Skip to content
simplesec

Product

Scan, prioritise, translate. SimpleSec does no more than that.

SimpleSec finds the vulnerabilities in your IT, sorts them by their real risk and explains them twice: technically for your IT, and in plain words for your management.

Step 1: Scan

From the outside like an attacker. From the inside like your IT.

Two separate systems, two views of the same IT: bookable on their own, brought together in one platform. The scans run regularly, not once a year.

The methodtwo views, one platform
SimpleScan
Attack surface management
Subdomains
www · vpn · shop-alt
Reachable services
14 open from the internet
DNS & mail
SPF · DMARC · CAA
DMZ · 6 servers
reachable from outside
Server VLAN · 17
servers, NAS, backups
Clients · 548
workplaces
Production · 34
checked gently
SimpleSec box
checks from the inside
Outside: the internet
Inside: your network
SimpleSec platformone place:IT viewManagement viewNetwork map
Check path Findings flow into the platform

SimpleScan

Outside viewbookable on its own

Your company, as the internet sees it.

It finds all domains, subdomains and reachable services, the forgotten ones too, and reports what changes: newly seen, gone, altered. It also checks the DNS and mail configuration: SPF, DMARC, orphaned records.

  • No installation: one approval is enough
  • Starts passive; active checks only after proof of domain control
  • The data stays in the EU

SimpleSec box

Inside viewbookable on its own

Your network, checked fully from the inside.

A small appliance in your network checks the full internal infrastructure: servers, firewalls, NAS, clients, Active Directory and Microsoft 365, so everything that is invisible from the outside.

  • One network socket is enough, no rebuild
  • Finds outdated firmware, factory passwords, open shares
  • Sensitive devices are checked gently or left out

Together: one platform. Both systems are built separately and are bookable on their own. Whoever uses both gets the combined view: attack chains from the first reachable subdomain to the backups.

Step 2: Prioritise

Not every vulnerability is a risk.

SimpleSec rates every finding with three questions: is it reachable from the outside or from the inside? How important is the affected system? Is the hole under active attack?

Findings that together make an attack path are shown as a chain, with the point where it breaks the fastest.

Attack chain: extortion through encryption

  1. 9.4Entry: RDP open to the internet~30 min · breaks the chain
  2. 7.1Spread: SMB signing switched off~20 min
  3. 5.2Target: backups reachable~45 min

Step 3: Translate

Two views, the same data.

IT view

For the people who fix it.

Every action with step-by-step instructions and an effort estimate. After the work, the next scan checks it automatically. Fixed is only what the scan confirms.

9.4Remote access (RDP) reachable from the internet3389/tcp · NLA=off~30 min
Factory password NAS: fixed, confirmed by the scanyesterday

Management view

For the people who answer for it.

One page a month: traffic light, risk score and three questions in plain words. What is possible, what are we doing about it, are we getting better? Without a single technical term.

Report July 2026 Red

How secure is your company?

A path from the outside to your backups is possible at the moment. Three actions break it. About two hours of work.

So that you know where you stand

What SimpleSec is not.

No antivirus, no firewall.

SimpleSec does not replace protection software. It shows where your gaps are. You still need those systems.

No attack detection.

SimpleSec finds vulnerabilities before they are used. It does not watch attacks that are running.

It fixes nothing automatically.

The work stays with your IT or your service provider. SimpleSec delivers the instructions, the effort and the check afterwards.

No absolute security.

That does not exist, not for anybody. SimpleSec makes your risk visible and smaller, not zero.

FAQ

Before you have to ask.

Does SimpleSec replace our antivirus or our firewall?

No. SimpleSec finds vulnerabilities before they are used. You still need protection software and a firewall. The scan does show whether these systems are outdated or configured wrongly.

How long does the setup take?

External scans start without an installation. For the box, one week is typically realistic, and it depends on your IT.

Where is our data?

Scan results are stored encrypted and kept strictly separate per tenant. We disclose the location, the hosting and the data processing agreement in the conversation and in the contract.

Does the scan disturb our operation?

The scans are set to a low load. Sensitive devices such as production, medical technology or old printers can be checked gently or left out completely.

Do we need our own security staff?

No. The platform makes the prioritisation, the instructions and the reports. Your IT or your service provider does the work, with an effort estimate per action.

What does SimpleSec cost?

The price depends on the scope and the number of systems; we name concrete figures in the conversation.

Let's talk about your systems.

Setup in one week. Then you decide.

Request a demo