A fictional owner with a very real question
Imagine Maya, the owner of a fictional twelve-person accounting firm in Beaverton. Her company uses cloud email, a public website, remote access supplied by an IT provider and a small office firewall. Nothing appears broken. Employees can work, clients can send documents and the website loads normally. Still, Maya keeps wondering whether something important is exposed to the internet that nobody has noticed.
She does not want an open-ended consulting project, and she is not ready to authorize penetration testing. She wants a focused answer to a smaller question: what can the public internet observe right now, which observations matter, and what should she ask her provider to fix first? That is the problem a fixed-scope external checkup is designed to address.
Maya is a fictional composite, not a Wolex customer testimonial. The scenario reflects the ordinary uncertainty many small professional offices face when several vendors, cloud services and years of changes have shaped the environment.
The assessment begins with authorization, not scanning
Before any technical collection, the business identifies the domains and public IPv4 addresses it owns or has explicit authority to assess. The scope should be written clearly. A responsible provider does not turn a company name into permission to scan every related system it can find.
For the Wolex Small Business Network Security Checkup, the customer submits only authorized public assets and a short environment summary. Passwords, private keys, MFA codes, configuration files and internal access are neither requested nor accepted. That boundary keeps the engagement understandable and reduces the chance that sensitive information is collected unnecessarily.
The first deliverable is therefore not a list of tools or commands. It is a defensible statement of what was authorized, what was reviewed and what remained outside the engagement.
Public domain and email controls tell a business story
A company domain does more than direct visitors to a website. Public DNS records identify name servers, mail providers, certificate-authority controls and email-authentication policy. An external review can examine whether those records are present, syntactically valid and consistent with the business services that appear to be in use.
SPF helps describe which systems may send mail for a domain. DMARC tells receiving organizations how to handle messages that fail authentication and can provide reporting that helps the owner understand legitimate and unauthorized sending sources. Missing or overly broad policy does not prove that fraud has occurred, but it can make impersonation easier and reduce the business visibility needed to strengthen enforcement safely.
For Maya, a finding such as missing DMARC needs two explanations. The owner needs to understand the invoice-fraud and customer-trust impact. The technical provider needs the observed DNS evidence, a cautious rollout sequence and a validation method. A professional report serves both audiences instead of handing the owner an unexplained technical warning.
- DNS and mail-routing evidence for authorized domains
- SPF and DMARC posture with plain-language business impact
- DNSSEC and certificate-authority authorization observations
- Positive controls that are already working as intended
HTTPS review goes beyond seeing a padlock
A browser padlock is useful, but it does not describe the entire website-security posture. An external check can confirm whether ordinary HTTP traffic is redirected to HTTPS, whether the secure site responds consistently and whether common response headers give the browser additional instructions for handling content, framing, permissions and referrer information.
The absence of a header such as Content Security Policy does not automatically mean the website is compromised. It means a protective layer was not observed and should be evaluated with the website provider. A good finding avoids fear-based language, explains the limitation and gives the provider a safe validation path, such as testing a report-only policy before enforcement.
Cookie attributes and a published security contact can also be reviewed from the public side. These observations are useful because they are repeatable: after the website provider makes an approved change, the same request can confirm whether the public result changed.
A public IP check looks for exposure without attempting entry
When a customer authorizes a public IPv4 address, a safe check can attempt ordinary TCP connections to a defined list of common services. The objective is to record whether a connection was observed, not to log in, collect a banner, send a service payload, guess a password or exploit a vulnerability.
This distinction matters. If Remote Desktop or an administrative service accepts a connection from the internet, the observation deserves professional review because it may create a direct place for attackers to target credentials or newly discovered weaknesses. The service may still be intentional. The report should identify the exposure, explain the risk and recommend an approved VPN, trusted source restriction or another controlled path without changing production systems during the assessment.
A port that is not observed is not proof that every path is safe. It may be closed, filtered, rate-limited or unreachable from the assessment location. That limitation belongs in the report so a positive observation is not mistaken for a guarantee.
- Connect-only tests of a defined common-service set
- No credentials, exploitation, service payloads or password guessing
- Evidence tied to the exact authorized public address and observation time
- Professional review before an observation becomes a customer finding
What this checkup deliberately does not claim
An external posture review is not an internal vulnerability assessment, a firewall-configuration audit, a compliance certification or a penetration test. It cannot see an unpatched workstation behind the firewall, verify every internal network segment or confirm how administrators manage accounts. Those questions require separate authorization, access and scope.
Clear limitations protect the customer from buying the wrong service. They also make the findings more credible. The business knows which risks were evaluated and can decide whether a deeper firewall, Wi-Fi, VPN, endpoint, cloud or internal assessment is justified.
For many small businesses, the external checkup is valuable precisely because it is a defined first step. It establishes evidence without asking the owner to surrender credentials or commit to a broad project before the initial priorities are understood.
The report should explain what to do on Monday morning
A long list of scanner output does not give an owner a plan. A professional report should separate confirmed priorities from informational observations, show the positive controls already present and organize remediation into a sequence the business can manage.
Maya should be able to read the executive section and explain the first three actions in her own words. Her IT provider should be able to open the same report and find technical evidence, recommended change boundaries and validation steps. A chart can show the distribution of findings, but the chart is useful only when the written interpretation explains why the priorities matter.
The Wolex report pairs plain-English meaning with technical evidence, includes a prioritized action plan and provides one limited validation retest requested within thirty days. The retest does not expand the original scope; it checks whether the public result for the original assets and findings changed after remediation.
- Executive risk summary for the owner
- Visual finding breakdown and positive controls
- Technical evidence and confidence for the provider
- Prioritized 7-, 30- and 60-day actions
- A validation method for each important recommendation
How to decide whether the $497 checkup is worthwhile
The checkup is a good fit when a business wants an evidence-based external baseline, has a defined set of public domains or IPv4 addresses and needs a report that can be used with Wolex, an existing provider or an internal administrator. It is especially useful before a cyber-insurance discussion, after a provider or website change, or when the owner has never received a clear explanation of the company’s public exposure.
It is not the right purchase when the immediate need is incident response, internal scanning, a compliance audit, exploitation testing or urgent remediation. Those situations need a different scope. A serious provider should say so before accepting payment.
Wolex Technologies provides the fixed-price checkup for small businesses and nonprofits in Beaverton, Hillsboro, Portland and beyond. Customers can review the complete illustrative sample before buying, authorize only the assets they want assessed and receive the professionally reviewed report normally within two business days after completing the secure intake.
