External digital exposure assessment
VERCOD CyberCheck
What can a potential attacker see about your company?
A cyberattack often begins long before an attacker makes the first attempt to access an information system. Publicly available information, domains, email addresses, misconfigurations, exposed services and other digital traces may reveal more than you expect.
VERCOD CyberCheck shows you how your company appears from the perspective of a potential attacker and identifies practical measures that can reduce your digital exposure.
VERCOD CYBERCHECK
What is VERCOD CyberCheck?
VERCOD CyberCheck is a VERCOD d.o.o. service for assessing an organisation’s external digital exposure.
CyberCheck analyses publicly available digital information, domains, subdomains, email security, exposed services and other digital traces that a potential attacker could use when preparing a cyberattack.
Why CyberCheck?
What a potential attacker may see
Do you know what can be discovered about your company?
Before attempting an attack, a potential attacker may examine a wide range of publicly available technical and business information:
- web domains
- subdomains
- DNS information
- publicly accessible servers
- web technologies
- SSL/TLS certificates
- email addresses
- public information about employees
- management information
- business contact details
- old or forgotten web services
- email security configuration
- information from known data breaches
- information useful for phishing
- information useful for social engineering
- information useful for CEO fraud
- information useful for Business Email Compromise – BEC
CyberCheck examines this information from a defensive perspective – so you can see it before someone else uses it against you.
VERCOD CYBERCHECK
What do we assess?
The assessment focuses on the organisation’s external attack surface and publicly available digital traces.
Digital Exposure
A review of the organisation’s publicly visible technical footprint.
- domains
- subdomains
- DNS
- publicly exposed services
- web applications
- web technologies
- SSL/TLS certificates
Email Security
A review of controls designed to protect the domain and email environment.
- SPF
- DKIM
- DMARC
- spoofing exposure
- domain impersonation risk
- phishing exposure
Digital Footprint
A review of publicly available information.
- the company
- contact details
- employees
- employee roles
- management
- the organisation
- business relationships
Social Engineering Exposure
Information that could support a targeted deception attempt.
- phishing
- spear phishing
- CEO fraud
- BEC
- impersonation
- social engineering
Known Data Breaches
Where lawful and technically possible.
- known data breaches
- compromised email addresses
- compromised user accounts
- publicly known data disclosures
Assessment outcome
More than a list of technical findings
CyberCheck is not merely an automated technical scan. Findings are reviewed, assessed and presented in a way that is useful both to technical teams and company management.
Depending on the selected package, the client receives:
- an external digital exposure assessment
- identification of material risks
- findings classified by severity
- a concise written summary
- an explanation of potential consequences
- practical recommendations
- measures the organisation can implement itself
- a prioritised action list
- suggestions for further specialist activities
Clear prioritisation
Risk levels
LOW
The finding does not usually represent an immediate threat, but an improvement is recommended.
MEDIUM
A potential attacker could use the finding when preparing an attack.
HIGH
Prompt remediation is recommended.
CRITICAL
The finding represents a material risk and requires priority attention.
VERCOD CYBERCHECK
VERCOD CyberCheck packages
Choose an assessment scope suited to the size and needs of your organisation. Pricing is provided following an enquiry.
CyberCheck Basic
Essential digital exposure assessment
Small businesses and organisations performing their first digital exposure assessment.
Includes
- assessment of one primary domain
- basic DNS review
- subdomain review
- SSL/TLS review
- basic discovery of publicly exposed services
- SPF, DKIM and DMARC
- basic domain impersonation review
- basic review of publicly available contact information
- basic digital exposure rating
The client receives
- a concise written summary
- a list of key findings
- risk classification
- essential recommendations
- measures the organisation can implement itself
RECOMMENDED
CyberCheck Plus
Comprehensive digital exposure assessment
For organisations seeking a more detailed understanding of their external digital exposure.
