# HackRisk – Full Reference > HackRisk is an AI-powered cybersecurity risk monitoring platform for SMBs, built by CyberLab (Cyberlab Security Limited, UK). This file is the expanded, machine-readable companion to https://www.hackrisk.ai/llms.txt. Everything below is sourced from the HackRisk website (https://www.hackrisk.ai). ## What is HackRisk? HackRisk is a platform developed to be your early warning system for cyber security risks – an affordable, lightweight solution to keep your environment secure between rounds of penetration testing. It gives SMBs continuous, outside-in visibility across their entire attack surface: identifying weaknesses, discovering hidden assets, and understanding how much of their information is already in the hands of bad actors. HackRisk provides continuous monitoring across six domains: - Dark Web Scanning – https://www.hackrisk.ai/services/dark-web-scanning - Recon Scanning – https://www.hackrisk.ai/services/recon-scanning - Vulnerability Scanning – https://www.hackrisk.ai/services/vulnerability-scanning - Phishing Simulations – https://www.hackrisk.ai/services/phishing-simulations - Security Awareness Training – https://www.hackrisk.ai/services/security-awareness-training - Supply Chain Security – https://www.hackrisk.ai/services/supply-chain-security Customers receive a HackRisk Score (graded A*–F) summarising their cybersecurity posture. See https://www.hackrisk.ai/what-is-a-hackrisk-score. An interactive platform tour is available at https://www.hackrisk.ai/platform-tour and an example HackRisk Report PDF at https://www.hackrisk.ai/example-hackrisk-report.pdf. ## The HackRisk Score (cyber risk score / rating) Source: https://www.hackrisk.ai/what-is-a-hackrisk-score Your HackRisk Score is a real-time measure of your organisation's cybersecurity risk, graded A*–F. It aggregates data from dark web monitoring, external reconnaissance, and vulnerability scanning into a single, actionable number. ### How the score is calculated HackRisk continuously aggregates data from three core intelligence streams: dark web monitoring, external recon scanning, and vulnerability detection. Each finding is weighted by severity and exploitability. The result is a risk percentage from 0 to 100, and it is a measure of risk, so a higher number means more risk: 0% is a clean bill of health and 75%+ is critical. That percentage is then translated into a letter grade – the same A*–F system that makes credit scores and energy ratings immediately understandable. The grade runs the opposite way to the percentage: A* is the best grade and sits at the lowest risk, F is the worst and sits at the highest. Only the services an organisation has switched on count towards the score, and it is a plain mean across those enabled modules – no module carries a bigger coefficient than any other, and there are no per-service weightings. That mean is then scaled by the band of the worst-performing module, so your weakest area carries the most weight: the fastest way to move the score is to fix whatever is worst, not whatever is easiest. ### Grade system Seven grades, listed in ascending order of risk. The range is the risk percentage, where a higher figure means more risk. | Grade | Risk percentage (higher is worse) | Label | Meaning | |---|---|---|---| | A* | 0–9 | Low risk | Your external security posture is strong. No critical exposures detected, credentials are clean, and your attack surface is well managed. | | A | 10–24 | Low risk | Few or minimal vulnerabilities identified. They should still be addressed, but none require urgent remediation. | | B | 25–36 | Medium risk | Minor issues are present but no critical exposures. Routine remediation and monitoring will bring this down. | | C | 37–49 | Medium risk | Several exposures exist that should be addressed. Attackers probing your perimeter may find exploitable weaknesses. | | D | 50–62 | High risk | Significant vulnerabilities are present. Credentials may be exposed. Remediation should be started soon. | | E | 63–74 | High risk | Serious weaknesses across your external surface. Remediation should be planned and started rather than queued. | | F | 75–100 | Critical risk | Severe exposure identified. Credentials may already be compromised and exploitation may already have occurred. Immediate remediation is advised. | The seven grades subdivide HackRisk's four risk bands: Low 0–24%, Medium 25–49%, High 50–74%, Critical 75%+. ### What affects your score - Exposed credentials: email addresses and passwords discovered in stealer logs, breach dumps, and dark web