Skip to main content

Vulnerability assessment

External vulnerability assessment - see where attackers look first.

An external vulnerability assessment scans your internet-facing systems - ports, services, email, and web apps - and maps known weaknesses by CVSS severity, without exploiting them (that is what separates it from a penetration test). CyberCerber delivers it as CyberAudyt: a flat $900, plain-English report in 5 business days.

Methodology you already know from the standards

  • OWASP Top 10
  • CVSS
  • CVE
  • NIST
  • Plain-English report
  • Flat price

What it is

A vulnerability assessment, a pentest, and PreScan are three different questions

You do not need all three at once. Each level answers a different question about your infrastructure - and each has a different price and depth. The compliance bridge is in the guide on US data-security compliance.

PreScan

Free

“What can the internet already see about you?”

A passive scan of your attack surface - DNS, certificates, open ports, breached passwords. No login to your systems, nothing installed. Free, results in 24 hours.

CyberAudyt (vulnerability assessment)

$900

“Which weaknesses do you actually have, and what to fix first?”

An active scan combined with manual OWASP Top 10 verification. The result is a vulnerability map with CVSS priorities and a remediation plan. We map the weaknesses - we do not exploit them.

Pentest

$4,900

“Will your defenses hold against a real attack?”

Controlled exploitation of selected vulnerabilities. For regulated entities, or when a corporate client explicitly requires proof. Usually only after two assessment cycles.

Assessment scope

What we check in a vulnerability assessment

Attack surface & open ports

We map what your business publishes to the internet: subdomains, open ports, remote-access services (RDP, VPN, admin panels), and software versions. Exposed remote desktop and an unpatched service are the two most common ransomware entry points.

Web applications (OWASP Top 10)

We manually verify your sites and web apps against the OWASP Top 10 - outdated CMS and plugins, misconfigurations, exposed login panels. An automated scan alone does not settle this; a vulnerability assessment pairs the scan with human verification.

Email security (SPF/DKIM/DMARC)

We check the SPF, DKIM and DMARC configuration of your domain. Without them, anyone can impersonate your address and send a client or your bookkeeper an email about a “changed account number.” It is the first move in wire-transfer fraud (BEC).

Breached passwords & account exposure

We check your company addresses against breach feeds (Have I Been Pwned and dark-web sources). One leaked password, reused across services, is usually the open path into your system, email, or booking tool.

TLS certificates & encryption

We verify certificate validity, weak ciphers, and HTTPS configuration. An expired certificate or an old protocol is not just a browser warning - it is a real window for eavesdropping and impersonation.

Backup exposure

We check whether your backup is directly reachable from the internet - and therefore exposed to being encrypted along with everything else. A backup nobody has tested for restore is not a backup, just hope.

Deliverables

What you get with CyberAudyt

A fixed scope - you know exactly what you get before you pay. See a sample report.

  • Plain-English PDF report - owner summary plus a technical section for your IT person
  • Full vulnerability list with severity ratings (Critical / High / Medium / Low) and CVSS where it makes sense
  • Prioritized remediation plan your IT person can act on right away
  • Email configuration guide (SPF, DKIM, DMARC) for your domain
  • Breach-exposure report - which addresses, in which breaches, when
  • External exposure map - exactly what the internet sees from your IP addresses
  • Industry section - configuration of your specific software (practice management, accounting, or booking)
  • 30-minute closing call - a walk through the findings, point by point

The process

How it works, step by step

  1. 1

    Order & scope

    You give us the domain and scope (website, email, infrastructure). We agree on a scan window. We do not need access to your systems.

  2. 2

    Scan & verification - 5 business days

    We combine an automated scan with manual verification of priority findings against the OWASP Top 10. No exploitation attempts, no load on your network.

  3. 3

    Plain-English report

    You get the report: an executive summary, a CVSS-prioritized vulnerability list, and a remediation plan. No jargon in the parts written for you.

  4. 4

    30-minute consultation

    We walk through the findings point by point - what to fix first and how much effort it takes. Your IT person does the fixing. No lock-in.

  5. 5

    Re-scan after fixes (optional)

    Once vulnerabilities are remediated, we re-check that the fixes actually worked - for half the price of CyberAudyt. Proof for you, your client, and your auditor.

