External digital exposure assessment

VERCOD CyberCheck

What can a potential attacker see about your company?

A cyberattack often begins long before an attacker makes the first attempt to access an information system. Publicly available information, domains, email addresses, misconfigurations, exposed services and other digital traces may reveal more than you expect.

VERCOD CyberCheck shows you how your company appears from the perspective of a potential attacker and identifies practical measures that can reduce your digital exposure.

Analytical view of a company external digital exposure security assessment
VERCOD CYBERCHECKExternal digital exposure assessment

VERCOD CYBERCHECK

What is VERCOD CyberCheck?

VERCOD CyberCheck is a VERCOD d.o.o. service for assessing an organisation’s external digital exposure.

CyberCheck analyses publicly available digital information, domains, subdomains, email security, exposed services and other digital traces that a potential attacker could use when preparing a cyberattack.

Why CyberCheck?

See your company through the eyes of a potential attacker.

Discover your digital exposure before someone exploits it.

From findings to practical action.

Cybersecurity starts with understanding your own exposure.

What a potential attacker may see

Do you know what can be discovered about your company?

Before attempting an attack, a potential attacker may examine a wide range of publicly available technical and business information:

  • web domains
  • subdomains
  • DNS information
  • publicly accessible servers
  • web technologies
  • SSL/TLS certificates
  • email addresses
  • public information about employees
  • management information
  • business contact details
  • old or forgotten web services
  • email security configuration
  • information from known data breaches
  • information useful for phishing
  • information useful for social engineering
  • information useful for CEO fraud
  • information useful for Business Email Compromise – BEC

CyberCheck examines this information from a defensive perspective – so you can see it before someone else uses it against you.

VERCOD CYBERCHECK

What do we assess?

The assessment focuses on the organisation’s external attack surface and publicly available digital traces.

01

Digital Exposure

A review of the organisation’s publicly visible technical footprint.

  • domains
  • subdomains
  • DNS
  • publicly exposed services
  • web applications
  • web technologies
  • SSL/TLS certificates
02

Email Security

A review of controls designed to protect the domain and email environment.

  • SPF
  • DKIM
  • DMARC
  • spoofing exposure
  • domain impersonation risk
  • phishing exposure
03

Digital Footprint

A review of publicly available information.

  • the company
  • contact details
  • employees
  • employee roles
  • management
  • the organisation
  • business relationships
04

Social Engineering Exposure

Information that could support a targeted deception attempt.

  • phishing
  • spear phishing
  • CEO fraud
  • BEC
  • impersonation
  • social engineering
05

Known Data Breaches

Where lawful and technically possible.

  • known data breaches
  • compromised email addresses
  • compromised user accounts
  • publicly known data disclosures

Assessment outcome

More than a list of technical findings

CyberCheck is not merely an automated technical scan. Findings are reviewed, assessed and presented in a way that is useful both to technical teams and company management.

Depending on the selected package, the client receives:

  • an external digital exposure assessment
  • identification of material risks
  • findings classified by severity
  • a concise written summary
  • an explanation of potential consequences
  • practical recommendations
  • measures the organisation can implement itself
  • a prioritised action list
  • suggestions for further specialist activities

Clear prioritisation

Risk levels

LOW

The finding does not usually represent an immediate threat, but an improvement is recommended.

MEDIUM

A potential attacker could use the finding when preparing an attack.

HIGH

Prompt remediation is recommended.

CRITICAL

The finding represents a material risk and requires priority attention.

VERCOD CYBERCHECK

VERCOD CyberCheck packages

Choose an assessment scope suited to the size and needs of your organisation. Pricing is provided following an enquiry.

CyberCheck Basic

Essential digital exposure assessment

Small businesses and organisations performing their first digital exposure assessment.

Includes

  • assessment of one primary domain
  • basic DNS review
  • subdomain review
  • SSL/TLS review
  • basic discovery of publicly exposed services
  • SPF, DKIM and DMARC
  • basic domain impersonation review
  • basic review of publicly available contact information
  • basic digital exposure rating

The client receives

  • a concise written summary
  • a list of key findings
  • risk classification
  • essential recommendations
  • measures the organisation can implement itself
Request CyberCheck Basic

CyberCheck Pro

Continuous digital exposure monitoring

A contract-based package for monitoring change over time.

4 assessments per yearOne assessment every three months

Includes

  • everything in CyberCheck Basic and Plus
  • comparison with the previous assessment
  • monitoring changes to domains, subdomains and exposed services
  • monitoring DNS, SSL/TLS, SPF, DKIM and DMARC
  • monitoring public information, digital traces and breach information
  • reviewing changes in the organisation’s security profile

The client receives

  • after every assessment: an updated summary, new findings, change review, new priorities and recommendations
  • an annual review after four assessment cycles
  • a comparison of digital exposure over time
  • a review of remediated and newly identified risks
  • recommendations for the next period
  • priority communication and specialist consultation within the agreed contract scope
Request a CyberCheck Pro quote

CUSTOM PROPOSAL

CyberCheck Enterprise

Enterprise Digital Exposure & Cybersecurity Programme

An individually tailored programme for larger or more complex organisations.

