Free Tools

Twenty-six tools, no signup required to try most of them.

Checklists, calculators, generators and simulations — built from the same practitioner experience behind our advisory work. Most show results instantly; a few offer a free PDF if you'd like a copy emailed to you.

Readiness checklists

Score yourself, get a gap list

Ransomware Readiness Checklist

10 questions on backups, segmentation and response — score plus a downloadable PDF gap list.

Start checklist →

Cyber Insurance Readiness Checker

The controls insurers actually look for — MFA, backups, EDR — scored against typical underwriting questions.

Start checklist →

DPDP Act Quick-Check

A fast gut-check on how your personal-data handling stacks up against the Digital Personal Data Protection Act.

Start checklist →

MFA & Access Control Self-Assessment

A narrower, identity-focused cousin of the SOC-CMM assessment — eight questions on access control maturity.

Start checklist →

SOC-CMM Maturity Assessment

Our flagship 15-question, 5-domain assessment with instant gauge scoring.

Start assessment →

Industry Maturity Benchmark

Already have a SOC-CMM score? See how it compares to illustrative ranges for your industry.

Compare your score →
Calculators

Turn a number into a decision

CERT-In Reporting Deadline Calculator

Enter your detection time, get the exact six-hour cutoff and a who-to-call checklist.

Calculate deadline →

Data Breach Cost Estimator

Industry and record count in, a rough breach-cost range out — useful for budget conversations.

Estimate cost →

SOC Staffing Calculator

Alert volume and coverage hours in, an estimated analyst headcount for 24x7 coverage out.

Calculate staffing →
Generators

Pick your scenario, get a starting document

Vendor Risk Questionnaire Generator

Pick your industry, get a tailored third-party security questionnaire to send to vendors.

Build questionnaire →

Incident Response Contact Tree Builder

Fill in your roles and names, get a printable escalation tree for the wall.

Build contact tree →

Security Policy Pack Generator

Pick which policies you need, get downloadable starter outlines for each.

Build policy pack →

Tabletop Exercise Scenario Picker

Choose your industry and top concern, get a free scenario script to run with your team.

Pick a scenario →
Spot-the-scam simulations

Learn by trying to get fooled

Phishing Email Simulator

A realistic inbox view — click the parts of the email that gave the scam away.

Try the demo →

Spot the Fake Login Page

Side-by-side real vs. spoofed login pages — find the tells before you'd type a password.

Try the demo →

Vishing Call Simulator

A simulated "IT support" call transcript — pick your responses and see what gave the scam away.

Try the demo →

Missing a tool you'd find useful?

Everything here is free and built by practitioners. If there's a gap, let us know.

Suggest a tool
DNS & domain checks

Real, live checks against your own domain

Email Spoofing Risk Checker

SPF, DKIM and DMARC analyzed instantly — see how easy it'd be to spoof email from your domain.

Check your domain →

Typosquat & Lookalike Domain Detector

Generates likely typosquat variants of your domain and checks which ones are actually registered.

Check for lookalikes →

Domain Age Checker

See exactly when any domain was registered — a brand-new domain is a classic scam signal.

Check domain age →
Live intelligence feeds

Real public threat data, refreshed automatically

CISA Known Exploited Vulnerabilities

Vulnerabilities CISA confirms are actively being exploited right now — not just theoretical CVEs.

View live feed →

Live Phishing Domain Watcher

Watches Certificate Transparency logs in real time for newly-issued lookalike-brand certificates.

View live feed →

Global Threat Activity Map

Real, recently-reported malicious IPs, geolocated and visualised — refreshed hourly.

View map →
Analyzers & scanners

Paste something, get a real answer

Email Header Analyzer

Paste raw headers, get SPF/DKIM/DMARC results and the server hop path — parsed entirely in your browser.

Analyze headers →

Dependency Vulnerability Checker

Paste your package.json or requirements.txt, checked against Google's free OSV.dev database.

Check dependencies →

Port & Protocol Reference

Searchable reference of common ports, what runs on them, and why each one matters.

Search ports →
Demos & games

Learn by trying it yourself

What This Website Already Knows About You

Live, real-time browser exposure demo — see your own fingerprint surface, no login required.

See your exposure →

Build the Kill Chain

Drag the stages of a cyber attack into the correct order — a quick game, not just a quiz.

Play now →

Operation Foothold — Mini CTF

A real three-clue capture-the-flag challenge hidden in page source, HTTP headers, and cookies.

Start the challenge →

We use cookies for basic site function and, where ads are enabled, for advertising personalisation. See our Privacy Policy.