Forensic Five reviews what you expose on the internet, how you watch the property, and whether you can recover when something fails. Work is scoped in writing and delivered as a report you can share with counsel, insurers, or a board.
Websites, servers, and applications reviewed from the outside in. Assessments, scans, and consulting.
Walk the yard. Write coverage and evidence. Review the cameras so they do not become the breach.
What is copied, who can wipe it, and the last proven restore. Recovery is a finding, not a checkbox.
The public scan does not require an account. Paid work does not start until you approve a written scope and fee.
Cyber stays the core practice. Site security and backup sit beside it so a theft, a camera breach, and a failed restore are not three different vendors.
Website, application, and server reviews. Free public-site scan as the on-ramp. Consulting when you already have a deadline or an incident.
Walk the property. Write coverage and evidence. Review the security of the cameras so the system that watches the yard is not itself the hole.
A restore that has been proven, copies that ransomware cannot delete in the same night, and a report an insurer can read.
Public-surface check. No account. Useful, not a substitute for an assessment.
Run a scanRemediation, incidents, and controlled attack simulation when a scan is not enough.
ConsultingYou approve the scope, the window, and the fee before any testing begins. The report states what was covered and what was not.
We confirm targets, constraints, and what “done” looks like: a website, a server, a property walk, or a backup restore test.
Analyst review of the named target: a scan, a site walk, or a restore test. We validate what matters and discard noise before it reaches your inbox.
Prioritized findings, evidence, and recommended next steps — written for operators and for the people who approve the work.
We walk the report with you, help sequence remediation, and retest when you want confirmation the fix held.
Most organizations hesitate for the same reasons. These are the terms we work under so a review does not become a risk of its own.
We test only the hosts, applications, and accounts you authorize in writing. We do not scan neighbouring systems, staff personal devices, or third-party services you do not control.
Assessments and scans are scheduled with you. Destructive or high-impact tests are off by default. If a check could affect availability, we say so before it runs.
Reports are confidential to the named client. We do not publish client names, scores, or findings. We will sign an NDA when your counsel requires it.
The free website scan is a public-surface check. It is useful. It is not a substitute for a scoped assessment. Paid work includes analyst review and a written report you can stand behind.
You receive a written scope and fee before we start. There is no requirement to buy hosting, cameras, tools, or a monthly package to get the report. Follow-on work is optional.
If a finding is unconfirmed, we mark it that way. We do not promise that every vulnerability has been found. The report states method, coverage, and limits so you can brief a board or an insurer honestly.
We work with professional services firms, yards, and growing companies that need a defensible answer about their internet-facing systems, their property, and their backups, without staffing a security department.
Reports are written so a technical lead can act and a director can brief. The report is not contingent on buying hosting, cameras, software, or a retainer from us or from an affiliated company.
Typical assessment window, including the written report
Usual response to new inquiries during business hours
Public website scan — no login and no mailing-list signup
We will execute your confidentiality agreement before work begins
Tell us the website, the property, or the backup. We will reply with what we would review, how long it takes, and a fee before any work starts.