marketplaces. Even old credentials create risk if passwords are reused. - Open ports & services: unnecessarily exposed services increase your attack surface. Legacy protocols, admin interfaces, and unpatched services all count against you. - Known vulnerabilities: CVEs matched against your external infrastructure. Critical and high-severity vulnerabilities with public exploits have significant score impact. - Dark web mentions: references to your domain, brand, or executive names on dark web forums, paste sites, and threat actor channels. - SSL certificate health: expired, self-signed, or misconfigured SSL certificates signal poor security hygiene and can enable man-in-the-middle attacks. - Subdomain exposure: forgotten staging environments, legacy APIs, and dangling DNS records extend your attack surface beyond your primary domain. - Training completion: how much of their assigned security awareness training your people have finished, and how well they scored on it. Higher completion lowers your risk. - Phishing simulation results: how your team responds to simulated phishing. Opening the email counts against you, clicking the link counts for more, and entering credentials counts for most. ### How to improve your score 1. Check your dark web exposure. Start with credential exposure. If your staff email addresses appear in breach data, prompt password resets and enforce MFA immediately. 2. Patch and close open ports. Review your HackRisk recon scan results and close any services that don't need to be publicly accessible. Apply critical patches as a priority. 3. Audit your SSL certificates. Ensure all domains and subdomains have valid, trusted certificates. Enable HSTS and redirect HTTP to HTTPS everywhere. 4. Enumerate your attack surface. Use HackRisk's subdomain and asset discovery to identify forgotten infrastructure. Decommission or secure anything you don't actively maintain. 5. Monitor continuously. Your score reflects your current posture. New breaches, newly discovered subdomains, and new CVEs can change your score overnight. Your first HackRisk Score is free – no credit card required. Get it via https://www.hackrisk.ai/get-your-free-report. ## Dark Web Scanning (dark web monitoring for SMBs) Source: https://www.hackrisk.ai/services/dark-web-scanning Your credentials are already for sale. Find out before the attackers act. HackRisk provides continuous monitoring across millions of dark web sources, forums, and data breach repositories – so you know the moment your business is exposed. Key facts: - 32% of incidents involved stolen or misused credentials (IBM X-Force 2026). - 24/7 continuous monitoring. - Credentials are alerted as soon as they are found. - Millions of dark web sources scanned. ### Features - Credential leak detection: monitoring of paste sites, hacker forums, and breach dumps for your employees' email addresses and passwords. - Dark web forum alerts: instant notifications when your business is discussed in threat actor communities. - Third-party breach alerts: get notified when suppliers or partners suffer breaches that could affect your business. - Real-time notifications: actionable alerts delivered immediately via email and dashboard, with clear remediation guidance. - Data Breach Support Hub: expert resolution advice the moment we identify a breach affecting your data. ### How it works 1. HackRisk scans millions of dark web sources – continuously crawling paste sites, forums, Telegram channels, and breach databases around the clock. 2. Findings are matched to your domain and employees – every finding is cross-referenced against your registered domains and email patterns. 3. You are alerted instantly with remediation guidance – an actionable alert with exactly what was found, where, and the recommended steps to contain the risk. ## Recon Scanning (external attack surface mapping) Source: https://www.hackrisk.ai/services/recon-scanning See your attack surface through an attacker's eyes. Automated external reconnaissance maps every asset you own on the public internet – including the ones you've forgotten about. Key facts: 100% external asset visibility; 6 layers of exposure mapped (domain information, SSL certificates, subdomains, recon data changes, URLs, vulnerabilities); 0 agents to install for external scanning. ### Features - Subdomain enumeration: discover every subdomain associated with your domain, including legacy and forgotten properties. - Open port detection: identify all open ports on your external-facing infrastructure and flag unnecessary exposure. - Exposed service identification: detect admin panels, databases, APIs, and other services that should not be publicly accessible. - DNS record analysis: audit DNS records for misconfigurations that could enable subdomain takeover or spoofing attacks. - SSL certificate monitoring: track certificate expiry, detect mis-issued certificates, and identify weak configurations. - Shadow IT discovery: uncover cloud services and assets spun up outside IT's knowledge before attackers find them first. ### How it works 1. Enter your domain – no agents, no network changes, no IT project required. 