Includes

  • everything in CyberCheck Basic, Plus and Pro
  • periodic and quarterly assessments
  • change comparisons and an annual report
  • specialist consultation
  • multiple domains, brands or related companies
  • complex IT environments and extended external attack surface monitoring
  • monitoring of critical systems
  • Microsoft 365 or Google Workspace security review
  • server, web application, internal infrastructure and network segmentation reviews
  • reviews of privileged users, administrator accounts and IAM
  • backup and data recovery process reviews
  • security policy reviews and a cybersecurity improvement plan
  • incident response planning and tabletop exercises
  • phishing simulations and security awareness training
  • individual consultation for management and other services by proposal

The scope of CyberCheck Enterprise is defined individually based on the size of the organisation, infrastructure complexity, number of domains and systems, and the required level of monitoring.

Request an Enterprise proposal

Service scope

Package comparison

CapabilityBasicPlusProEnterprise
Basic domain assessment
DNS
SPF
DKIM
DMARC
SSL/TLS
SubdomainsBasicExtendedExtendedCustom
Exposed servicesBasicCustom
Web technologies
Publicly available informationBasic
Employees and management
Phishing exposureBasic
Social engineering exposure
CEO fraudBasic
BECBasic
Known data breaches
Written summary
Risk assessment
RecommendationsBasic
Self-help measures
Executive Summary
Prioritised action plan
Quarterly assessments
4 assessments per year
Change comparison
Annual report
Consultation
Individual scope
Multiple domainsExtendedExtendedCustom
Multiple companiesCustom
Additional cybersecurity servicesCustom

Practical measures

Many improvements do not require a large budget

Practical security fundamentals can materially reduce the likelihood of abuse:

Cybersecurity can often be improved substantially by implementing a small number of fundamentals correctly.

  • enable MFA
  • use a password manager
  • do not reuse passwords
  • remove accounts belonging to former employees
  • keep systems and web applications updated
  • verify SPF, DKIM and DMARC
  • restrict administrator privileges
  • encrypt company devices
  • maintain backups and test data recovery
  • protect mobile devices
  • reduce unnecessary public disclosure of information
  • train employees to recognise phishing
  • verify unusual payment requests
  • independently verify supplier bank-account changes

From enquiry to action

How does CyberCheck work?

  1. 01

    Enquiry

    The client selects a package or describes its requirements.

  2. 02

    Scope definition

    The assessment scope is agreed.

  3. 03

    CyberCheck assessment

    VERCOD performs the agreed assessment.

  4. 04

    Report and recommendations

    The client receives the findings and recommended actions.

For Pro and Enterprise, the assessment is repeated periodically in accordance with the contract.

Agreed scope

A safe, non-invasive assessment

The standard CyberCheck scope primarily analyses publicly available information and the organisation’s external digital exposure.

Active security testing requires a separately agreed scope and appropriate written authorisation from the client.

The standard CyberCheck assessment does not normally include:

  • unauthorised intrusion
  • vulnerability exploitation
  • DoS testing
  • aggressive penetration testing
  • data modification
  • unauthorised acquisition of access
  • digital forensics

FAQ

Frequently asked questions

What is VERCOD CyberCheck?

VERCOD CyberCheck is a professional external digital exposure assessment that turns publicly visible technical and business information into clear findings and practical recommendations.

Is CyberCheck a penetration test?

No. The standard CyberCheck is a non-invasive review of publicly available information and external digital exposure. A penetration test is a separate service with an explicitly agreed scope and written authorisation.

Do you need access to our servers?

Access to your servers is not normally required for the standard external CyberCheck. Any additional access is agreed only for a separately commissioned and authorised scope.

Can the assessment affect our systems?

The standard assessment is designed to be non-invasive and does not include aggressive testing, vulnerability exploitation or DoS testing.

What do I receive after the assessment?

Depending on the package, you receive a written summary or detailed report, risk classification, explanations, recommendations and prioritised actions.

How often is CyberCheck Pro performed?

Once every three months, or four times per year.

Can you assess multiple companies or domains?

Yes. An extended scope covering multiple domains, brands or related companies is defined in a tailored proposal.

Does Enterprise include the capabilities of the other packages?

Yes. CyberCheck Enterprise includes everything in Basic, Plus and Pro, together with individually agreed additional services.

How much does CyberCheck cost?

Pricing depends on the selected package, organisation size and scope of the digital environment. Contact VERCOD for a tailored quotation.

Do you know what a potential attacker can see about your company?

Understand your digital exposure before someone exploits it.

Enquiry

Order CyberCheck

Tell us about your organisation and the required scope. We will respond with a suitable package recommendation or proposal.

VERCOD

Service provider

VERCOD d.o.o.

Legal name
VERCOD, upravljanje spletnih portalov, d.o.o.
Address
Spodnja Polskava 100
2331 Pragersko
Slovenia
Registration number
7534132000
Tax number
97387452