Includes
- everything in the Basic package
- extended domain and subdomain assessment
- more detailed external digital infrastructure review
- web technology review
- public information about employees and management
- social engineering exposure review
- phishing and spear-phishing exposure
- basic CEO fraud and BEC exposure assessment
- known breach review where lawful and technically possible
- review of potentially obsolete or unnecessarily exposed services
The client receives
- a more detailed written report
- an executive summary for management
- classified findings
- an explanation of potential consequences
- practical recommendations
- a prioritised action list
- measures the organisation can implement itself
CyberCheck Pro
Continuous digital exposure monitoring
A contract-based package for monitoring change over time.
Includes
- everything in CyberCheck Basic and Plus
- comparison with the previous assessment
- monitoring changes to domains, subdomains and exposed services
- monitoring DNS, SSL/TLS, SPF, DKIM and DMARC
- monitoring public information, digital traces and breach information
- reviewing changes in the organisation’s security profile
The client receives
- after every assessment: an updated summary, new findings, change review, new priorities and recommendations
- an annual review after four assessment cycles
- a comparison of digital exposure over time
- a review of remediated and newly identified risks
- recommendations for the next period
- priority communication and specialist consultation within the agreed contract scope
CUSTOM PROPOSAL
CyberCheck Enterprise
Enterprise Digital Exposure & Cybersecurity Programme
An individually tailored programme for larger or more complex organisations.
Includes
- everything in CyberCheck Basic, Plus and Pro
- periodic and quarterly assessments
- change comparisons and an annual report
- specialist consultation
- multiple domains, brands or related companies
- complex IT environments and extended external attack surface monitoring
- monitoring of critical systems
- Microsoft 365 or Google Workspace security review
- server, web application, internal infrastructure and network segmentation reviews
- reviews of privileged users, administrator accounts and IAM
- backup and data recovery process reviews
- security policy reviews and a cybersecurity improvement plan
- incident response planning and tabletop exercises
- phishing simulations and security awareness training
- individual consultation for management and other services by proposal
The scope of CyberCheck Enterprise is defined individually based on the size of the organisation, infrastructure complexity, number of domains and systems, and the required level of monitoring.
Request an Enterprise proposalService scope
Package comparison
| Capability | Basic | Plus | Pro | Enterprise |
|---|---|---|---|---|
| Basic domain assessment | ✓ | ✓ | ✓ | ✓ |
| DNS | ✓ | ✓ | ✓ | ✓ |
| SPF | ✓ | ✓ | ✓ | ✓ |
| DKIM | ✓ | ✓ | ✓ | ✓ |
| DMARC | ✓ | ✓ | ✓ | ✓ |
| SSL/TLS | ✓ | ✓ | ✓ | ✓ |
| Subdomains | Basic | Extended | Extended | Custom |
| Exposed services | Basic | ✓ | ✓ | Custom |
| Web technologies | — | ✓ | ✓ | ✓ |
| Publicly available information | Basic | ✓ | ✓ | ✓ |
| Employees and management | — | ✓ | ✓ | ✓ |
| Phishing exposure | Basic | ✓ | ✓ | ✓ |
| Social engineering exposure | — | ✓ | ✓ | ✓ |
| CEO fraud | — | Basic | ✓ | ✓ |
| BEC | — | Basic | ✓ | ✓ |
| Known data breaches | — | ✓ | ✓ | ✓ |
| Written summary | ✓ | ✓ | ✓ | ✓ |
| Risk assessment | ✓ | ✓ | ✓ | ✓ |
| Recommendations | Basic | ✓ | ✓ | ✓ |
| Self-help measures | ✓ | ✓ | ✓ | ✓ |
| Executive Summary | — | ✓ | ✓ | ✓ |
| Prioritised action plan | — | ✓ | ✓ | ✓ |
| Quarterly assessments | — | — | ✓ | ✓ |
| 4 assessments per year | — | — | ✓ | ✓ |
| Change comparison | — | — | ✓ | ✓ |
| Annual report | — | — | ✓ | ✓ |
| Consultation | — | — | ✓ | ✓ |
| Individual scope | — | — | — | ✓ |
| Multiple domains | — | Extended | Extended | Custom |
| Multiple companies | — | — | — | Custom |
| Additional cybersecurity services | — | — | — | Custom |
Practical measures
Many improvements do not require a large budget
Practical security fundamentals can materially reduce the likelihood of abuse:
Cybersecurity can often be improved substantially by implementing a small number of fundamentals correctly.
