Skip to main content
About

About CyberCerber

Fixed-price external IT vulnerability assessment for SMB owners in three verticals: dental clinics, accounting firms, aesthetic medicine practices. Plain-language report in 5 business days, no contracts, no retainers.

Why we exist

The three verticals in CyberCerber's portfolio - dental, accounting, aesthetic medicine - share a common pattern: they process sensitive personal or financial data, they are exposed on the internet, and their owners rarely have dedicated IT staff. To an automated scanner working across the entire public IPv4 space, these are ideal targets - the gap between what an attacker knows and what the owner knows is widest here.

The cybersecurity market largely serves enterprises. Security firms work on bespoke pricing, billable hours, and multi-year SOC contracts. For a 4-chair dental practice, an 8-person CPA firm, or a solo aesthetic clinic, that offering is inaccessible - on price, jargon, and operational fit. A breach notification sent to every patient is still a business-ending event whether the firm has 10 employees or 10,000.

CyberCerber was built to close that gap. Three fixed-price products: PreScan (free), CyberAudyt ($900) and Pentest ($4,900) - instead of hourly billing. Plain-English reports readable by the owner, not just IT. Five business days from order to report. No standing contract, no retainers. Work product that meets HIPAA risk-analysis requirements and the FTC Safeguards Rule at a price affordable to a 10-person firm.

We do not serve large enterprises, do not provide formal compliance audits, and do not represent clients before regulators. We do one thing well: external vulnerability assessment of internet-facing infrastructure, in plain English, at a fixed price. That is sufficient for 95% of the SMBs we serve.

Founder

IW

Photo: pending

Iwo Wojciechowski

CEO and founder, CyberCerber. Cybersecurity specialist.

Founded CyberCerber in 2022 on the belief that SMB owners - dental clinics, accounting firms, aesthetic medicine practices - deserve the same quality of cybersecurity assessment as large enterprises, at a price and in a language tailored to their reality.

Specialises in external vulnerability assessments of internet-facing IT infrastructure - no need for internal network access. This allows delivery without risking disruption to daily operations and without lengthy on-boarding.

Contact: contact@cybercerber.com

LinkedIn: pending (in preparation).

How we work

CyberCerber's vulnerability assessment methodology is documented and repeatable. Every audit follows the same steps in the same order.

Step 1 - attack surface inventory

Map every publicly visible asset: DNS records, TLS certificates, mail servers, web servers, admin panels, open ports. Detect shadow infrastructure - subdomains the owner may not remember owning.

Step 2 - vulnerability scan

Active scan of ports, services, software versions. Map findings to the CVE database and calculate CVSS per FIRST.org. Cross-reference against the CISA Known Exploited Vulnerabilities Catalog - the CVEs actually used by attackers in the wild.

Step 3 - manual verification (CyberAudyt and Pentest)

Every priority finding is reproduced manually by an analyst. Eliminates false positives. Manual OWASP Top 10 verification for web applications - SQL injection, XSS, broken authentication, security misconfiguration. Satisfies the HIPAA Security Rule risk analysis requirement (45 CFR § 164.308(a)(1)) and the FTC Safeguards Rule penetration-testing obligation.

Step 4 - plain-English report

PDF report in English with four sections: executive summary, critical findings (fix within 7 days), attack narrative, remediation plan. The technical section is for your IT provider or MSP; the first three are for the owner.

Step 5 - consultation

30-minute remote call included - walk-through of the report, fix-order recommendations, Q&A. No sales pressure - if the right fix is outside our scope, we say so.

What we do NOT do

  • No formal HIPAA, FTC Safeguards, or NIS2 compliance audits - that is law firm / compliance consultancy territory.
  • No representation before HHS, the FTC, or any data-protection authority.
  • No managed infrastructure - that is your IT or MSSP.
  • No internal-network testing without a signed engagement (Pentest only).
  • No ad-hoc "security consulting" outside the packaged offering.

Why fixed pricing

Hourly billing rewards firms that stretch projects. Fixed pricing rewards efficiency. You know what you will pay - and what you will get - before signing. Three products map to three needs: PreScan is free diagnostics, CyberAudyt is the full external audit, Pentest for regulated entities or corporate-client requirements. Details on the pricing page.

Building in public

Cybersecurity is a credentialing industry, but for an SMB client value comes from operational experience, not paper. As a 2022-founded firm, CyberCerber is building its credentials and industry-affiliation path in public. Current roadmap (target dates pending):

  • OSCP (Offensive Security Certified Professional)
  • CEH (Certified Ethical Hacker)
  • OWASP Chapter participation
  • ISACA membership (target year to be confirmed)

We would rather say "in progress" than fabricate. Certificates are evidence for regulated industries; competence is what makes effective SMB audits today.

Where we operate

We serve clients in the US and Europe - primarily dental practices, accounting firms, and aesthetic medicine clinics. All audits are fully remote: no on-site visit required, no access to internal systems. The external nature of the assessment is a feature, not a limitation - it replicates exactly what an attacker sees.

Legal entity

Brand:
CyberCerber
Legal entity:
VIVO Finanse sp. z o.o.
KRS:
0000944301
NIP:
8992914597
Registered:
Wroclaw, Poland
Founded:
2022

VIVO Finanse sp. z o.o. is the legal entity; CyberCerber is the operating brand. Contracts and regulatory filings use the full legal name; commercial communication uses CyberCerber.