Choosing an assessment
The six Verisight assessments, what each one looks at and what it needs from you.
| Assessment | Looks at | What you provide | Touches your systems? |
|---|---|---|---|
| Full Security Snapshot | Your internet-facing domains | Verified domains + authorisation | Passive only |
| Adversary View | What an attacker can discover about you | Verified domains + authorisation; optional active-testing opt-in | Passive by default; active only if you opt in |
| Microsoft 365 Health Check | Entra ID, Exchange Online, Teams, SharePoint, Defender, Purview configuration | Admin consent to a read-only app | Read-only API access |
| AWS Security Review | S3, EC2 security groups, IAM, password policy, plus ~660 deep checks | A read-only IAM role | Read-only API access |
| Cyber Essentials Readiness | The five Cyber Essentials control areas | Your answers and evidence notes | No network testing |
| Supply Chain Check | Open-source dependencies in your projects | Lockfiles / manifests | Nothing; we only read the files |
Which one first?
- Most organisations: start with a Full Security Snapshot. It needs nothing but a DNS record.
- You run on Microsoft 365: add the Microsoft 365 Health Check. Misconfigured identity and email are the most common way into small businesses.
- You run on AWS: the AWS Security Review, which also unlocks the Infrastructure map.
- You build software: a Supply Chain Check, then keep Stack Watch on.
- A customer or insurer asks about Cyber Essentials: Cyber Essentials Readiness.
How ordering works
- Choose the product in Assessment Products and fill in its scope.
- Place the order. If your plan includes it, it's fulfilled immediately; otherwise you pay through Stripe Checkout.
- The assessment appears in Assessments. Depending on the product it then needs authorisation, a connector, or nothing more.
Paying does not by itself authorise any scanning. Collection always needs its own explicit authorisation or connector consent.