- enable MFA
- use a password manager
- do not reuse passwords
- remove accounts belonging to former employees
- keep systems and web applications updated
- verify SPF, DKIM and DMARC
- restrict administrator privileges
- encrypt company devices
- maintain backups and test data recovery
- protect mobile devices
- reduce unnecessary public disclosure of information
- train employees to recognise phishing
- verify unusual payment requests
- independently verify supplier bank-account changes
From enquiry to action
How does CyberCheck work?
- 01
Enquiry
The client selects a package or describes its requirements.
- 02
Scope definition
The assessment scope is agreed.
- 03
CyberCheck assessment
VERCOD performs the agreed assessment.
- 04
Report and recommendations
The client receives the findings and recommended actions.
For Pro and Enterprise, the assessment is repeated periodically in accordance with the contract.
Agreed scope
A safe, non-invasive assessment
The standard CyberCheck scope primarily analyses publicly available information and the organisation’s external digital exposure.
Active security testing requires a separately agreed scope and appropriate written authorisation from the client.
The standard CyberCheck assessment does not normally include:
- unauthorised intrusion
- vulnerability exploitation
- DoS testing
- aggressive penetration testing
- data modification
- unauthorised acquisition of access
- digital forensics
FAQ
Frequently asked questions
What is VERCOD CyberCheck?
VERCOD CyberCheck is a professional external digital exposure assessment that turns publicly visible technical and business information into clear findings and practical recommendations.
Is CyberCheck a penetration test?
No. The standard CyberCheck is a non-invasive review of publicly available information and external digital exposure. A penetration test is a separate service with an explicitly agreed scope and written authorisation.
Do you need access to our servers?
Access to your servers is not normally required for the standard external CyberCheck. Any additional access is agreed only for a separately commissioned and authorised scope.
Can the assessment affect our systems?
The standard assessment is designed to be non-invasive and does not include aggressive testing, vulnerability exploitation or DoS testing.
What do I receive after the assessment?
Depending on the package, you receive a written summary or detailed report, risk classification, explanations, recommendations and prioritised actions.
How often is CyberCheck Pro performed?
Once every three months, or four times per year.
Can you assess multiple companies or domains?
Yes. An extended scope covering multiple domains, brands or related companies is defined in a tailored proposal.
Does Enterprise include the capabilities of the other packages?
Yes. CyberCheck Enterprise includes everything in Basic, Plus and Pro, together with individually agreed additional services.
How much does CyberCheck cost?
Pricing depends on the selected package, organisation size and scope of the digital environment. Contact VERCOD for a tailored quotation.
Do you know what a potential attacker can see about your company?
Understand your digital exposure before someone exploits it.
Enquiry
Order CyberCheck
Tell us about your organisation and the required scope. We will respond with a suitable package recommendation or proposal.
Important legal information
VERCOD CyberCheck is a professional assessment of digital exposure within the agreed scope and reflects conditions identified at the time of the assessment. The service does not guarantee that the client’s information systems contain no other vulnerabilities or that a cyber incident cannot occur. Unless explicitly agreed in an individual proposal, the standard CyberCheck service does not constitute a penetration test, certification or formal compliance audit.
VERCOD
Service provider
VERCOD d.o.o.
- Legal name
- VERCOD, upravljanje spletnih portalov, d.o.o.
- Address
- Spodnja Polskava 100
2331 Pragersko
Slovenia - Registration number
- 7534132000
- Tax number
- 97387452
- info@vercod.com
- Phone
- +386 69 737 737