Skip to content

Learn

Learn cyber security

Understand common security controls, assess your current position and use free tools to check the public configuration of your websites and domains.

Assess

Check a domain

Run a free check against the public security configuration of a domain you control.

Run security check

DNS, email authentication, TLS, headers and public technology. Exposed services need the verified check.

Get started

New to cyber security?

Learn the model behind every control: what you protect, what could go wrong, what you do about it, and how you show it is working.

Start with the basics
  1. AssetsWhat you need to protect
  2. RisksWhat could go wrong, and how badly
  3. ControlsWhat you do about it
  4. EvidenceHow you show it is in place
  5. MonitoringHow you know it still is
The ideas the basics guide explains, in the order most work follows them.

Explore by task

Guided paths

Guided path

Secure a website and domain

Learn what your domain exposes, check each part of its public configuration, run the complete check and keep it under watch.

A globe crossed by a network of connected points

10 stepsDNSTLSHTTPEmailExternal security

  1. Security basicsGuide
  2. Understand your external attack surfaceGuide
  3. Check DNS configurationTool
  4. Check TLS and certificatesTool
  5. Check HTTP security headersTool
  6. Check email authenticationTool
  7. Review exposed servicesTool
  8. Run the complete Ironfang security checkIronfang Security
  9. Fix findingsReference
  10. Turn on continuous monitoringIronfang Security

Guided path

Prepare for Cyber Essentials

Understand the scheme and its five controls, work through the checklist, gather evidence and go to a certification body ready.

A public building with a row of columns

12 stepsCyber EssentialsUKReadiness

  1. Cyber Essentials overviewGuide
  2. Cyber Essentials requirementsGuide
  3. Define the assessment scopeGuide
  4. Review firewalls and internet gatewaysGuide
  5. Review secure configurationGuide
  6. Review security update managementGuide
  7. Review user access controlGuide
  8. Review malware protectionGuide
  9. Use the Cyber Essentials checklistChecklist
  10. Collect technical evidenceGuide
  11. Resolve remaining gapsChecklist
  12. Continue to the official assessment and certificationGuide

Guided path

Prepare for ISO 27001

Scope an ISMS, assess and treat its risks, choose controls, find the gaps and prepare for audit. Ironfang's checks support the technical controls only.

Three glass plates stacked one above another

12 stepsISO 27001ISMSRisk managementReadiness

  1. ISO 27001 overviewGuide
  2. Define the ISMS scopeGuide
  3. Identify assets and interested partiesGuide
  4. Perform an information security risk assessmentGuide
  5. Define risk treatmentGuide
  6. Understand Annex A controlsGuide
  7. Build the Statement of ApplicabilityGuide
  8. Implement and document controlsGuide
  9. Perform a gap analysisGuide
  10. Collect evidenceGuide
  11. Prepare for internal audit and management reviewGuide
  12. Prepare for certificationGuide

Understand

Understand cyber security

The ideas and terms behind every check and framework, and the difference between the kinds of assessment.

Assess

Assess your security

Find out where you stand: a structured assessment, a working checklist and the complete check of a verified domain.

Prepare

Security frameworks

Cyber Essentials and ISO 27001, explained practically. Ironfang's checks give technical evidence for some controls; certification is a separate, formal process.

Free tools

Free security tools

View all security tools

Each tool runs the same checks as Ironfang Security against one domain, at once and without an account.

Fix

Fix security findings

Every Ironfang check has a reference page: what it looks at, the findings it can raise and the practical steps for correcting them. The guides explain the controls behind them.

Monitor

Monitor your external security

A free tool answers what is true now. Ironfang Security keeps the evidence for your verified domains and checks them again, so you can see whether something changed, whether a fix worked and whether a problem came back.