Compliance

A vulnerability assessment as your testing evidence: HIPAA and FTC Safeguards

HIPAA Security Rule3

The HIPAA Security Rule already requires a risk analysis of vulnerabilities to ePHI. The proposed 2025 update would make six-monthly vulnerability scans and annual penetration testing explicit - no small-practice exemption. An external assessment is the simplest way to evidence it. Context: US data-security compliance.

FTC Safeguards Rule4

For accountants, CPAs and tax preparers, the FTC Safeguards Rule requires annual penetration testing plus vulnerability assessments at least every six months - unless you run continuous monitoring. CyberAudyt covers the vulnerability-assessment half. More for accounting firms.

Pricing

A flat price, visible up front

You start for free. You pay only if there is something to fix. The CyberAudyt price is flat - regardless of how many online services, subdomains, or locations you have. Full pricing.

Start here

PreScan

Free

results in 24 h

A passive external scan. We show what the internet can see - with no access on your side. It answers the question “is there anything to worry about at all.”

Most chosen

CyberAudyt

$900

report in 5 business days

A full vulnerability assessment with manual OWASP Top 10 verification, a CVSS list, a plain-English report, and a 30-minute call. Flat price regardless of how many online services and subdomains you run.

Re-scan after fixes

$450

after remediation

Half the price of CyberAudyt for businesses that have already had one. We confirm the fixes actually closed the gaps - proof for you, a corporate client, or an auditor.

A flat price - no hourly rates, no surprises. Regulated entity or an explicit corporate-client requirement: a full pentest is available ($4,900).

Guarantee: if CyberAudyt does not surface at least 3 actionable findings to fix - you pay nothing.

Questions we hear most

Common questions

“Does HIPAA require a vulnerability scan?”
The HIPAA Security Rule already requires a risk analysis of vulnerabilities to ePHI. The proposed 2025 update (NPRM) would make six-monthly vulnerability scans and annual penetration testing explicit, with no small-practice exemption. An external vulnerability assessment is the simplest way to evidence that testing.
“Does the FTC Safeguards Rule require a penetration test?”
Yes, for covered financial institutions - which the FTC reads to include accountants, CPAs, and tax preparers. Unless you run continuous monitoring, the rule requires annual penetration testing plus vulnerability assessments at least every six months. CyberAudyt covers the vulnerability-assessment half.
“What is the difference between a vulnerability assessment and a penetration test?”
A vulnerability assessment maps weaknesses - what is exposed and how to fix it. A penetration test checks exploitation - whether a weakness can actually be used. Most businesses start with an assessment; a pentest comes after remediation, or when a regulator or corporate client explicitly requires it.
“How much does an external vulnerability assessment cost?”
CyberAudyt is a flat $900 - no hourly billing, no “starting at.” The price is the same regardless of how many online services or subdomains you run. If the scope genuinely exceeds the typical (say, more than 5 separate web apps), we tell you before you sign, not after.
“Will the assessment disrupt my operations?”
No. The scan is non-intrusive - we read what your systems already publish to the internet. We do not log in, install agents, attempt exploitation, or load your network. Your business runs as normal.
“If you find something, do I have to fix it with you?”
No. The report tells you what is wrong and what to fix - your own IT person or any firm can do the work. If you do not have a trusted IT person, we will point you to a solution, but there is no lock-in and no subscription.

Start with what the internet can see

You send us just your domain name. Within 24 hours we show what an attacker sees. If nothing serious - you keep the report and we step away. If there are problems - the next step is a full vulnerability assessment (CyberAudyt) at a flat price. No pressure, no subscription.

No card. No access to your systems. No monthly fees.

Sources

  1. 1NIST - vulnerability assessment definition (csrc.nist.gov)
  2. 2OWASP Top 10 - most common web-application vulnerabilities (owasp.org)
  3. 3HHS OCR - HIPAA Security Rule and 2025 NPRM (hhs.gov)
  4. 4FTC Safeguards Rule - what your business needs to know (ftc.gov)
  5. 5FIRST - CVSS scoring system (first.org/cvss)