Cybersecurity

Website & IT Infrastructure Security Scan

Professional security analysis of your website, server, and IT infrastructure. We detect vulnerabilities, configuration errors, and known security gaps before someone unauthorized does.

IT Infrastructure Security Scan

The service consists of a technical analysis of publicly accessible systems to detect vulnerabilities, configuration errors, and known security gaps (CVEs). The report includes a risk level and specific remediation recommendations.

The scan covers open ports and services, software versions with known CVEs, web server and database configuration errors, missing HTTP security headers, expiring or invalid SSL/TLS certificates, and web application vulnerabilities (OWASP Top 10), among others. Each finding is described with a risk level (low/medium/high/critical) and a specific remediation recommendation.

How does the security scan work?

1

Request

You fill in the form and accept the terms confirming your right to the infrastructure.

2

Contact & scope

We confirm the scope of work and agree on the details. No action is taken without your consent.

3

Analysis

We scan your infrastructure using professional security tools.

4

Report

You receive a detailed PDF report with results, a risk assessment, and recommendations.

Pricing packages

Basic

  • ✔ External port and service scan
  • ✔ Known CVE check
  • ✔ HTTP header analysis
  • ✔ SSL certificate verification
  • ✔ PDF report

€25

Premium

  • ✔ Everything in Business
  • ✔ Full infrastructure audit
  • ✔ Server configuration analysis
  • ✔ Recurring monitoring after the audit
  • ✔ Dedicated support after the audit

from €120

✔ If the scan does not detect any vulnerabilities of significant risk, the Client is not charged for the service (applies to the Basic and Business packages).

Red Teaming – simulating a real attack

Red Teaming is a controlled simulation of a real attack on an organization. The goal is to test the resilience of infrastructure, security procedures, incident detection, and the IT team's response.

Unlike a security scan, Red Teaming focuses on the entire attack chain — from reconnaissance and initial access, through privilege escalation, to achieving the objective (e.g. access to data or critical systems). It provides a realistic assessment of how your organization would respond to a security incident.

Testing may include analysis of external exposure, privilege escalation attempts, phishing tests against employees, assessment of internal network segmentation, and verification of detection and response tools (EDR/SIEM).

Who is Red Teaming for?

Companies with sensitive data

Law firms, accounting offices, medical facilities, companies processing personal data.

Companies after an incident

Organizations that experienced an attack and want to verify the vulnerabilities were actually fixed.

Pre-audit verification

Companies preparing for ISO 27001 certification, a compliance audit, or a vendor assessment.

Pricing packages

Starter

  • ✔ External infrastructure test
  • ✔ Attempted external access
  • ✔ Report with results and recommendations

€250

Full Scope

  • ✔ Full APT attack simulation
  • ✔ Social engineering tests (phishing)
  • ✔ Response procedure verification
  • ✔ Report for management and the IT department

custom quote

Frequently asked questions

What is a website and server security scan?

A security scan is a technical analysis of your IT infrastructure for vulnerabilities, configuration errors, and known gaps (CVEs). We check open ports, software versions, web server configuration, the SSL certificate, and HTTP security headers, among others. The results are delivered as a PDF report with a risk assessment and recommendations.

How long does a security scan take?

A standard external scan (Basic package) is completed within 1–2 business days of scope confirmation. The Business and Premium packages include a more thorough analysis and may take up to 5 business days. We agree on the exact timeline individually before starting work.

Do I need to be an IT specialist to order a scan?

No. To order a scan, you only need to provide the domain or IP address of the infrastructure and confirm you have the right to manage it. The final report is written in a way that is clear for both business owners and technical teams.

What does the security scan report include?

The report includes a list of detected vulnerabilities with an assigned risk level (low/medium/high/critical), a description of each finding, potential consequences, and a specific remediation recommendation. The Business and Premium packages include a phone consultation to discuss the results.

What's the difference between Red Teaming and a security scan?

A security scan is primarily an automated and manual technical analysis — we look for known vulnerabilities. Red Teaming is a simulation of a real, multi-stage attack on the entire organization: it includes reconnaissance, attempted access, privilege escalation, and verifying the team's response. It's a deeper, more realistic security assessment.

Is scanning my infrastructure legal?

Yes, provided you have the right to manage the infrastructure in question. We require confirmation of this fact before every scan — it's a mandatory condition for the service. We do not perform any tests without the written consent of the system owner.

Do you scan infrastructure without prior contact?

No. No scanning activity is performed without prior contact and confirmation of the scope of work with the Client. The Client is required to document their right to manage the specified domain, server, or infrastructure — scanning third-party infrastructure without the owner's consent is never performed.

Order the service