External Security Analysis · Entry level test

This is what an attacker sees of your company

Your systems answer questions from the internet, every day, to anyone. We ask the same questions an attacker asks and write down what comes back.

34 checks on your domain and IP address No access to your systems Report in 5 working days

199 € excl. VAT · fixed price

What a report looks like

An anonymised example from real assessments.

External analysis · Findings

34 checks

Remote access is open to the internet

Reachable from any country, around the clock. An attacker only needs a valid password.

Employee passwords sit in data leaks

Leaked from other services and freely available. If a password is reused, your access is open.

Emails can be forged in the company name

SPF, DKIM and DMARC are missing or ineffective. Invoices and payment requests in your name become possible.

An admin interface is reachable without protection

The login page of an internal system sits on the net, without a second factor and without restriction to known locations.

A forgotten test server still answers

Running for years, no longer updated, and nobody in the company feels responsible for it.

29 further checks with nothing to report

That is in the report too. You see what was checked and what is in order.

Your report names every point, with location and evidence, and says what to fix first.

Before anyone attacks, they look around. Which systems answer, where an old server is still running, whether emails can be forged in your name. None of it needs access to your systems, and you notice nothing.

We do the same, with your written permission, and stop where an attack would start. You get the report.

When the analysis makes sense

Six typical situations from practice.

IT that grew over the years

Systems were added over the years, some long forgotten. The analysis lists what is still reachable from the internet.

Website on WordPress or another CMS

Version, plugins and login page are often readable from the outside. We show what an attacker sees of it.

Your own servers on site

Mail, ERP or remote maintenance run at your site. The report shows whether any of it sits on the internet unintentionally.

Home office and remote access

VPN and remote maintenance are popular entry points. We check what answers there and how current it is.

Questionnaire from an insurer or client

Cyber insurers and large customers ask about the state of your IT. The report is documented evidence with a date.

Never checked from the outside

If nobody has done this yet, the outside view is the simplest way to find out where you stand. Check once, then you know.

What we check

34 checks across seven areas: active scans of your systems and research in public sources. Each area unfolds for the detail.

6Email & DNS Can someone send emails in your name?
  • SPF: is it defined which servers may send for you
  • DKIM: are your mails signed and is the key published validly
  • DMARC: is there a policy against spoofed senders and does anyone read the reports
  • MTA-STS and TLS-RPT: is encrypted delivery enforced
  • DNSSEC: are your DNS answers signed against manipulation
  • Name servers: zone transfer to the outside, redundancy and stale records
10Reachable services What answers from the internet? Forgotten systems, open admin access.
  • Open ports on your IP address, reviewed in full
  • Admin access from the internet: SSH, remote maintenance, interfaces of firewall, NAS and printers
  • Databases and file shares that answer to the outside
  • VPN endpoints and their version status
  • Service banners and product versions visible to the outside
  • Subdomains: full enumeration, including the forgotten ones
  • Test, staging and legacy systems that are still online
  • Orphaned DNS records pointing at third party cloud resources that can be taken over
  • Connected devices on the line: cameras, building technology, controllers
  • Cloud storage and shares without access protection
4Web configuration Is your website configured cleanly to the outside?
  • Security headers: enforced encryption, protection against injected content and framing by third party sites
  • Cookies: are they protected against reading and interception
  • Exposed paths and files: version control, configuration files, backups, open directory listings
  • Login and admin interfaces as well as recognisable system versions
4Reputation & credentials Are passwords for your domain sitting in leak collections? Do lookalike domains exist?
  • Company addresses in known leak collections, with source and date
  • Your domain and mail servers on block lists that cost you deliverability
  • Typo and lookalike domains suitable for fraud mail in your name
  • Certificates issued in your name, including ones you never ordered
1OSINT What is already in search engines and archives?
  • Indexed content that should not be public: documents and directories in search engines, old versions of your site in web archives, credentials and internal names in public code repositories, usable details in the metadata of your PDF and Office files
3Encryption Is your encryption up to date?
  • TLS versions and cipher suites: are outdated, attackable variants still offered
  • Certificates: chain, issuer, remaining validity and coverage of all names
  • Encryption of mail transport at your mail servers
6Vulnerabilities Are there known gaps in your reachable systems?
  • Known vulnerabilities in the detected products and versions
  • Comparison against the list of gaps demonstrably exploited in the wild
  • Software without vendor support, for which no security updates exist any more
  • Default and sample configurations left in place after installation
  • Third party components embedded in your website with known gaps
  • Misconfigurations that look harmless alone and form a path in combination

6 + 10 + 4 + 4 + 1 + 3 + 6 = 34 checks

What you get

  • PDF report Written by us in plain language. Every check was read and rated by a person.
  • Traffic light rating on page 1 Red, amber, green. The first page shows the overall picture and is enough for management.
  • Every finding with evidence, impact and recommendation What we found, what an attacker can do with it and what to do about it. Sorted by urgency.
  • 30 minute review We go through the report together, online or by phone. Your IT provider is welcome to join.

Important: checks we cannot perform are listed in the report with a reason. There is no "passed" for something that was not tested.

