External security posture
Fictional example · professionally reviewed

What can the public internet see about your business?
Your public website, business email domain and internet-facing systems can reveal issues that are easy to miss. Get a professionally reviewed, plain-English report showing what to address first. Fixed scope: $497, with no passwords or internal access required.
See the deliverable first
The finished report is designed for two audiences at once: owners receive a plain-English explanation of business impact, while technical teams receive the evidence, remediation steps and validation checks needed to act.
Fictional example · professionally reviewed
What to expect
Every engagement begins with the current environment, business priorities and the evidence needed to make a defensible decision.
Review public DNS, mail routing, name servers, CAA, SPF, DMARC and DNSSEC evidence for up to five named domains or hostnames you authorize.
Evaluate public website availability, HTTP-to-HTTPS enforcement, response-security headers, cookie protections and security-contact publication.
Perform safe, connect-only checks of common TCP services on up to six authorized public IPv4 addresses. No credentials, service payloads, banners or exploits are used.
Receive a professionally reviewed report with an executive risk summary, visual risk breakdown, technical evidence, plain-English explanations and prioritized remediation guidance.
Request an expanded-scope quote before purchasing the $497 checkup.
Service guide
Useful scope, operating context and decision points for organizations evaluating this service.
The $497 Small Business Network Security Checkup gives an organization an evidence-based view of what its authorized public domains and IPv4 addresses expose to the internet. Wolex reviews public DNS and email-security posture, HTTPS and browser protections, security-contact publication and common public TCP-service exposure.
This is a non-destructive external posture review. It does not require credentials or internal access, and it does not include exploitation, password testing, phishing, denial-of-service testing, internal scanning or authenticated configuration review. Deeper firewall, Wi-Fi, VPN, endpoint, cloud and internal assessments are scoped separately.
Automated observations do not become customer findings without professional review. The finished report separates confirmed priorities from positive controls, explains each issue in plain language and preserves the technical evidence needed by an IT provider or internal administrator.
The report includes an executive risk rating, visual finding summary, documented assessment coverage, prioritized remediation guidance and validation steps. It is normally delivered through a protected link within two business days after a complete intake, and the service includes one limited validation retest requested within 30 days.
The checkup is designed for professional small businesses, nonprofits and growing organizations that need a credible first step without committing to a full internal assessment. It is especially useful when a cyber-insurance questionnaire, customer request, internet-facing change or recurring uncertainty raises questions about the public attack surface.
Customers can use the prioritized report with Wolex, an existing provider or an internal technical team. If remediation, authenticated firewall review, internal assessment or recurring monitoring is needed, that work is proposed separately so the $497 scope remains clear.
Frequently asked questions
No. The $497 checkup covers up to five named public domains or hostnames and six named public IPv4 addresses. An allocated network range is not automatically scanned. For more targets or a network-wide assessment, use the expanded-scope request form before paying.
The protected report is normally delivered within two business days after Wolex receives a complete secure intake. Every automated observation is professionally reviewed before release.
No. This is a fixed-scope external posture review of only the public domains and IPv4 addresses you authorize. It does not include exploitation, password testing, phishing, denial-of-service testing, internal scanning or authenticated firewall, Wi-Fi, VPN, cloud or endpoint configuration review.
You provide the business name, delivery email, authorized public domains or IPv4 addresses and a short environment summary through a secure, single-use intake. Do not provide passwords, private keys, MFA codes, session cookies or configuration files.
Yes. Remediation, authenticated firewall review, internal assessment and recurring monitoring are available as separately scoped services. You can use the report with Wolex, your current provider or your internal team.
Yes. The report is delivered through a signed, expiring link. Assessment content is handled under the published retention process and is not shared with third parties without authorization.
Next step