2. HackRisk maps every external-facing asset – systematically enumerating subdomains, open ports, exposed services, and DNS records across your entire external footprint. 3. You get a prioritised remediation list – findings are ranked by severity so your team knows exactly what to tackle first to reduce risk fastest. ## Vulnerability Scanning Source: https://www.hackrisk.ai/services/vulnerability-scanning Find and fix vulnerabilities before attackers exploit them. Automated vulnerability scanning against your web applications and network assets, scored by severity so you always know what to fix first. Key facts: - 115k+ known vulnerabilities scanned for – powered by Tenable. - CVSS severity scoring standard. - 0 agents to install for external scanning; internal vulnerability scanning does require something installed. ### Features - Web application scanning: deep scanning of web applications for injection flaws, authentication issues, and logic vulnerabilities. - Network vulnerability detection: identify unpatched services, weak configurations, and known vulnerabilities across your network perimeter. - CVE identification: every finding is mapped to the relevant CVE so your team has full context on the threat and its exploitability. - OWASP Top 10 coverage: full coverage of the OWASP Top 10 most critical web application security risks. - Prioritised remediation: CVSS scoring plus business context means you fix the vulnerabilities that matter most, first. - Compliance reporting: export findings in formats suitable for Cyber Essentials, ISO 27001, and insurance requirement evidence. ### How it works 1. HackRisk scans your external-facing assets – publicly accessible web applications and network perimeter, no credentials or agents required. 2. Vulnerabilities are identified and scored – tested against thousands of known vulnerabilities, each finding scored by severity using CVSS. 3. You receive a prioritised fix list – the report tells you exactly what to fix, why it matters, and how to remediate each vulnerability. HackRisk Core also includes an internal vulnerability scan covering 5 endpoints; additional vulnerability scan targets (IPs, internal devices, or extra external services) can be added at +£8 per target per month. ## Phishing Simulations (phishing simulation campaigns) Source: https://www.hackrisk.ai/services/phishing-simulations Train your team to spot attacks before the real ones land. Realistic phishing simulations that test your people, identify the most at-risk staff, and trigger immediate training for anyone who clicks. Key facts: - 50% of all ransomware incidents started with malicious email or phishing (Sophos State of Ransomware 2026). - 300+ phishing templates. - Under 60 seconds to trigger training after a click. ### Features - Realistic phishing emails: campaigns crafted to mimic the tactics used by real threat actors, including spear-phishing and brand impersonation. - Individual click-through tracking: see exactly who clicked and who submitted credentials – tracked at the individual level so you know exactly where training is needed. - Instant training for clickers: anyone who clicks is automatically served a short training module at the moment they're most receptive. - Progress tracking over time: run regular campaigns and watch click rates fall as your security culture improves across your organisation. - Custom branding available: simulate attacks using your own supplier or partner brands for the most realistic possible test. ### How it works 1. HackRisk creates a tailored phishing campaign – realistic phishing emails matched to your industry and the current threat landscape. 2. Employees receive realistic test emails with no advance warning – just like a real attack. 