Services

Cyber security services, in one score.

Six continuous services covering your technology, your people and your suppliers. Each is scored on its own and all of them roll into the single number on the front of your HackRisk Report – so you can see where you stand without reading a vulnerability table.

Start Your Free Trial

What every service includes

Continuous, not annual

Every service runs continuously rather than once a year. Your exposure changes the moment someone spins up a subdomain or reuses a password, and a report dated last March cannot tell you that.

Written to be forwarded

Findings arrive in plain English with a severity and a recommended fix, not as a CVE dump. The report is built to be read by whoever signs off the budget, which is rarely the person who understands the finding.

Backed by people

The platform is automated; the advice behind it is not. CyberLab's team is accredited by CREST, the NCSC and to ISO 27001, and they are who you reach when a finding needs a decision rather than a description.

Scored, so you can see movement

Each service produces its own score and all of them roll into one number. That makes progress legible: you can show a board that exposure fell this quarter without asking them to read a vulnerability table.

Who these services are for

HackRisk is built for organisations that have something worth protecting and no dedicated security team to protect it – typically UK businesses between ten and a few hundred people, where security sits with an IT manager, an operations lead, or an outsourced provider alongside everything else.

That shapes what the services do. They assume nobody has time to triage a raw scanner output, that evidence will be needed for an insurer, a Cyber Essentials assessment or a client security questionnaire, and that the person reading the report may have to explain it to someone else the same afternoon.

How the six work together

The services cover three kinds of exposure, and the gaps between them are where most incidents start. Recon and vulnerability scanning cover your technology – what is reachable from the internet and what is wrong with it. Dark web scanning covers your credentials, including the ones leaked through somebody else's breach. Phishing simulations and awareness training cover your people, who are the route in when the technology holds. Supply chain security covers everyone else's exposure that becomes yours the moment you share data with them.

Running them separately produces six views that never quite reconcile. Running them together produces one, which is the point of the score: a weakness in one area cannot hide behind strength in another, and you can see at a glance which of the three is dragging the number down.

How this differs from a penetration test

A penetration test is a person, working to a scope, trying to break in over a fixed window. It goes deeper than any automated service and it is the right tool when you need assurance on a specific system, or a report an auditor will accept. What it does not do is tell you what changed the following week.

These services are the other half: continuous, broad, and shallower by design. They watch the whole external surface and tell you when it moves. Most organisations need both – monitoring to catch drift, and a pentest when something specific has to be proven. If a test is what you actually need, CyberLab does those too, and we will say so rather than sell you monitoring instead.

What it costs to start

The first HackRisk Report is free and arrives within 24 hours of a scan, with 30 days of access to the portal behind it. No card is required, because nothing is due – the point is that you see your own exposure before deciding whether it is worth paying to watch.

After that, HackRisk Core is £49.99 a month on a twelve-month commitment or £59.99 rolling, and Cyber Essentials Readiness starts at £77 a month. Additional domains, extra scan targets and per-person training are priced individually.

Questions worth asking

Which cyber security services does a small business actually need?

At minimum, visibility of what is reachable from the internet and whether your credentials have leaked – recon scanning, vulnerability scanning and dark web scanning cover that. Phishing simulations and awareness training matter as soon as you have staff handling email, which is to say immediately. Supply chain security becomes urgent once you hold client data or your clients start sending you security questionnaires.

Do I need all six services, or can I start with one?

The free HackRisk Report covers your external exposure across the scanning services, so you can start by seeing what is there rather than choosing in advance. The subscription bundles them because the gaps between services are where incidents start, but training and phishing simulation are priced per person and can be added when you are ready.

How quickly will I see results?

The first report arrives within 24 hours of the scan completing. Findings after that appear as they are discovered rather than on a reporting cycle, so a newly exposed service or a freshly leaked credential shows up when it happens.

Is this a replacement for a penetration test?

No, and it is not sold as one. Monitoring is continuous and broad; a penetration test is deep, scoped and point-in-time. They answer different questions, and most organisations that take security seriously end up doing both.

Who runs the services behind the platform?

CyberLab, a UK security consultancy accredited by CREST, the NCSC and to ISO 27001. HackRisk is the productised version of work its team already does, which is why there are people to escalate to rather than only a dashboard.

You can see how the scoring works in how the HackRisk Score works, read an example report before committing to anything, compare the tiers on pricing, or check which integrations will push findings into the tools your team already uses.

What's your HackRisk Score?

Get started in minutes. Your free report lands within 24 hours.

Start Your Free TrialNo credit card required