Automated assessment for Australian SMBs

Automated Cyber Security Assessment for Australian Small Businesses

An automated cyber security assessment reviews what your business exposes to the internet without needing access to your servers, laptops or internal network. It is fast, repeatable and a reasonable first step when nobody has looked at your external exposure recently.

It is also bounded. Automated external checks see publicly observable configuration and exposure. They do not see inside your applications, your staff accounts or your internal systems, and they are not a substitute for a manual penetration test or professional advice.

What an automated external assessment can assess

Automated assessment works from the outside in, using the same public signals an attacker can gather before ever attempting anything intrusive. That view is genuinely useful because misconfiguration and forgotten exposure are common and visible.

  • Whether HTTPS is present and correctly configured, and the state of the public TLS certificate.
  • Browser-facing HTTP response headers such as Strict-Transport-Security, Content-Security-Policy, X-Frame-Options and X-Content-Type-Options.
  • Public DNS configuration and the email-authentication records SPF, DKIM and DMARC published for the domain.
  • Publicly reachable hosts, services and subdomains associated with the domain, including ones the business may have forgotten.
  • Publicly visible technology and version signals that indicate software worth reviewing or updating.
  • Public reputation and threat-intelligence signals associated with the domain and its hosts.

What it cannot assess

An automated external assessment is a reconnaissance-grade view. It cannot confirm exploitability, business logic flaws or anything that requires authenticated access, and it cannot see the parts of your environment that never face the internet.

  • Logic flaws, privilege-escalation paths and authenticated application weaknesses that require a human tester.
  • Internal networks, staff laptops, servers and cloud consoles that are not publicly exposed.
  • Whether an identified weakness is actually exploitable in your specific environment.
  • Staff behaviour, phishing susceptibility, physical security and supplier processes.
  • Backup coverage, recovery capability and incident-response readiness.

How ScoutLab's automated assessment works

The Free Scan is a no-cost external check of a domain you own or manage. It produces a risk score and a summary of externally visible findings, and the full written report with the detailed findings and remediation guidance unlocks for $99.

The Deep Scan is a broader automated external assessment at $199. It requires you to confirm authorisation for the scope first, then examines the wider public attack surface — additional discovered hosts and subdomains, and further external security signals — and includes the full report for that scan.

Both are automated. Nothing in either service logs in to your systems, changes configuration, or attempts intrusive exploitation.

Where automated assessment fits in a wider security programme

The Australian Cyber Security Centre's small-business guidance puts weight on multi-factor authentication, prompt updates and tested backups. Those controls do most of the risk reduction, and an external assessment does not replace them.

Treat automated assessment as the visibility layer: it tells you what the internet can see, how that changes, and which items are worth escalating to your developer, IT provider or a specialist.

  • Use it before and after website, hosting, DNS or email changes.
  • Use it when you inherit a website, agency or supplier and want an independent external view.
  • Use it periodically, because exposure changes even when the business does not.

Automated assessment or a manual engagement?

Both have a place. This is the decision most Australian small businesses are actually making.

How quickly do I need a view of my exposure?

Automated assessmentMinutes, self-service, repeatable whenever you want.
Manual engagementDays to weeks, scheduled with a tester or consultancy.

Do I need proof that a weakness is exploitable?

Automated assessmentNo — findings are signals and configuration issues to investigate.
Manual engagementYes — a tester attempts controlled exploitation and demonstrates impact.

Does the assessment need authenticated or internal access?

Automated assessmentNo access is used; only publicly observable information.
Manual engagementCredentials, internal access and defined rules of engagement are typical.

Do I need a signed report for a customer, tender or auditor?

Automated assessmentA written report of external findings, not a certification.
Manual engagementOften the right choice when a formal attestation is required.

What is the cost profile?

Automated assessmentFree external check, $99 full report, $199 Deep Scan.
Manual engagementProfessional day rates, quoted per engagement.

What ScoutLab does not do

Being explicit about scope matters more than marketing language, so here is what is out of scope.

  • ScoutLab does not provide manual penetration testing or red-team engagements.
  • ScoutLab does not provide manual security consultancy, advisory retainers or remediation implementation.
  • ScoutLab does not issue compliance certification, attestation or audit sign-off of any kind.
  • ScoutLab does not guarantee that your website, domain or business is secure — no external assessment can.
  • ScoutLab does not log in to your systems or change your website, hosting, DNS or email configuration.

Run a free external security check

Start with the free external check of a domain you own or manage. It reviews publicly visible website, domain and email security signals and shows what is worth investigating first.

Run the free website security check

Frequently asked questions

What is an automated cyber security assessment?

It is an assessment that uses automated checks against publicly observable information — website responses, TLS and certificates, HTTP security headers, DNS and email-authentication records, discoverable hosts and public threat-intelligence signals — to identify externally visible weaknesses without accessing your internal systems.

Is an automated assessment the same as a penetration test?

No. A penetration test is a manual engagement in which a tester attempts controlled exploitation to demonstrate real impact. An automated external assessment identifies signals and configuration issues to investigate, and ScoutLab does not provide manual penetration testing.

Can ScoutLab certify that my business is compliant or secure?

No. ScoutLab produces a written report of externally visible findings. It does not issue compliance certification or attestation, and no external assessment can guarantee that a website or business is secure.

What is the difference between the Free Scan and the Deep Scan?

The Free Scan is a no-cost external check of a single domain, with the full written report unlocking for $99. The Deep Scan is a broader automated external assessment at $199 that requires scope authorisation, covers additional discovered hosts and subdomains and further external signals, and includes the full report for that scan.

Do I need permission to scan a domain?

Yes. Only assess domains your business owns or is authorised to assess. The Deep Scan requires you to confirm that authorisation before the broader assessment starts.

How often should an Australian small business run an external assessment?

Re-check after any change to the website, hosting, DNS or email, and on a regular schedule as well, since publicly visible exposure can change without the business changing anything. Scheduled monitoring is designed for exactly that.