Cyber Health Score
External cyber assurance · UK

Understand your external risk. Fix what matters first.

Cyber Health Score helps organisations assess their publicly visible posture, prioritise findings, track remediation with evidence, and report progress from a single structured workspace.

  • Based on completed assessments
  • Verified assets only
  • Multi-tenant workspace
  • Nottingham, UK
cyberhealthscore.app / posture
Posture overview
Sample organisation
Cyber Health Score↑ sample
74
/ 100
DNS
81
Email
62
TLS
78
HTTP
74
Score trend
EarlierNow
Findings needing attention
22
findings
Needs action3
Review7
Medium12
Changes since last scan
↑ 4 findings resolved
+ 1 domain verified
! 3 new observations
Illustrative only. After sign-in you'll see notifications and report sharing for your organisation.

Sample dashboard preview with illustrative score 74 and finding counts. Not live tenant data.

Externally observable assessment
Based on publicly accessible information and completed assessments
Prioritised findings
Ordered by severity, exposure, and organisational context
Evidence-backed remediation
Record what changed, attach evidence, and verify improvement
Stakeholder-ready reporting
Technical and executive outputs for different audiences
Secure multi-tenant workspace
Tenant-isolated data, role-aware access, and audit history
The challenge

Many organisations lack a structured view of their external cyber posture.

CHS provides a single structured workflow, not a collection of unrelated tools, so your team can move from raw findings to evidenced improvement in a repeatable way.

See how it works
Too many disconnected security checks without a joined-up view
Technical findings that lack business context or clear priority
Uncertainty about what to address first, and what can wait
Limited evidence that remediation was completed
Difficulty communicating progress to leadership and stakeholders
Poor visibility of external supplier posture
How CHS helps

A structured journey from exposure to outcome

A

See what is externally visible

Understand domains, exposed services, configuration weaknesses, and other publicly observable signals from your verified assets.

  • Domain and asset discovery
  • DNS health and email security posture
  • SSL/TLS certificate status
  • Exposed service signals
B

Focus on what matters

Prioritise findings using severity, exposure, affected assets, and organisational context, not just a raw list of issues.

  • Severity-ordered findings
  • Category-level scoring
  • Score snapshots after each assessment
  • Overdue remediation visibility
C

Track remediation

Assign work, record progress, attach supporting evidence, and follow remediation through to completion.

  • Finding ownership
  • Status tracking
  • Evidence attachment
  • Remediation history
D

Verify improvement

Use completed reassessments to confirm what changed. Improvement is visible and evidenced, not assumed.

  • Before and after comparison
  • Score movement
  • Verified resolution
  • Audit-ready history
E

Report clearly

Create technical and executive views for different audiences, from detailed findings to boardroom summaries.

  • Technical reports
  • Executive summaries
  • Secure evidence report sharing where enabled
  • Governance-ready format
Ready to start?

Make your external cyber posture easier to understand and improve.

How it works

From setup to evidenced improvement

A repeatable six-step process that moves your team from raw exposure to structured, reportable cyber assurance. Results are based on completed assessments.

01Workspace setup

Create your workspace

Register your organisation account with a verified work email. Your workspace is isolated to your organisation from the outset.

02Asset management

Add and verify assets

Add the domains you own and complete domain ownership verification. Assessment scope stays tied to assets you control.

03Posture assessment

Review the completed assessment

View your Cyber Health Score, category breakdown, and prioritised findings from the completed external assessment.

04Findings

Prioritise remediation

Work through findings ordered by severity and exposure. Assign ownership, set status, and focus on what matters first.

05Evidence & verification

Record evidence and reassess

Attach supporting evidence to remediation activity. Request a reassessment to verify that exposure has been reduced.

06Reporting

Share progress

Generate technical and executive reports. Share evidence outputs with leadership, stakeholders, or auditors where your plan and role allow.

Assessment results are based on completed external observations of verified assets. CHS does not perform real-time breach detection or penetration testing.

Platform

Everything in one structured workspace

Explore the major Cyber Health Score product areas in one place, from posture and findings through governance, evidence, reporting, and authorised email simulations.

Cyber Health Score

See your external security posture in one prioritised score.

Completed assessments produce a Cyber Health Score with category context so teams can see overall posture at a glance.

  • Overall Cyber Health Score with category breakdown
  • Score movement after completed assessments
  • Severity-ordered findings summarised alongside posture
Explore security scans

Posture overview. Illustrative Cyber Health Score for Northbridge Labs

Who it serves

One platform, different perspectives

CHS serves the same organisation from multiple angles, not separate products for separate teams.

Business leaders

Understand what is exposed, track progress against priorities, and receive executive reporting without needing a technical background.

  • Executive summary reports
  • Score and trend visibility
  • Governance-ready evidence

IT and security teams

Investigate prioritised findings, manage remediation activity, attach evidence, and request reassessments to verify improvements.

  • Finding detail and remediation guidance
  • Evidence management
  • Domain and asset oversight

Governance and risk teams

Review findings mapped to your risk register, maintain remediation history, and prepare assurance material for audits and board reviews.

