Skip to main content
CY6Check Your Six

Cybersecurity risk assessment

Find out what you are exposed tobefore you decide it is worth fixing

The external scan is free, takes about fifteen minutes and needs nothing more than your domain name. It reports what an attacker can already see about your firm from outside your network — which is the same thing they would start from. You keep the report whether or not you ever speak to us again.

Why people run it

Four reasons, and none of them are fear

We do not publish breach statistics and we are not going to start here. These are the situations people describe when they actually pick up the phone.

  • You think coverage costs too much

    That is a reasonable thing to think before you know what you are exposed to. Run the assessment, get a number for what your exposure actually is, and then decide. If it turns out you are in good shape, we will tell you so and you will have paid nothing for a straight answer.

  • You want an audit and do not know where one starts

    It starts here. The external scan is free and takes a quarter of an hour. If the results warrant going further, the full assessment looks at everything the external scan cannot see, and you own the report either way.

  • Somebody has asked you for evidence

    An insurer at renewal, a corporate client with outside counsel guidelines, a regulator. The assessment produces a scored report with findings prioritised by risk, which is a considerably better answer than a description of your intentions.

  • You inherited the environment and nobody documented it

    The asset inventory alone is often worth the exercise. A surprising number of firms discover machines, accounts and cloud applications that nobody currently employed knew were running.

What it checks

Two levels. One of them costs nothing.

The difference is not depth of reporting, it is line of sight. One looks at you from the internet. The other looks from inside the building.

Start here

External scan

Free

No card, no commitment, no obligation to talk to us afterwards

Everything an attacker can learn about you without touching your network. This is the view from outside your front door, and it is the view they start from.

What it needs
Your domain name, and any public IP addresses you own
How long
Ten to fifteen minutes to run
  • External vulnerabilities on anything you publish to the internet
  • Open ports and what is answering on them
  • TLS certificate problems and whether HTTPS is enforced
  • Dark-web breach exposure, graded by how recent it is
  • Email and domain records that let somebody impersonate you

What it will not tell youIt cannot see inside your network. A firm can score well here and still have every workstation unpatched behind the firewall, which is exactly why the internal assessment exists.

Run the free scan (opens in a new tab)

Full risk assessment

$500

Or included with a coverage membership, on whatever cadence you want it

The external scan, plus everything that is only visible from inside: the machines, the accounts, the cloud tenant and the data sitting on it.

What it needs
A temporary agent installed on the network, with your permission
How long
About ten minutes to set up, then two to three hours to run
  • Internal vulnerability scanning across the machines on your network
  • Application scanning, both cloud applications and installed desktop software
  • Detection of personally identifiable information sitting on your systems
  • Identity and access management review
  • Password security, including credentials saved in browsers
  • Microsoft 365 tenant security configuration
  • Full asset inventory, so you know what you actually own

What it will not tell youIt is a point-in-time picture. An environment that scores well in March can drift by September, which is the argument for continuous monitoring rather than for a bigger annual report.

Ask about a full assessment

Straight answer

Why this one asks who you are

The six-point check on this site gives you its answer immediately and transmits nothing, because it only ever asked you questions about yourself. This is different: it scans infrastructure you own, which means we need to know who you are and that you are authorised to ask for it. Scanning a domain on behalf of somebody who does not control it is not a service, it is a probe. The report is yours regardless of whether you ever speak to us again.

If you would rather have an answer without giving anyone anything, the six-point check is on this site, takes two minutes, and transmits nothing at all.

Where it fits

An assessment is a photograph, not a smoke alarm

This is worth being clear about, because the industry generally is not. A risk assessment tells you what is true today. It does not tell you what changed last night.

What the assessment does

Produces a scored report with findings prioritised by risk, an inventory of what you actually own, and a list you can work through in order. It is the right starting point and it is often the only thing a firm needs in order to make a decision.

What coverage adds

Somebody watching between the photographs, and somebody fixing what the report found. Members get the full assessment periodically rather than paying per run, which is the honest version of “continuous” — a scan on a schedule, plus monitoring in between.

See what coverage costs

Run the scan first

It is free, it takes fifteen minutes, and it will tell you whether this conversation is worth having at all. We would rather you found out than took our word for it.

Or call 1-855-966-2967