in the detected products and versions
  • Comparison against the list of gaps demonstrably exploited in the wild
  • Software without vendor support, for which no security updates exist any more
  • Default and sample configurations left in place after installation
  • Third party components embedded in your website with known gaps
  • Misconfigurations that look harmless alone and form a path in combination

6 + 10 + 4 + 4 + 1 + 3 + 6 = 34 checks

What you get

  • PDF report, 6 to 12 pages Written by us in plain language. Every check was read and rated by a person.
  • Traffic light rating on page 1 Red, amber, green. The first page shows the overall picture and is enough for management.
  • Every finding with evidence, impact and recommendation What we found, what an attacker can do with it and what to do about it. Sorted by urgency.
  • 30 minute review We go through the report together, online or by phone. Your IT provider is welcome to join.

Important: checks we cannot perform are listed in the report with a reason. There is no "passed" for something that was not tested.

What this analysis cannot do

The analysis checks from the outside. What is only visible from the inside, it cannot judge. That is exactly what the IT Check is for, and it covers all of these points:

  • Phishing resistance of your staff
  • Whether your backups actually restore
  • Internal network and Active Directory configuration
  • Microsoft 365 settings
  • How ransomware would spread inside the house
  • Workstation security: updates, virus protection, encryption
  • Wi-Fi and separation of company and guest network
  • Server room, backup power and fire protection

This page

External Security Analysis

  • View from the outside, like an attacker
  • No access to your systems needed
  • 34 checks on domain and site IP
  • Report in 5 working days, about 10 minutes of your time

399 € excl. VAT

The full audit

IT-Check

  • Audit from the inside, on site at your company
  • Over 100 checks in eight areas, light penetration test included
  • Backups with a tested restore, user accounts, network, server room
  • Findings with an action plan within two weeks, presented in person
  • On request as an independent second opinion alongside your IT partner

from 1.299 € excl. VAT · first call, no charge

Go to the IT Check

How it runs

Four steps, five working days.

You name domain and site IP

Two details are enough. We find the subdomains ourselves.

You sign the scan approval

One page with scope, addresses and time window. We do not start without the signature.

We scan and research

34 checks: active scans on your addresses and research in public sources. No login attempts, your business carries on as normal. Your security monitoring may raise alerts, and you get our source IP in advance.

Report and review

Within 5 working days of approval. You receive the PDF and we discuss it in 30 minutes.

Your effort: about 10 minutes

Price

One fixed price, one invoice. No subscription, no follow up costs.

399 € excl. VAT
1 domain including every subdomain we find Included
1 site IP one connection up to /29, meaning up to eight addresses Included
Each additional domain or site IP for example a second location or a second brand 99 €
Report, review and follow up questions no follow up costs, no subscription Included

Example: a company with one domain and three locations pays 399 € plus two times 99 €, so 597 € excl. VAT.

Legal and trust

These commitments are in writing in the scan approval before we start:

  • We only check what you approved in writing
  • We change nothing on your systems and try no passwords
  • The report goes to you alone. No publication, no disclosure, no naming as a reference without your consent
  • The data is stored encrypted in Austria and deleted after the review on request
  • Based in Berndorf, Lower Austria. One contact with a name and a phone number

The analysis is not a full penetration test and not a security certificate. It shows the state at the time of the assessment. What you do with the findings is your decision.

Common questions

Will we notice anything?
Your business carries on as normal. Our scans only ask what your systems answer to the outside anyway, at normal pace and without load. There are no login attempts and we do not exploit any vulnerabilities. If you run security monitoring or protection software, the scan can trigger alerts there, just like a real attacker would. We share our source IP in advance so the alerts can be attributed. If everything stays quiet, that is a result for the report too.
Is this legal?
Yes, with your approval. Active scanning without the owner's permission would not be lawful. That is why you sign a one page scan approval up front with domain, IP address and time window. We do not start without it.
What if our website is hosted by a provider?
That is the normal case and changes nothing about the process. Findings that sit with the hosting provider are marked as such. We write the recommendation so you can forward it to the provider directly.
What if nothing is found?
Then that is exactly what the report says, with evidence that the check ran. You hold a dated, documented outside view you can present to an insurer, a client or your management. In our experience though, almost every company has at least one forgotten system or a spoofable sender address.
Do we need our IT provider for this?
Not for the analysis. All we need is the domain, the site IP and the signed approval. Your IT provider then implements the recommendations in the report. They are welcome to join the review call.
What happens to the data?
The report goes to you alone. We publish nothing, disclose nothing to third parties and do not name you as a reference without your consent. The data is stored encrypted in Austria and deleted after the review on request, at the latest after twelve months.

Ready?

Know what is visible from the outside

Send us your domain and site IP. You receive the scan approval to sign and, five working days later, the report.

Price 399 € excl. VAT
Request the analysis

How secure is your IT really?

The IT Check reviews your IT across 8 areas with more than 100 checks. Findings within two weeks, from 1,299 € excl. VAT.