Find answers in our FAQ

Do you still have questions before deciding on CheckFix’s automated security check with fix strategy? You might find the answers in our frequently asked questions. And if not – feel free to contact us: office@checkfix.io.

1. What is the difference between a hack test, a pentest, and the CheckFix Security Check?

A “hack test” is an informal umbrella term for any proactive security check from an attacker’s perspective – the attempt to find vulnerabilities before real hackers can exploit them. Both classic penetration tests and CheckFix are forms of a hack test, but they differ significantly in depth, effort, and cost.

The key differences:

  • Penetration Test (Pentest): Manual, in-depth security analysis by IT security experts who actively look for vulnerabilities and attempt to exploit them. Can also examine internal systems. Cost: typically €5,000–15,000 per assessment, usually once per year.

  • CheckFix Security Check (free): Automated analysis of your external attack surface – everything publicly accessible via your domain. No manual effort, no active intrusion into your systems. Delivers an A–F rating within 24 hours.

  • CheckFix Basic / Premium (€490–950/year): Extends the Security Check with a prioritised to-do list giving concrete instructions on which findings to fix and where. 96% cheaper than a classic pentest and feasible on a regular basis.

Which option fits whom?
Pentests are suitable for in-depth audits of individual systems or specific compliance requirements. CheckFix can be used as a prelude to a pentest to quickly identify the biggest entry points that a professional can then examine more thoroughly.

For small and medium-sized businesses that want to review their external attack surface regularly – to close vulnerabilities before hackers find them – CheckFix is the right choice.

For supply chain reviews under NIS-2, DORA, or ISO 27001, there is a dedicated variant: the CheckFix Risk Manager.

⇥ Start now with the free Security Check

 

2. How does the CheckFix security analysis work?

CheckFix analyzes your IT infrastructure from an external perspective – exactly as hackers would see your company.

Step 1 – Discovery:

  • Automatic scan of all publicly accessible systems based on your domain. We extract this from your email address. You can subsequently have 2 additional domains checked.
  • Identification of servers and mail infrastructure
  • Detection of open ports and services

Step 2 – Vulnerability Assessment (automated):

  • Cross-reference with CVE database (known vulnerabilities)
  • Check of SSL/TLS certificates
  • Analysis of mail security (SPF, DKIM, DMARC)
  • Security header check

Step 3 – Report & Dashboard:

  • Clear dashboard with A-F rating
  • PDF report with all technical details
  • Unique: ToDo checklist with prioritization for your designated technician to work through the tasks

Important: CheckFix works non-invasively – no attacks are simulated, only publicly available information is analyzed.

3. What does CheckFix cost and what services are included?

Free Security Check:

  • Initial vulnerability analysis
  • Basic assessment of your IT security
  • Non-binding and immediately available

CheckFix Basic: €590/year

  • 2 complete security analyses per year
  • Permanent dashboard access
  • PDF reports with technical details
  • Unique ToDo checklist with step-by-step instructions
  • Prioritization by criticality (Critical → High → Medium → Low)
  • Comparison with other companies
  • AI-Assistent

ROI calculation: A single security incident costs SMEs an average of €25,000. CheckFix costs less than €50/month – insurance that actively protects instead of just paying out.

⇥ Choose from our plans now

4. Which companies is CheckFix suitable for?

CheckFix is suitable for any company with an online presence – from sole proprietorships to corporations.

You benefit from CheckFix if you have:

  • Website(s), online shop, or web applications
  • Email communication (own server or cloud like Microsoft 365/Google Workspace)
  • Optional: Remote access (VPN, RDP) or APIs

CheckFix examines your systems from an attacker’s perspective from the outside – exactly where 90% of all cyberattacks begin.

For SMEs: Professional IT security without five-figure pentest budgets. Vulnerabilities are explained so your technician can fix them themselves.

Typical scenario: Website by agency, mail server set up by a “tech-savvy friend” – CheckFix shows whether everything is secure. Because a system administrator doesn’t replace a cybersecurity expert (and vice versa 😉).

For larger companies: Quick external security checks for management and IT leadership. Uncover forgotten open ports, outdated systems, or configuration errors.

Typical scenario: Management receives an objective overview of security status – independent of internal or external IT service providers.

5. Does CheckFix help with NIS2/KRITIS compliance?

CheckFix covers the technical part of your security requirements: regular vulnerability assessment of your IT systems.

What CheckFix provides:

  • Regular monitoring for technical vulnerabilities
  • Documented security checks as proof
  • Actionable recommendations for your IT team

What CheckFix does NOT cover: NIS2 and KRITIS also require administrative measures such as policies, process documentation, risk registers, and incident management.

For supply chain management: We are currently developing NisFix – a platform specifically for the NIS2 requirement “supply chain security”. NisFix helps you monitor suppliers, document audits, and maintain records.

CheckFix will be integrated as a technical verification component. You can start now: Use CheckFix today for yourself and your suppliers – you’ll need the documented security checks for compliance anyway, regardless of which solution you choose later.

⇥ Interested in NisFix? Join our waiting list!

6. What exactly does CheckFix check?

CheckFix performs regular external security checks – from the perspective of an attacker on the internet. This covers where over 70% of all cyberattacks start: at your publicly accessible IT infrastructure.

Everything accessible via your domain(s) on the internet is checked:

  • Servers & Hosting: Open ports, outdated software, known CVEs
  • Domains & Subdomains: Automatic detection of subdomains
  • Mail Infrastructure: SPF, DKIM, DMARC configuration (spoofing protection)
  • SSL/TLS Certificates: Validity, encryption strength, configuration
  • Web Services: Security headers (HSTS, CSP, X-Frame-Options)
  • Warning for publicly accessible critical services
  • CVE Database: Cross-reference with 200,000+ known vulnerabilities

Not checked:

  • Internal networks without internet access
  • Systems behind firewalls without external exposure
  • Social engineering or physical security

💡 Why external? The external attack surface is the largest entry point for cybercriminals. Those who are secure here eliminate the most common attack vector.

