Find out what your website tells strangers.

A plain-English security test for small British businesses. Run properly, with your written permission, and explained by a person who'll pick up the phone.

Your domain, your email and your website. No sign-up, no email address, nothing to buy, and they read only what you already show every visitor.

Who reads your report

Hosting, domains, email and databases since 1996. Websites are the small part.

The person reading your report is the person who runs the mail and the DNS for other people's businesses. That is the whole credential, and it is why this page is written in the first person rather than by a company.

It also means you get a plan rather than a data dump. A scanner produces a list. Knowing which three items on that list actually matter for your business, and which one can wait until next quarter, is the part a person does.

Before the price, not after it

What this is, and what it isn't

What this is.

Automated security testing of your public website, run with your written permission using Beagle Security, an ISO 27001-certified testing platform. The findings are read and written up by a person, so you get a plan rather than a data dump.

What it isn't.

It isn't a manual penetration test by a CREST-certified consultant. Those start around £2,500, and I'll tell you plainly when you need one instead of this. It doesn't certify you for Cyber Essentials. That's IASME's job and I'll point you to them. And if you take card payments, it doesn't satisfy PCI DSS requirement 11.3.

Why say so here.

Because you'd find out eventually, and it's better you hear it from me before you pay than from an auditor afterwards.

The free checks

What they read, and what they can't tell you

There are three, and between them they read what your domain, your mail and your website already tell anybody who asks: who holds the domain name and when it runs out, who handles your mail and whether somebody else can send email pretending to be you, and whether your pages arrive over a secure connection and what they put on your visitors' computers.

None of that is private, which is why I can check it without asking. It's also the first thing anyone with bad intentions looks at.

What they can't tell you is whether your login is guessable, whether your forms can be used to reach your database, or whether a customer can see another customer's data. That needs a proper test, and a proper test needs your permission in writing.

The two things

One is free. The other is £595 plus VAT.

The free checks

Free, and they read only what is public.

  • Who holds your domain name, and when it runs out
  • Whether somebody else can send email pretending to be you, and which part of that nobody can read from outside
  • Whether your pages arrive over a secure connection, and whether anything on them does not
  • No account, no card, and nothing is stored against your name

They aren't a test of your application. They read the front door and tell you what it says.

The Website Security Report

£595 plus VAT, for one web application.

  • One authorised automated test, run with your written permission
  • Findings triaged and written up in plain English
  • A thirty minute walkthrough call, so you can ask what any of it means
  • A retest after the fixes, if you want one

It's automated rather than a consultant working through your application by hand, and I'll say so again on the call if that's what you actually need.

How it works

Nothing runs until you've signed and the domain is verified.

Those two steps are not paperwork for its own sake. Testing a website you have not proved you control is the thing this whole page exists to not do.

  1. Run the free checks

    They read only what your site shows every visitor, so nothing needs your permission yet.

  2. Decide whether you want the full report

    Get in touch and we'll talk about whether this is the right thing for you. Sometimes it isn't, and I'd rather say so before you pay.

  3. Sign a short authorisation

    It names your domains and says what may be tested. It's one page, and it's the document that makes the test lawful.

  4. Prove the site is yours

    A file or a DNS record, whichever is easier. This proves control to the testing platform, not just to me.

  5. The test runs

    Over 48 to 72 hours. I'll agree a quiet window with you first if you'd rather it ran overnight.

  6. The report, then the call

    Written up in plain English, then thirty minutes on the phone or a video call to go through it.

Questions

The four people actually ask

Will this take my site down?

Very unlikely, and I'll agree a quiet window with you beforehand if you'd rather be certain. I'll also tell you if I think testing your live site is a bad idea.

Do I need this for Cyber Essentials?

No. Cyber Essentials doesn't require a penetration test, and Cyber Essentials Plus checks your controls by scanning rather than by attacking them. What I can do is fix the web-facing things that make the self-assessment awkward, and write up the evidence.

Why do you need my permission if you can already see my site?

Because looking at a website and testing one are different things, legally and technically. Anyone offering to test your site without asking is telling you something about how they work.

What if you find something bad?

I'll ring you within one working day and hold the written report until we've spoken. You won't learn about a serious problem from a PDF attachment.

One photograph

The person who picks up the phone

Julian Mullins