3. Clickers get instant security training – those who click are immediately enrolled in a targeted training module, turning a failure into a learning moment. Phishing simulations are available bundled with Security Awareness Training as an add-on at +£2 per person per month. ## Security Awareness Training Source: https://www.hackrisk.ai/services/security-awareness-training Turn your biggest vulnerability into your strongest defence. Short, engaging training modules that build a security-first culture across your entire organisation – tracked and reported in your dashboard. Key facts: - 60% of breaches involved a human element (Verizon DBIR 2025). - 20+ training modules. - 5 minutes average module length. ### Features - Short-form video modules: bite-sized training videos designed to hold attention and drive retention – no hour-long compliance marathons. - Phishing awareness: teach your team to recognise phishing, smishing, and vishing attacks with real-world examples. - Password hygiene: password best practices, multi-factor authentication, and the dangers of credential reuse. - Social engineering defence: train staff to handle pretexting, impersonation, and physical social engineering attempts. - UK-specific governance training: modules covering UK GDPR, the Data Protection Act 2018, and Cyber Essentials – content many US-based providers simply don't offer. - Completion certificates: certificates generated for each completed module, useful for audits and insurance renewals. ### How it works 1. HackRisk recommends modules for your team based on your industry and risk profile. 2. Staff complete training at their own pace – modules are accessible on any device and can be completed in short sessions, with no disruption to the working day. 3. You track progress and compliance in your dashboard – completion rates, assessment scores, and certificates across your whole organisation in real time. ## Supply Chain Security (supply chain risk management) Source: https://www.hackrisk.ai/services/supply-chain-security Your suppliers are part of your attack surface. Know their risk. Automated supplier questionnaires with RAG risk ratings give you a complete picture of your supply chain's security posture – without the spreadsheet chaos. Key facts: - 30% of breaches involved a third party (Verizon DBIR 2025). - Unlimited supplier invitations included on every plan. - 100% web-based – no software for suppliers to install. - Supply Chain Security is included free with the Free HackRisk Report plan. ### Features - Supplier risk questionnaires: send standardised security questionnaires to your suppliers and third-party vendors in a few clicks. - Supplier score visibility: suppliers share their overall HackRisk Score and individual module scores, giving you a full picture of their security posture – not just a questionnaire result. - RAG questionnaire ratings: supplier questionnaire responses are automatically rated Red, Amber, or Green based on their answers, visible in your dashboard. - Evidence collection: suppliers can upload certificates, policies, and supporting documents directly through the platform. - Executive summary reports: board-ready reports showing your full supply chain risk posture, suitable for audit and insurance purposes. ### How it works 1. Send questionnaires to your suppliers – add your supplier list and HackRisk dispatches tailored security questionnaires on your behalf. 2. Suppliers complete the questionnaire through a simple web form and can upload supporting evidence – no software required on their end. 3. Review scores, questionnaire ratings, and reports – your dashboard shows every supplier's HackRisk Score, module scores, and questionnaire RAG rating at a glance, with drill-down detail and exportable board reports. ## Cyber Essentials Readiness Source: https://www.hackrisk.ai/pricing The Cyber Essentials Readiness plan helps UK businesses achieve Cyber Essentials or Cyber Essentials Plus certification – with a dedicated account manager and quarterly consultant sessions – while spreading the cost of certification. - Price: from £77/month on a 12-month term. - Includes everything in HackRisk Core, plus: - Dedicated account manager - Security consultant sessions - Cyber Essentials / Cyber Essentials Plus certification - Continuous compliance - Spread the cost of Cyber Essentials - Up to 10% cyber insurance discount - Optional add-on (Cyber Essentials Readiness plans only): CE+ pre-assessment consultation – a guided pre-assessment session before your Cyber Essentials Plus audit. Price on request. - HackRisk's vulnerability scanning supports compliance with exportable findings suitable for Cyber Essentials, ISO 27001, and insurance requirement evidence. - Security awareness training includes UK-specific modules covering Cyber Essentials, UK GDPR, and the Data