Free External Vulnerability Scan on One Public IP

NetFusion Designs runs a free external vulnerability scan on one public IP address for Canadian businesses. It is a standing offer with no end date. Tell us which address you want looked at, we scan it from the internet the way an attacker would, and then we walk you through what came back. There is nothing to install, and nothing on your internal network is touched.

Perform a free test
Get started!

External Vulnerability Assessment

User application identity authentication login
Bank capital office building law
Email
Radio station signal antena tower
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Be the first to know when we launch new features and events.
Free external scan

What the scan actually looks at

The scan views your public IP from the open internet, which is the same vantage point an attacker has before they know anything about your business. It records what your edge is advertising to the world and compares that against publicly known weaknesses.
Externally reachable services: what is actually answering on that address, and whether it is meant to be answering at all.
Open ports, including the ones opened years ago for a project that finished and were never closed again.
Exposed management interfaces such as firewall, router, remote desktop and administrative logins that can be reached straight from the internet.
TLS and certificate problems, including expired or mismatched certificates, weak ciphers, and outdated protocol versions that are still enabled.
Known-vulnerable software versions that your edge devices and services report publicly in their banners and response headers.
Geeshan Subasingha professional headshot

What the free scan does not cover

This is the part most offer pages leave out, so we will be direct about it. A free external scan is a narrow instrument, and knowing where it stops is the only honest way to judge whether the results mean anything for your business.
It is not a penetration test. We identify weaknesses that are visible from the outside. We do not chain them together to see how far into your environment they would lead.
It does not touch your internal network. File servers, workstations, line-of-business applications and the segmentation between departments all sit behind the firewall and stay out of scope.
It does not test your staff. There is no phishing simulation, no pretext phone call, and no attempt to talk anyone into handing over a password.
It does not attempt exploitation. We will tell you that a door appears to be unlocked. We do not open it, and we do not walk through it.
It does not produce an audit certificate. Nothing in the results can be handed to an auditor, an insurer or a client as proof of compliance, and we would rather say so plainly than let you assume otherwise.
It covers one public IP address. If your organization publishes services from several addresses, the scan sees only the address you give us.
If one of those exclusions describes the thing you are actually worried about, the free scan is the wrong tool, and we would rather tell you that now than afterwards. Our penetration testing and vulnerability assessment service covers internal networks, multiple addresses and controlled exploitation.

What you get back

You get reviewed findings rather than a raw scanner export. An unfiltered tool dump is mostly noise, and handing someone a wall of red text is not the same as telling them what is wrong.
Padlock

Findings ranked by severity

Everything we find is ordered by how much it actually matters to your business, so the items worth acting on sit at the top rather than being buried among low-risk observations.
User application identity authentication login

Plain terms, and what to do next

Each finding is explained in language you can take to an owner or a board: what is exposed, why it matters, and the specific change that would close it. Where the fix is straightforward, we say so.
We are deliberately not quoting a turnaround time, a page count or a number of checks performed, because all three depend entirely on what is actually out there on your address. What we will commit to is that a person at NetFusion Designs reads the results before you do.

What happens after the scan

No obligation, either way
We go through the findings with you, and that is the whole of it. There is no obligation attached to the scan, no contract to sign before you see the results, and no requirement to become a client in order to be told what is wrong with your perimeter.
A follow-up conversation usually covers three things: which findings we would address first and why, whether the work is something your existing team or IT provider can handle, and whether anything we saw points to a wider problem worth examining properly. If your current provider can close the gaps, that is a perfectly good outcome and we will tell you so.
A scan that finds nothing serious is a legitimate result too. It happens, it is worth knowing, and we are not going to manufacture a crisis in order to create a sales conversation. If your edge is in good shape, the honest answer is that your edge is in good shape.
Scope

Who this suits, and who should ask for more

The free scan suits an organization that wants a straight answer to a narrow question: is anything obviously exposed on our public IP right now? It is a sensible first look if you have recently inherited an environment, changed IT providers, or simply never had anyone check.
Suits you if you want to know whether anything obvious is exposed on your public IP today.
Ask for more if you carry a compliance obligation, face an audit, or have a client security questionnaire to answer.
Ask for more if your real concern is the internal network, staff behaviour, or how far an attacker could travel once inside.
Businesses working under privacy legislation, sector regulation or a client's security requirements generally need evidence that a free external scan cannot produce. Our guide to IT compliance in Ontario sets out what those obligations tend to ask for.
If the internal network is the real worry, that is penetration testing and internal vulnerability assessment territory rather than a free external scan. And if you are weighing up providers rather than a single test, how to choose an IT provider is a more useful place to start.
Digital shield graphic representing network security and vulnerability protection

Questions we get asked about the free scan

Is it safe to run against our systems?

Yes. The scan reads what your public IP address already advertises to anyone on the internet. It does not attempt exploitation, it does not try to log in to anything, and it does not send traffic designed to break a service.

Will it affect our systems or slow anything down?

It should not. The traffic involved is small and looks much like the ordinary internet noise your firewall already handles every day. If you would prefer we run it outside business hours, tell us when you send the address and we will arrange it.

Do you need credentials or access to anything?

No, and that is rather the point of an external scan. We need the public IP address and your confirmation that you are authorized to have it tested. No accounts, no VPN, and no agent installed anywhere.

What if you find something serious?

We tell you promptly and directly rather than saving it for a scheduled call, and we explain what we would do about it. If your own team or provider can close it sooner than we can, we will say that too. Our helpdesk and Security Operations Centre are staffed 24/7, so there is always somebody to talk to.

Is this really free?

Yes. There is no charge for the scan or for the conversation about the results, and no card details are collected at any stage. It is a standing offer, not a promotion with a closing date.

So what is the catch?

There is no catch, but there is a reason. The scan gives us a genuine reason to introduce ourselves, and it gives you something useful whether or not you ever become a client. Some organizations take the findings straight to their existing provider and we never hear from them again. That is a fair trade for us, and we would rather be open about the motive than pretend there is not one.

Request your free external vulnerability scan

Send us the public IP address you want looked at, along with your name and email, and we will take it from there. NetFusion Designs is a SOC 2 Type 2 attested managed service provider at 141 Main Street N, Markham, Ontario, with a staffed helpdesk and Security Operations Centre running 24/7. If you would rather ask a question before sending an address, call 647-476-5259.