Do you still have questions before deciding on CheckFix’s automated security check with fix strategy? You might find the answers in our frequently asked questions. And if not – feel free to contact us: office@checkfix.io.
A “hack test” is an informal umbrella term for any proactive security check from an attacker’s perspective – the attempt to find vulnerabilities before real hackers can exploit them. Both classic penetration tests and CheckFix are forms of a hack test, but they differ significantly in depth, effort, and cost.
The key differences:
Penetration Test (Pentest): Manual, in-depth security analysis by IT security experts who actively look for vulnerabilities and attempt to exploit them. Can also examine internal systems. Cost: typically €5,000–15,000 per assessment, usually once per year.
CheckFix Security Check (free): Automated analysis of your external attack surface – everything publicly accessible via your domain. No manual effort, no active intrusion into your systems. Delivers an A–F rating within 24 hours.
CheckFix Basic / Premium (€490–950/year): Extends the Security Check with a prioritised to-do list giving concrete instructions on which findings to fix and where. 96% cheaper than a classic pentest and feasible on a regular basis.
Which option fits whom?
Pentests are suitable for in-depth audits of individual systems or specific compliance requirements. CheckFix can be used as a prelude to a pentest to quickly identify the biggest entry points that a professional can then examine more thoroughly.
For small and medium-sized businesses that want to review their external attack surface regularly – to close vulnerabilities before hackers find them – CheckFix is the right choice.
For supply chain reviews under NIS-2, DORA, or ISO 27001, there is a dedicated variant: the CheckFix Risk Manager.
⇥ Start now with the free Security Check
CheckFix analyzes your IT infrastructure from an external perspective – exactly as hackers would see your company.
Step 1 – Discovery:
Step 2 – Vulnerability Assessment (automated):
Step 3 – Report & Dashboard:
Important: CheckFix works non-invasively – no attacks are simulated, only publicly available information is analyzed.
Free Security Check:
CheckFix Basic: €590/year
ROI calculation: A single security incident costs SMEs an average of €25,000. CheckFix costs less than €50/month – insurance that actively protects instead of just paying out.
CheckFix is suitable for any company with an online presence – from sole proprietorships to corporations.
You benefit from CheckFix if you have:
CheckFix examines your systems from an attacker’s perspective from the outside – exactly where 90% of all cyberattacks begin.
For SMEs: Professional IT security without five-figure pentest budgets. Vulnerabilities are explained so your technician can fix them themselves.
Typical scenario: Website by agency, mail server set up by a “tech-savvy friend” – CheckFix shows whether everything is secure. Because a system administrator doesn’t replace a cybersecurity expert (and vice versa 😉).
For larger companies: Quick external security checks for management and IT leadership. Uncover forgotten open ports, outdated systems, or configuration errors.
Typical scenario: Management receives an objective overview of security status – independent of internal or external IT service providers.
CheckFix covers the technical part of your security requirements: regular vulnerability assessment of your IT systems.
What CheckFix provides:
What CheckFix does NOT cover: NIS2 and KRITIS also require administrative measures such as policies, process documentation, risk registers, and incident management.
For supply chain management: We are currently developing NisFix – a platform specifically for the NIS2 requirement “supply chain security”. NisFix helps you monitor suppliers, document audits, and maintain records.
CheckFix will be integrated as a technical verification component. You can start now: Use CheckFix today for yourself and your suppliers – you’ll need the documented security checks for compliance anyway, regardless of which solution you choose later.
CheckFix performs regular external security checks – from the perspective of an attacker on the internet. This covers where over 70% of all cyberattacks start: at your publicly accessible IT infrastructure.
Everything accessible via your domain(s) on the internet is checked:
Not checked:
💡 Why external? The external attack surface is the largest entry point for cybercriminals. Those who are secure here eliminate the most common attack vector.
Scope: You can monitor up to 3 domains per CheckFix subscription. For larger infrastructures or individual requirements, contact us – we’ll find a suitable solution!
Depending on the selected package, CheckFix performs 1-2 comprehensive security checks per year:
Why this rhythm?
Annual or bi-annual checks are the standard for professional security audits and correspond to common compliance cycles (ISO 27001, NIS2, KRITIS). Between checks, your IT team has time to systematically address the vulnerabilities found.
CheckFix delivers prioritized, actionable recommendations instead of a daily flood of alerts. This allows you to use resources efficiently and achieve measurable improvements.
💡 Your advantage: You receive focused reports with clear to-dos – not thousands of unfiltered alerts like with continuous monitoring tools. You can decide the timing yourself through our practical dashboard.
Need more frequent checks? Contact us for a customized quote.
CheckFix works exclusively with publicly accessible information:
CheckFix shows you what attackers can see – without attacking itself.
The scoring system is based on school grades:
Important: The better your rating, the less interesting you are to hackers who usually look for “low-hanging fruit”.
The ToDo checklist is the heart of CheckFix – and unique in the market:
Instead of abstract reports, you receive an interactive dashboard where:
AI-powered implementation support: Our specially trained AI assistant supports you with implementation – regardless of which system you use (Plesk, cPanel, Azure, AWS…). Simply ask a question, receive concrete instructions for your environment.
Teamwork made easy:
Example from the report:
“CS3: Configure SPF record for odoo.example.com” → Precise instructions on which DNS entry needs to be set where. Unsure about implementation in your system? The AI assistant helps.
💡 Bonus: In addition to the dashboard, you receive a detailed PDF report for documentation and compliance evidence.
The good news: Your technician can do it!
CheckFix was developed precisely so that any competent technician can implement the to-dos – without external security consultants or specialized pentesters. Whether you’re a one-person startup or a large corporation.
Why this works:
Typical scenarios:
Small business:
Website by agency, server maintained by “IT acquaintance” → They can close all security gaps themselves with CheckFix
Medium/Large company:
Own IT department or external system administrator → Gets clear task list and can start immediately
💡 What’s special: A system administrator doesn’t replace a cybersecurity expert – but CheckFix translates security expertise so that any competent technician can implement it. Without five-figure consulting costs.
Ideally twice a year (included in CheckFix “Premium”) – for these reasons:
CheckFix makes security a regular routine instead of a one-time mandatory exercise.
Currently, the firewall undergoes a basic check. Specifically, 1,000 ports are examined.
No. Only those IP addresses connected to the domain name (company name) are found. For example, if a server is rented that neither uses an SSL certificate from the company nor has a DNS entry with the company name, it will very likely not be found by CheckFix. This is due to CheckFix’s fundamental principle of working like a hacker does. If a server/IP address is not connected to the company name, the hacker cannot associate it with the company, and therefore it is not typically at the center of a hacker attack.
User errors are one of the biggest problems in IT security. Most commonly through opening phishing emails or clicking on an untrustworthy link in an email. Of course, an automated tool can never prevent human error. However, if your email settings are perfect, fewer risky emails will get through to you. Therefore, work through the open to-dos from your CheckFix security check to protect yourself as best as possible. Nevertheless, it remains essential to train your employees well.
E-mail: office@checkfix.io
Phone: +43 660 77 24 524
Poststraße 3
8530 Deutschlandsberg
Austria
E-mail: office@checkfix.com