What this analysis cannot do

The analysis checks from the outside. What is only visible from the inside, it cannot judge. That is exactly what the IT Check is for, and it covers all of these points:

  • Phishing resistance of your staff
  • Whether your backups actually restore
  • Internal network and Active Directory configuration
  • Microsoft 365 settings
  • How ransomware would spread inside the house
  • Workstation security: updates, virus protection, encryption
  • Wi-Fi and separation of company and guest network
  • Server room, backup power and fire protection

This page

External Security Analysis

  • View from the outside, like an attacker
  • No access to your systems needed
  • 34 checks on domain and IP address
  • Report in 5 working days, about 10 minutes of your time

199 € excl. VAT

Book now

The full audit

IT Check

  • Audit from the inside, on site at your company
  • Over 100 checks in eight areas
  • Light penetration test included
  • Backup concept, user accounts, network, server room
  • We check whether an outage would genuinely stop you
  • Findings with an action plan within two weeks, presented in person

from 1.299 € excl. VAT · book a call

Go to the IT Check

How it runs

Three steps, five working days.

  1. You name domain and IP address

    Two details are enough. We find the subdomains ourselves.

  2. We scan and research

    34 checks: active scans on your addresses and research in public sources. No login attempts, your business carries on as normal. Your security monitoring may raise alerts, and you get our source IP in advance.

  3. Report and review

    Within 5 working days of approval. You receive the PDF and we discuss it in 30 minutes.

Your effort: about 10 minutes

Attackers move faster than any maintenance schedule

Nobody is looking for your company name. The search is for reachable systems, automated and around the clock. Once a gap becomes public it takes hours, not weeks, until it is tried everywhere.

  • 80 % of 320 test systems deliberately left exposed online were compromised within 24 hours. Unit 42, Palo Alto Networks
  • 52 s after going live a test server was attacked for the first time, on average 13 attempts per minute. Sophos, Cyberattacks on Cloud Honeypots

Businesses running a content management system or an online shop are hit hardest. A plugin nobody has updated for two years, a subdomain left over from an old campaign, a test system that was never switched off. In IT that has grown over time these are easy to miss, and from the outside they are visible immediately.

The external analysis shows you exactly what an attacker sees, before they try it. For 199 € and without access to your systems.

Price

One fixed price, one invoice. No subscription, no follow up costs.

199 € excl. VAT
1 domain the main address is assessed, subdomains we find are listed Included
1 IP address a single address, no matter what runs behind it How do I find my IP address? Included
Each additional domain or IP address for example a second location or a second brand 69 €
Report, review and follow up questions no follow up costs, no subscription Included

Example: a company with one domain and two further locations pays 199 € plus two times 69 €, so 337 € excl. VAT.

Book now

  • Delivered within 5 working days
  • Payment in advance, invoice with VAT shown
  • Your own domains and IPs only, verified before the scan (section 118a StGB if declared falsely)

Payment handled by Stripe. Privacy

Legal and trust

These commitments are in writing in the scan approval before we start:

  • We only check what you approved in writing
  • We change nothing on your systems and try no passwords
  • The report goes to you alone. No publication, no disclosure, no naming as a reference without your consent
  • The data is stored encrypted in Austria and deleted after the review on request
  • Based in Berndorf, Lower Austria. One contact with a name and a phone number

The analysis is not a full penetration test and not a security certificate. It shows the state at the time of the assessment. What you do with the findings is your decision.

Common questions

Will we notice anything?
Your business carries on as normal. Our scans only ask what your systems answer to the outside anyway, at normal pace and without load. There are no login attempts and we do not exploit any vulnerabilities. If you run security monitoring or protection software, the scan can trigger alerts there, just like a real attacker would. We share our source IP in advance so the alerts can be attributed. If everything stays quiet, that is a result for the report too.
What does the test say about my IT security?
It answers one question: does your business look like an easy target from the outside, waiting for an automated scan to come along, or does an attacker find nothing simple at your address. That is an important part of your IT security and a good place to start. What it looks like behind the door, meaning backups, user accounts, server room and network, is what the IT Check shows.
Is every subdomain assessed individually?
No. We look for which subdomains and addresses are publicly discoverable at all and list them in the report. What gets assessed is the domain and the IP address you release. So you see what is visible from the outside without it turning into an assessment of twenty systems.
How do I find my IP address?
Connect a computer to the company network and open icanhazip.com. What it shows is your public IP address. Most smaller businesses have exactly one. If yours has several, you will find them in your internet provider's customer portal or contract, or your IT provider can tell you. If you are unsure, we are happy to help.
Is this legal?
Yes, with your explicit approval. Active scanning without the owner's permission would not be lawful. You release the domains and IP addresses that are to be assessed. At payment you already confirm that you are authorised to control them. Once the order reaches us we cross check the details against public registers and call you if anything is unclear. If something does not add up we run no scan and refund the amount.
What if nothing is found?
Then that is exactly what the report says, with evidence that the check ran. You hold a dated, documented outside view you can present to an insurer, a client or your management. In our experience though, almost every company has at least one forgotten system or a spoofable sender address.
Do we need our IT provider for this?
Not for the analysis. All we need is the domain, the IP address and your approval. Your IT provider then implements the recommendations in the report. They are welcome to join the review call.
What happens to the data?
The report goes to you alone. We publish nothing, disclose nothing to third parties and do not name you as a reference without your consent. The data is stored encrypted in Austria and deleted after the review on request, at the latest after twelve months.

Ready?

Know what is visible from the outside

Send us your domain and IP address. You release the assessment and get the report five working days later.

Price 199 € excl. VAT

How secure is your IT really?

The IT Check reviews your IT across 8 areas with more than 100 checks. Findings within two weeks, from 1,299 € excl. VAT.