What Does a Free Cybersecurity Assessment Actually Include?

Something free in cybersecurity tends to raise the same eyebrow as something free at a car dealership. Somebody, somewhere, is paying for it, and it is usually the person who agreed to the "quick, no-obligation" chat. That instinct is not wrong. A lot of "free assessments" in this industry are thinly disguised sales calls, built to manufacture urgency rather than deliver information.
The fair question, then, is not whether free cyber assessments exist. They clearly do. It is what one actually checks, whether the result tells a business anything it did not already suspect, and whether accepting it commits anyone to buying something. Those questions deserve straight answers, so here they are.
What a Free Cybersecurity Assessment Is Supposed to Do
At its core, a free cybersecurity assessment is an external check of how a business looks from the outside, from the perspective of someone trying to get in. It does not require installing software on every device or handing over admin credentials. Most reputable versions work off a single input: a company domain.
From there, automated scanning tools examine what is publicly visible or exposed about that domain, the way a would-be attacker might reconnoitre a target before doing anything else. That includes checking whether email systems can be spoofed, whether staff credentials have already leaked in a prior breach elsewhere on the internet, whether internet-facing systems have known weaknesses, and whether sensitive data is sitting somewhere it should not be.
None of this replaces a full security audit. It is a starting snapshot, not a forensic deep-dive. The distinction matters because a good provider will tell a business exactly that, rather than presenting a five-minute scan as if it were a comprehensive review.
AffinityScan: What Gets Scanned
Affinity MSP built AffinityScan as an instant, domain-based cyber risk check. A business enters its domain, and within roughly sixty seconds, the scan returns results across four areas:
Email security. Whether the domain's email authentication settings, such as SPF, DKIM, and DMARC, are configured correctly enough to stop someone else sending convincing emails that appear to come from that business. This is the same weakness behind a large share of business email compromise incidents, where an attacker impersonates a trusted sender rather than breaking into anything directly.
Network visibility. What is publicly discoverable about the systems sitting on that domain, including exposed services or open ports that were perhaps never meant to be internet-facing in the first place.
Data exposure. Whether staff credentials or company data connected to that domain already appear in known data breaches elsewhere. This is a genuinely useful check most business owners have never run, because the breach that exposed the password was probably not even their own; it might have happened to a completely unrelated service an employee once signed up for using their work email.
Vulnerabilities. Known technical weaknesses in whatever infrastructure the scan can see from the outside, prioritised by how exploitable they are rather than dumped into an undifferentiated list.
Every one of these checks something a business would otherwise have no visibility into at all. That is really the value case for a free scan: not comprehensiveness, but a first honest look at problems that are, by definition, invisible from the inside.
In our experience, the email security result is the one that most often surprises people. Business owners tend to assume email is either secure or it is not, without realising that authentication settings can be half-configured in a way that looks fine but does nothing to stop impersonation. It is rarely deliberate neglect. It is usually a setting nobody revisited after the domain was first set up.
What the Report Actually Covers
The output is a Risk Snapshot Report, structured to be read by a business owner, not just an IT manager. Rather than a wall of technical output, it groups findings by the four areas above, flags what is genuinely urgent versus what is worth monitoring, and explains in plain language what each finding means and why it matters.
This is the part where a lot of "free scans" quietly fall short. Some competitor tools generate a report designed to look alarming regardless of what they find, because a frightening report is easier to convert into a sales meeting than an accurate one. A scan is only useful if the findings are proportionate. Not every result needs to be a five-alarm fire, and treating them that way just trains business owners to stop trusting the process.
What Happens After the Scan
This is usually where the scepticism is fairest, so it deserves a direct answer. After the scan runs, Affinity MSP's team reviews the results with the business, at no cost and with no obligation to engage further. The purpose of that conversation is to explain what the findings mean in the context of that specific business, not to run a script toward a signed contract.
For some businesses, the result is reassuring: a handful of small fixes, most of them free or already within reach internally. For others, it surfaces a genuine gap, an unmonitored exposed service, or credentials that have already leaked, that is worth addressing regardless of who ends up doing the work. Either outcome is a legitimate one. A scan that only ever finds problems requiring a paid engagement is not measuring risk. It is measuring how the report was written.
Is It Worth Doing?
For a cost of five minutes and a domain name, yes. The realistic worst case is a report confirming there is nothing urgent to worry about, which is itself useful information for a business owner who has never had that confirmed. The realistic best case is catching something like a leaked credential or a misconfigured email setting before it becomes an actual incident, which is precisely the kind of gap the Australian Cyber Security Centre's Essential Eight is built around closing.
The genuine risk with any free assessment, from any provider, is not the scan itself. It is what happens afterward. Ask what the follow-up conversation actually involves before agreeing to it, and treat a report that finds nothing but reasons to buy something as a signal in itself.
Run an AffinityScan
AffinityScan takes a domain and about sixty seconds, and returns a Risk Snapshot Report covering email security, network visibility, data exposure, and vulnerabilities. There is no cost, no software to install, and no obligation attached to the follow-up conversation.
FAQ
Is a free cybersecurity assessment accurate?
A free scan checks what is externally visible, such as email authentication, exposed services, and leaked credentials. It is accurate for what it measures, but it is a snapshot, not a full audit of internal systems.
Does AffinityScan require installing anything?
No. AffinityScan runs from a business domain name and does not require software installation or system access.
Will I be pressured to buy something afterward?
Affinity MSP's follow-up conversation explains the findings and is genuinely no-obligation. A results conversation that only ever leads to a sales pitch regardless of findings is a fair reason to be sceptical of any provider.
How is this different from a full cybersecurity audit?
A full audit examines internal systems, policies, and controls in depth, often over days or weeks. A free assessment like AffinityScan is a fast, external-only starting point.