Protection Act 2018. - To get started, speak with an expert: https://www.hackrisk.ai/contact ## Pricing Source: https://www.hackrisk.ai/pricing and https://www.hackrisk.ai/pricing.md. All prices in GBP. Fees are exclusive of applicable taxes. ### Free Report (Supply Chain Security) – Free - Price: Free – no card details needed. - What you get: - HackRisk Report in 24 hours - HackRisk Score - Top 5 results for every scan - AI-powered resolution advice - HackRisk Portal with unlimited users - One-time scan: Dark Web Scan, External Vulnerability Scan, external asset map - Supply chain security: unlimited supplier invitations, supplier questionnaires, certification sharing - Includes 30 days of portal access. If a paid subscription is not activated within 30 days, access simply ends – there is no automatic charge, because no card details are taken. - Get started: https://www.hackrisk.ai/get-your-free-report ### HackRisk Core – £49.99/month on a 12-month commitment - Price: £49.99/month on a 12-month commitment (£599.88 over the year), or £59.99/month on a 1-month rolling basis with no long-term commitment. Both are billed monthly - only the length of commitment changes. - Billing annually saves £120 a year compared to rolling – the equivalent of two months free. - The service is identical on both terms – only the billing changes. - Cancel anytime on rolling plans. No setup fees. - Everything in the Free Report, plus: - Continuous monitoring – 1 domain - Internal vulnerability scan – 5 endpoints - Instant email alerts - Regular, automated reports; every result, unredacted - Full resolution advice for every issue; on-demand reports - Up to 10% cyber insurance discount ### Cyber Essentials Readiness – from £77/month (12-month term) - Price: from £77/month on a 12-month term. - Everything in HackRisk Core, plus: dedicated account manager, security consultant sessions, Cyber Essentials / Cyber Essentials Plus certification, continuous compliance, spread the cost of Cyber Essentials, up to 10% cyber insurance discount. - Contact: https://www.hackrisk.ai/contact ### Add-ons | Add-on | Price | Notes | |---|---|---| | Additional domains | +£25 per domain / month | Extend monitoring to cover more of your business | | Additional vulnerability scan targets | +£8 per target / month | Add IPs, internal devices, or extra external services | | Security Awareness Training & Phishing Simulation | +£2 per person / month | Interactive training and realistic phishing tests to build staff resilience | | CE+ pre-assessment consultation | Price on request | Cyber Essentials Readiness plans only | ### Billing terms (summary) - Fees are payable monthly during the plan term and are exclusive of applicable taxes. - Plan terms are either rolling-monthly or 12-month; on expiry the agreement continues on a rolling monthly basis unless 30 days' written notice of non-renewal is given. - The trial (free report) runs for 30 days with no fees payable; access is revoked if a paid subscription is not activated. - Volume pricing is available for Managed Service Providers, and a charity/non-profit discount programme is offered – contact HackRisk to discuss. - Full terms: https://www.hackrisk.ai/terms-of-service ## The Free HackRisk Report Request a free HackRisk Report at https://www.hackrisk.ai/get-your-free-report. - Delivered within 24 hours. - Includes your HackRisk Score, top 5 results for every scan, and AI-powered resolution advice. - Includes 30 days of HackRisk Portal access with unlimited users. - No card details needed, no automatic charge, and no sales call. - The scan is read-only and external – nothing is installed and production systems are not touched. - Example report PDF: https://www.hackrisk.ai/example-hackrisk-report.pdf - Interactive platform tour: https://www.hackrisk.ai/platform-tour ## Frequently Asked Questions – General Source: https://www.hackrisk.ai (home page FAQs). ### What is HackRisk? HackRisk is a platform developed to be your early warning system for cyber security risks. An affordable, lightweight solution to keep your environment secure between rounds of penetration testing. This unique bundle gives you continuous, outside-in visibility across your entire attack surface - identifying weaknesses, discovering hidden assets, and understanding how much of your information is already in the hands of bad actors. ### What is my HackRisk Score? In your HackRisk Report, you'll see a risk level for each of the constituent services, and an overall risk score to show your current threat level. Your overall score accounts for the