Cyber Health Check
Systematic technical review of external attack surface, identity controls, configuration posture, and defensive readiness.
Why This Audit Exists
Most organizations suffer security breaches not from nation-state zero-days, but from basic hygiene failures: forgotten public staging servers, misconfigured DNS/DMARC records allowing domain spoofing, leaked API keys on public code repos, and legacy protocols left open to the internet.
The Cyber Health Check delivers a thorough, non-intrusive 5–7 business day inspection of your externally exposed assets, core systems configuration, and authentication boundaries to establish your empirical baseline.
What Is Inspected (Scope)
1. External Attack Surface & Perimeter Mapping
Reconnaissance of all public-facing IP ranges, domains, open ports, exposed administration portals (SSH, RDP, phpMyAdmin), and SSL/TLS cipher suites.
2. Email Security & Anti-Spoofing Records
Deep inspection of SPF, DKIM, and DMARC enforcement policies, preventing attackers from sending fraudulent emails pretending to be your executives or domain.
3. Credential & Dark Web Exposure
Auditing public data breaches and credential dumps for compromised corporate emails and enterprise tokens.
4. Core Host & Network Baseline Hygiene
Review of sample server configurations, patching cadences, backup integrity, and multi-factor authentication (MFA) coverage across primary accounts.
What Is Excluded
This health check is a non-destructive audit. It does not include active denial-of-service testing, physical on-site break-in attempts, or continuous 24/7 MDR monitoring (which is handled by ZIMA MDR).
Deliverables Included:
- ✔ Executive Summary
- ✔ Technical Findings across Infrastructure & Identity
- ✔ Threat Surface & Vulnerability Assessment
- ✔ Actionable Mitigation Priorities
- ✔ 90-Day Action Plan
- ✔ 60-Minute Senior Engineer Debrief