A practical look for the obvious ways in.
An external check for the weaknesses that actually get small businesses breached — exposed services, weak logins, out-of-date systems, misconfigurations. Clearly scoped and honest about its limits: this is a focused first look, not a deep red-team engagement. You get findings in plain English and a fix list ranked by what matters.
Straight about scope
This is light, external testing sized for a small business — the kind of check that catches the issues attackers find first. It is not a full red-team engagement, a deep application audit, or a compliance-grade penetration test. If you need one of those, I'll tell you plainly and point you to a specialist firm.
Everything included.
- An external scan of your internet-facing systems for exposed services and known weaknesses
- A check of common ways in — weak or missing MFA, default and reused credentials, exposed admin panels
- A review of your public footprint for information that quietly helps an attacker
- A basic look at your main website or app for the obvious, high-impact issues
- A plain-English report a non-technical owner can actually read and act on
- A fix list ranked by real risk, with what to do first and what can wait
- A short call to walk through findings and answer questions
Start to finish.
Scope in writing
We agree exactly what's in bounds and get written authorization before anything is touched. No surprises.
The look
The external checks run against the agreed targets, carefully, without disrupting your business.
Findings, in plain terms
What I found, why it matters, and how bad it really is — no jargon, no scare tactics.
The list
A prioritized fix list and a call to talk through it. Retesting a fix is included.
Scales with how many systems and domains are in scope. A single site and a handful of services sits near the bottom. Quoted before we start, always with written authorization first.
Start hereAsked often enough to write down.
Will this break anything?
No. The testing is external and non-disruptive by design, run against systems we've agreed on in writing. Anything intrusive is discussed and authorized first, or it doesn't happen.
How is this different from a “real” pen test?
Depth. A full penetration test or red-team engagement digs much deeper, chains exploits, and often tests internal systems and staff. This is a focused, affordable first look at the issues that get small businesses breached most often. For many small businesses it's exactly the right size — and I'll tell you if it isn't.
Do you need access to our systems?
For the external testing, no — just the addresses and written permission. If you want me to look at something internal, that's scoped and authorized separately.
Can you just fix what you find?
Often, yes — and if it's a good fit, the security & planning program picks up where the fix list leaves off. I'll never invent findings to sell more work.
Want a look before someone else takes one?
Tell me what you'd want checked. I'll scope it honestly — including if a deeper test is what you actually need.
Get in touch