AUTHORISED EXTERNAL SECURITY REVIEW

Find the security gaps visible from the internet.

Get an engineer-reviewed view of exposed services, known vulnerabilities and common configuration risks on a public target you are authorised to test.

Scope agreed before testing No card for the free check Typically 24–48 hours after scope confirmation
ILLUSTRATIVE REPORT EXAMPLE ONLY
72/ 100EXAMPLE SCORE
EXAMPLE PRIORITY3 actions identified

Exposed servicesExternal attack surface

REVIEW

Known vulnerabilitiesVisible software indicators

CHECK

Configuration postureCommon external controls

GOOD
Prioritised findingsClear next actionsEngineer reviewed

WHAT WE REVIEW

A focused view of external exposure.

The sweep starts with an agreed public target. We review what is externally observable and use bounded checks to turn visible risk into an ordered action list. It is not a substitute for a full internal audit or penetration test.

01

Exposed services

Identify internet-facing entry points that may be unnecessary or need tighter controls.

02

Known weaknesses

Highlight recognised issues associated with externally visible software and services.

03

Configuration risks

Check common external settings that can weaken an otherwise secure service.

04

Visible patch posture

Flag software indicators that may warrant version or patch verification.

05

Practical priorities

Order findings by likely importance and explain the next action in plain language.

CHOOSE YOUR DEPTH

Start with a baseline. Go deeper when needed.

Both routes begin with ownership and scope confirmation. Expanded targets or specialist testing are agreed separately.

QUICK BASELINEUseful first view

Free Security Check

£0No card required

A lightweight external review of one agreed public target, designed to show whether deeper investigation is worthwhile.

  • External posture score
  • High-level visible findings
  • Prioritised next step
  • Email summary
Request free check

The £300 price applies to DC Core’s standard agreed scope. We will confirm any different or expanded scope—and its price—before work begins.

REQUEST YOUR SWEEP

Confirm the target and your authority.

Security testing must have a clear boundary. Share the public asset you want reviewed and confirm that you own it or have permission from the owner.

  • We confirm scope before testing
  • Do not send credentials or secrets
  • Results go to the work email provided
Only include an asset your organisation owns or has written permission to test.
Do not include passwords, keys or other secrets.

Need help with scope? Email [email protected].

WHAT HAPPENS NEXT

Four clear steps.

  1. 01

    Request

    Choose a scope, name the target and confirm authority.

  2. 02

    Confirm

    We validate ownership, boundaries and safe testing conditions.

  3. 03

    Review

    DC Core assesses the agreed externally visible surface.

  4. 04

    Act

    You receive prioritised findings and practical next actions.

BEFORE YOU START

Security Sweep questions.

Need a different assessment? Email [email protected].

Is this a penetration test?

No. The standard Security Sweep is a bounded external exposure review. A penetration test, exploit attempt or intrusive assessment needs a separate written scope and authorisation.

Will the review disrupt our systems?

The scope is designed to minimise disruption, and we agree the testing boundary before work begins. No security assessment can honestly promise zero operational risk.

What access do you need?

The standard sweep begins with an approved public hostname or domain and does not require customer credentials. If a deeper review needs additional access, we agree that separately.

When will we receive results?

Results are typically delivered within 24–48 hours after we confirm the target, authority and testing scope. Timing may differ for expanded or specialist work.

Does a clean result prove the system is secure?

No. It reports what the agreed external review found at that point in time. It does not prove the absence of vulnerabilities or replace secure development, internal testing and ongoing monitoring.