highest level of risk identified overall, and how vulnerable that would leave your systems to a threat actor. Use it to track your progress as you reduce risks across your environment. ### How does HackRisk keep my business safe? By continuously assessing your exposure to security risks, HackRisk gives you all the information you need to proactively address security risks and reduce your exposure to cyber threats. Expert resolution advice within the platform helps you to resolve vulnerabilities and data breaches, and provides best practice to avoid incidents. ### What risks does HackRisk identify? HackRisk identifies exposed assets, open ports, breached credentials, emerging vulnerabilities, and other potential entry points in real time. Exposed web assets - including admin panels, subdomains, login pages, expired certificates, open databases, and APIs - are mapped to help you visualise your attack surface. ### Do I have to install anything? Nothing to get started. Your free HackRisk Report and all external scanning run from the outside and are read-only, so there is no software to roll out and your production systems are never touched. The exception is the internal vulnerability scan included with HackRisk Core, which covers 5 endpoints and does need something installed on the systems you want scanned from the inside. ## Frequently Asked Questions – Pricing Source: https://www.hackrisk.ai/pricing. ### Is the free HackRisk Report really free? Yes. We perform a full external scan and generate your first HackRisk Report within 24 hours, completely free of charge. It includes 30 days of portal access, no card details are needed, and there's no sales call. The scan is read-only and external - nothing is installed and we don't touch your production systems. ### What's the difference between the 12-month term and 1-month rolling? The service is identical - only the length of commitment changes, and both are billed monthly. HackRisk Core is £49.99/month on a 12-month commitment (£599.88 over the year), or £59.99/month on a 1-month rolling basis with no long-term commitment. The 12-month commitment saves you £120 a year compared to rolling - the equivalent of two months free. ### What happens when my 30 days of free portal access end? If you don't activate a paid subscription within the 30 days, your portal access simply ends. There is no automatic charge - we never take card details for the free report, so there's nothing to bill. To keep your access, activate a paid subscription at any point during the 30 days. ### How do I cancel my subscription? On the 1-month rolling plan you can cancel at any time by letting us know in writing. On a 12-month term, give us at least 30 days' written notice and your plan won't renew at the end of the term. Fees already invoiced are non-refundable - see our Terms of Service for the full details. ### What does 'continuous monitoring - 1 domain' mean? HackRisk Core continuously monitors one root domain, such as example.com, across your external attack surface. You can extend monitoring to additional domains for +£25 per domain per month. ### What's included in Cyber Essentials Readiness? Everything in HackRisk Core, plus a dedicated account manager, security consultant sessions, and your Cyber Essentials or Cyber Essentials Plus certification with continuous compliance - letting you spread the cost of certification. Plans start from £77/month on a 12-month term. ### Can I add extras later? Yes. Add-ons such as additional domains, extra vulnerability scan targets, and Security Awareness Training with Phishing Simulations can be added to HackRisk Core or Cyber Essentials Readiness at any time. ### Do you offer discounts for MSPs or charities? Yes. We have volume pricing for Managed Service Providers and a charity/non-profit discount programme. Contact us to discuss your specific situation. ## Company & Legal - HackRisk is a trading name of Cyberlab Security Limited (Company No. 12392586), registered in England & Wales. - CyberLab is the company behind HackRisk: a specialist cyber security company, certified to ISO 27001 and accredited by CREST and the NCSC. - Website: https://www.hackrisk.ai - Email: hello@hackrisk.ai - Address: Mereside, Alderley Park, Congleton Road, Macclesfield, SK10 4TG, UK - About: https://www.hackrisk.ai/about - Contact: https://www.hackrisk.ai/contact - Pricing: https://www.hackrisk.ai/pricing (machine-readable: https://www.hackrisk.ai/pricing.md) - Terms of Service: https://www.hackrisk.ai/terms-of-service - Privacy Policy: https://www.hackrisk.ai/privacy-policy