Scope: You can monitor up to 3 domains per CheckFix subscription. For larger infrastructures or individual requirements, contact us – we’ll find a suitable solution!

7. How often is my infrastructure checked?

Depending on the selected package, CheckFix performs 1-2 comprehensive security checks per year:

  • Basic: Annual security check
  • Premium: Bi-annual check (2x per year)

Why this rhythm?

Annual or bi-annual checks are the standard for professional security audits and correspond to common compliance cycles (ISO 27001, NIS2, KRITIS). Between checks, your IT team has time to systematically address the vulnerabilities found.

CheckFix delivers prioritized, actionable recommendations instead of a daily flood of alerts. This allows you to use resources efficiently and achieve measurable improvements.

💡 Your advantage: You receive focused reports with clear to-dos – not thousands of unfiltered alerts like with continuous monitoring tools. You can decide the timing yourself through our practical dashboard.

Need more frequent checks? Contact us for a customized quote.

8. How secure is my data during the analysis?

CheckFix works exclusively with publicly accessible information:

  • No login attempts or brute force
  • No exploitation of vulnerabilities
  • No data manipulation
  • GDPR-compliant data processing in Austria
  • Only external scanning (as hackers would do)

CheckFix shows you what attackers can see – without attacking itself.

9. What do the A to F ratings in the security check mean?

The scoring system is based on school grades:

  • A (Excellent): No critical vulnerabilities, best-practice configuration
  • B (Good): Minor optimization potential
  • C (Action needed): Medium risks should be addressed
  • D (Critical): Serious gaps present
  • E-F (Acutely vulnerable): Immediate action required

Important: The better your rating, the less interesting you are to hackers who usually look for “low-hanging fruit”.

10. What is the ToDo checklist and how does it help me?

The ToDo checklist is the heart of CheckFix – and unique in the market:

Instead of abstract reports, you receive an interactive dashboard where:

  • Concrete tasks are sorted by priority
  • Step-by-step instructions for remediation are provided
  • Affected systems, IPs, and domains are clearly identified
  • Technical details are available for IT service providers
  • Understandable explanations are available for decision-makers

AI-powered implementation support: Our specially trained AI assistant supports you with implementation – regardless of which system you use (Plesk, cPanel, Azure, AWS…). Simply ask a question, receive concrete instructions for your environment.

Teamwork made easy:

  • Invite colleagues, IT service providers, or external technicians
  • Everyone sees the current to-dos and can check them off directly
  • Work through the list together – everyone at their own pace
  • At the next check, you’ll see the improvement in black and white

Example from the report:
“CS3: Configure SPF record for odoo.example.com” → Precise instructions on which DNS entry needs to be set where. Unsure about implementation in your system? The AI assistant helps.

💡 Bonus: In addition to the dashboard, you receive a detailed PDF report for documentation and compliance evidence.

11. Do I need expensive security experts or can my technician implement this?

The good news: Your technician can do it!

CheckFix was developed precisely so that any competent technician can implement the to-dos – without external security consultants or specialized pentesters. Whether you’re a one-person startup or a large corporation.

Why this works:

  • Every vulnerability is translated into clear, actionable steps
  • Step-by-step instructions with concrete commands
  • Our GPT assistant helps with system-specific questions (Plesk? cPanel? AWS? – no problem)
  • Technical details are present but explained understandably

Typical scenarios:

Small business:
Website by agency, server maintained by “IT acquaintance” → They can close all security gaps themselves with CheckFix

Medium/Large company:
Own IT department or external system administrator → Gets clear task list and can start immediately

💡 What’s special: A system administrator doesn’t replace a cybersecurity expert – but CheckFix translates security expertise so that any competent technician can implement it. Without five-figure consulting costs.

12. How often should the security analysis be performed?

Ideally twice a year (included in CheckFix “Premium”) – for these reasons:

  • New vulnerabilities: New CVEs are published daily
  • System changes: New servers, services, domains
  • Certificates: Expiration dates are often overlooked
  • Compliance: NIS2 requires regular checks
  • Employee turnover: New admins, forgotten access
  • Before audits and certifications – CheckFix can be used as evidence

CheckFix makes security a regular routine instead of a one-time mandatory exercise.

13. Does CheckFix perform a firewall check?

Currently, the firewall undergoes a basic check. Specifically, 1,000 ports are examined.

14. Are all servers/IP addresses found?

No. Only those IP addresses connected to the domain name (company name) are found. For example, if a server is rented that neither uses an SSL certificate from the company nor has a DNS entry with the company name, it will very likely not be found by CheckFix. This is due to CheckFix’s fundamental principle of working like a hacker does. If a server/IP address is not connected to the company name, the hacker cannot associate it with the company, and therefore it is not typically at the center of a hacker attack.

15. Does CheckFix help against user errors?

User errors are one of the biggest problems in IT security. Most commonly through opening phishing emails or clicking on an untrustworthy link in an email. Of course, an automated tool can never prevent human error. However, if your email settings are perfect, fewer risky emails will get through to you. Therefore, work through the open to-dos from your CheckFix security check to protect yourself as best as possible. Nevertheless, it remains essential to train your employees well.

Contact

E-mail: office@checkfix.io

Phone: +43 660 77 24 524

secinto

secinto GmbH

Poststraße 3

8530 Deutschlandsberg

Austria

E-mail: office@checkfix.com

*Studie KPMG zur Cybersecurity in Österreich 2023