  • Findings mapped to risk register
  • Audit-ready history
  • Compliance evidence report output
Supplier Assurance
In development

Supplier security posture, coming to the platform

Supplier Assurance is in development. The intended direction is external posture observations for organisations in your supply chain, based on publicly accessible information rather than supplier-system access or consent-dependent scans.

Roadmap preview only. Supplier Assurance is not generally available yet.

  • Planned: monitor supplier domains you choose to review
  • Planned: review observable changes over time
  • Planned: record internal assessment notes and risk context
  • Planned: keep a review history for governance conversations

This preview does not imply that supplier monitoring, review history, or assurance workflows are available in your workspace today. It also does not imply supplier consent, internal system access, or a complete vendor-risk assessment.

Explore available products
Supplier observationsIn development
Example infrastructure provider
example-infra.co.uk
Medium
4 observationsLast reviewed Sample date
Example managed IT provider
example-managed.co.uk
Low
2 observationsLast reviewed Sample date
Example SaaS platform
example-saas.io
Review
7 observationsLast reviewed Sample date

Illustrative sample only. Roadmap preview, not live supplier data or a generally available product.

ASPE campaign dashboardAuthorised
Sample awareness exercise
Illustrative · sample participants
Complete
48
Sent
17
Clicked
31
Did not click

Illustrative campaign metrics only. Not live tenant data.

ASPE

AI-Powered Social Engineering Evaluator (ASPE)

Run controlled, authorised email-based phishing simulations to help teams recognise and respond to suspicious email. Campaign workflows include recipient setup, preview, delivery tracking, education pages, and reporting within your workspace.

Authorised email campaign workflows
Plan email simulations scoped to participants you configure
Controlled email delivery
Configurable intensity, timeline, and email scenario context
Delivery and click reporting
De-duplicated click engagement metrics from your campaign dashboard
Post-simulation education
Education pages help explain missed signals after a simulation
Evidence & Reporting

Move beyond a list of findings

Record what changed, attach supporting evidence, reassess the exposure, and communicate the outcome. Evidence is the proof. Reporting communicates the result.

1
Finding
Observation from completed assessment
2
Remediation
Work recorded, ownership assigned
3
Evidence
Supporting document attached
4
Reassessment
Exposure verified by next assessment
5
Verified outcome
Confirmed improvement recorded
6
Report
Communicated to relevant audience

Evidence records

Attach supporting files, screenshots, or configuration exports directly to a finding's remediation record. Evidence is scoped to the finding and visible in generated reports.

  • Linked to specific finding
  • Verification state tracked
  • Visible in report output
  • Maintained as audit history

Attaching a document does not automatically prove compliance or resolution. Verification through reassessment is a separate step.

Reports

Generate technical and executive reports from within your workspace. Different report types suit different audiences, from detailed findings to high-level progress summaries.

  • Technical report with full finding detail
  • Executive summary with score and trend
  • Evidence package for audit preparation
  • Secure sharing where supported
Security & trust

Built with responsible data handling in mind

CHS is designed for organisations that take data responsibility seriously.

Tenant isolation

Each organisation operates within its own isolated workspace. Data is not shared between tenants.

Role-aware access

Access within your workspace is controlled by role. Invite team members with appropriate permissions.

MFA support

Multi-factor authentication is supported to protect access to your organisation workspace.

Audit history

Activity within your workspace is logged. Review history supports governance and accountability requirements.

Scoped support access

Support access to your workspace is scoped and controlled. You remain in control of your data.

Secure report sharing

Reports can be shared securely with stakeholders where the feature is supported by your workspace plan.

Plans

Plans for every stage

Start with domain posture assessment and grow as your requirements expand.

For organisations getting started

Free

£0 / month

For first-time assessment and basic posture visibility.

  • 3 scans per month
  • One lifetime ASPE trial
  • Up to 100 recipients in your email simulation trial
  • Basic security score
  • Core findings and recommendations
Start free
Most popular
For growing organisations

Pro

£39 / month

£390 / year(same monthly entitlements)

For growing teams that need repeatable scanning, reports, and monthly ASPE campaigns.

  • 40 scans per month for new subscriptions
  • 10 verified assets
  • 3 ASPE campaigns per month
  • 250 recipients per ASPE campaign
  • Authorised email-based phishing simulations
  • Scan history and score trends
  • Downloadable reports
Get started
For organisations needing wider coverage

Business

Contact sales

For multi-asset operations and incident-ready support controls.

  • 1000 scans per month
  • Multiple assets and higher scale limits
  • Advanced diagnostics
  • Priority support
  • Support access policy and grant controls
Contact sales

Not sure which plan suits your organisation? Contact sales or view full pricing.

FAQ

Common questions

More detail is available in our documentation.

Get started today

Make your external cyber posture easier to understand and improve.

Understand your exposure. Prioritise what matters. Demonstrate progress.

Based on completed assessments of verified assets. Not real-time monitoring or penetration testing.

  • No intrusive testing
  • Verified assets only
  • Your data stays in your workspace