Find out what an attacker can already see.
Tell us your domain and roughly what you run. You get back a written assessment of your actual exposure, scored across seven domains against the CIS Controls v8 baseline, with every finding mapped to a numbered fix. No credentials are used and no systems are touched.
Counts from our published sample assessment of a fictional distributor. A real one reflects your environment.
Seven domains, each scored out of five.
This is the scorecard from the front of the report. None of it required access to anything: it is built from public DNS and web signals plus what you tell us on the form. The rubric follows CIS Controls v8 Implementation Group 1, the same baseline we run on every managed client.
Email trust and anti-phishing
1 / 5 CriticalDMARC absent, DKIM absent, SPF soft-fails. The domain is spoofable right now.
Detection and response
1 / 5 CriticalNo centralised logging. No retention beyond 90 days. No named incident-response arrangement.
Identity and access
2 / 5 High riskMulti-factor not enforced tenant-wide. No conditional access. Contractors on personal email.
Backup and recovery
2 / 5 High riskNo independent Microsoft 365 backup. Ransomware or an insider deletes SharePoint and it stays gone.
Endpoint and device
2 / 5 High riskContractor devices unmanaged, no device management, encryption unverified, endpoint detection inconsistent.
Data governance
2 / 5 High riskPIPEDA-regulated data handled without formal classification or an incident-response plan.
Network and perimeter
3 / 5 MediumHosting control panel reachable from the public internet. No documented segmentation between sites.
Most of your exposure is already public.
People assume a security review needs to be let inside. The findings that matter most usually do not, because the configuration an attacker cares about is published in DNS or handed out in an HTTP response. Here is what we read.
Whether anyone can send email as you.
SPF policy and mechanism, DKIM selectors and key length, DMARC presence and policy, MTA-STS and TLS reporting. This is the most common critical finding we publish, and it is the direct path to invoice fraud.
Whether your DNS answers can be forged.
DNSSEC signing, CAA issuance restriction, TLS versions offered, certificate issuer and validity. Without a CAA record, any certificate authority in the world can issue a certificate for your domain.
What is reachable that should not be.
Exposed hosting control panels, admin logins with no rate limiting, directories that list their own contents, and the security header baseline. These are found by looking, not by attacking.
Which of your addresses are already in breach data.
We check your domain against public breach corpora and flag executive addresses. A reused password plus no enforced multi-factor is a live account takeover, not a theoretical one.
The report shows how it ends.
Not fear-marketing. A step-by-step reconstruction using only techniques that appear in real Canadian SMB breach reports from the last eighteen months, run against the posture we just measured. Thirty days, because that is roughly the dwell time before a business email compromise gets noticed.
Reconnaissance
Your domain is enumerated from public sources. LinkedIn identifies the controller and procurement staff. There is no DMARC record. One executive password is already sitting in a breach corpus from 2023.
Stopped by DMARC enforcement, tenant-wide multi-factor, dark web credential monitoring.
The spoofed invoice
An invoice arrives from an address on your own domain, because nothing in DNS tells the receiving server to reject it. It looks internal because, as far as authentication is concerned, it is.
Stopped by DMARC set to reject, advanced email security with impersonation protection.
Quiet access
A reused password opens a mailbox. With no multi-factor there is nothing else to defeat. Forwarding rules go in, vendor threads get read, the payment cycle is learned. Nobody notices, because nothing is logged and nothing is watching.
Stopped by Enforced multi-factor, conditional access, centralised logging with retention.
The wire goes out
Banking details on a real invoice from a real vendor are changed. The payment is authorised by someone doing their job correctly, against a thread that has been running for weeks. The money is gone before the vendor asks where it is.
Stopped by Any single control above. That is the uncomfortable part: this chain needs every one of them to be missing.
Median loss and 18-day median dwell time: Canadian Anti-Fraud Centre, 2025 statistics.
It ends with a plan, not a proposal.
Nineteen numbered remediation items across three phases, each with an effort estimate, an impact rating and the CIS safeguard it satisfies. The report is written so you can run it yourself, hand it to your current provider, or ask us. All three are real options.
Discovery.
A 30-minute call, a read-only tenant audit, device inventory, a review of what you already pay for, then a refined scope and a firm quote. This is where estimates become numbers.
Stabilise.
Every critical item. DMARC, DKIM and SPF hardened, multi-factor and conditional access enforced tenant-wide, password manager rolled out, external attack surface locked down.
Foundation.
Contractor identity cleanup, device management and endpoint baseline, independent Microsoft 365 backup, advanced email security, and data classification.
How the estimates read.
XS is under two hours, S is two to eight hours, M is one to three days, L is four to ten days. Phase 1 ships before Phase 2 begins, so the order is decided rather than negotiated later.
What this is not.
This is a preliminary review, not a penetration test. It is produced from your intake form, public DNS queries, HTTP header and TLS inspection of your public web presence, passive review of indexed content, and a public breach-corpus lookup for addresses on your domain. No credentials are tested, nothing is exploited, and no intrusive scanning is performed.
It does not test your internal network, audit your Microsoft 365 tenant from the inside, review endpoint posture, or phish your staff. Those need a scoped engagement under an NDA, which we price from $2,500 and will only propose if the findings justify it. If they do not, we will tell you that too, and you keep the report either way. See assessments and penetration testing for the full engagement.
Three required fields. The rest are optional and only make the findings sharper, because we gather the public signals ourselves and these answers are what let us tell you which of them actually matter for your environment. Or call 672-983-1174 during business hours.