Questions worth asking.
Everything we are asked most often, in one place. If yours is not here, get in touch and a person will answer it.
About HackRisk
What is HackRisk?
HackRisk is a platform developed to be your early warning system for cyber security risks. An affordable, lightweight solution to keep your environment secure between rounds of penetration testing. This unique bundle gives you continuous, outside-in visibility across your entire attack surface - identifying weaknesses, discovering hidden assets, and understanding how much of your information is already in the hands of bad actors.
What is my HackRisk Score?
In your HackRisk Report, you'll see a risk level for each of the constituent services, and an overall risk score to show your current threat level. Your overall score accounts for the highest level of risk identified overall, and how vulnerable that would leave your systems to a threat actor. Use it to track your progress as you reduce risks across your environment.
How does HackRisk keep my business safe?
By continuously assessing your exposure to security risks, HackRisk gives you all the information you need to proactively address security risks and reduce your exposure to cyber threats. Expert resolution advice within the platform helps you to resolve vulnerabilities and data breaches, and provides best practice to avoid incidents.
Do I have to install anything?
Nothing to get started. Your free HackRisk Report and all external scanning run from the outside and are read-only, so there is no software to roll out and your production systems are never touched. The exception is the internal vulnerability scan included with HackRisk Core, which covers 5 endpoints and does need something installed on the systems you want scanned from the inside.
Is HackRisk accredited?
Yes. HackRisk is a trading name of Cyberlab Security Limited, and the accreditations are the company's. CyberLab holds ISO 27001:2022 and ISO 9001, is a CREST member accredited for Penetration Testing and Vulnerability Assessment, is NCSC CHECK accredited, is an NCSC Certification Body for Cyber Essentials and Cyber Essentials Plus, is an IASME Consortium member and IASME Accredited Assessor, and is a signatory to the CREST AI Charter. The full list, with the certifying bodies, is on our About page.
What risks does HackRisk identify?
HackRisk identifies exposed assets, open ports, breached credentials, emerging vulnerabilities, and other potential entry points in real time. Exposed web assets - including admin panels, subdomains, login pages, expired certificates, open databases, and APIs - are mapped to help you visualise your attack surface.
Pricing and plans
Is the free HackRisk Report really free?
Yes. We perform a full external scan and generate your first HackRisk Report within 24 hours, completely free of charge. It includes 30 days of portal access and no card details are needed. Someone from our team may follow up to walk you through the findings, but there is never any obligation to buy. The scan is read-only and external - nothing is installed and we don't touch your production systems.
What's the difference between the 12-month term and 1-month rolling?
The service is identical, and both are billed monthly - only the length of commitment changes. HackRisk Core is £49.99/month if you commit to 12 months, or £59.99/month on a 1-month rolling basis you can leave at any time. Committing to the year saves you £120 over those 12 months, the equivalent of two months free.
What happens when my 30 days of free portal access end?
If you don't activate a paid subscription within the 30 days, you keep free access to the dashboard and the supplier section - the rest of the portal is no longer available. There is no automatic charge - we never take card details for the free report, so there's nothing to bill. Activate a paid subscription at any time to restore full portal access.
How do I cancel my subscription?
You can cancel yourself in the HackRisk portal - there's no form to fill in and no need to call us. On the 1-month rolling plan, cancelling stops your plan renewing the following month. On a 12-month term, cancel at least 30 days before the end of the term and your plan won't renew. Fees already invoiced are non-refundable - see our Terms of Service for the full details.
What does 'continuous monitoring - 1 domain' mean?
HackRisk Core continuously monitors one root domain, such as example.com, across your external attack surface. You can extend monitoring to additional domains for +£25 per domain per month.
What's included in Cyber Essentials Readiness?
Everything in HackRisk Core, plus a dedicated account manager, security consultant sessions, and your Cyber Essentials or Cyber Essentials Plus certification with continuous compliance - letting you spread the cost of certification. Plans start from £77/month on a 12-month term.
Can I add extras later?
Yes. Add-ons such as additional domains, extra vulnerability scan targets, and Security Awareness Training with Phishing Simulations can be added to HackRisk Core or Cyber Essentials Readiness at any time.
Do you offer discounts for MSPs or charities?
Yes. We have volume pricing for Managed Service Providers and a charity/non-profit discount programme. Contact us to discuss your specific situation.