Resilience

What an attacker sees of your company, we see first.

We analyse what your company exposes on the internet: email, website, passwords leaked online. Without touching your systems. You get a clear report, in plain language, with the priorities to fix.

Ten seconds, public data only, no sign-up.

Exposure reportexample-srl.it
Example
3 issues to fixTwo are serious: anyone can send email in the company’s name, and some company passwords are already online.
  • HighDMARC missingEmail
  • High4 addresses in public data breachesPasswords
  • MediumSPF not strictEmail
  • OkValid HTTPS certificateWebsite

Try it now, free

Find out in ten seconds whether someone can send email pretending to be your company.

We only read the public SPF, DMARC and MX records, straight from your browser through Cloudflare’s public DNS. Nothing is stored.

Passive analysis: no access to your systems
Reports in plain language, no jargon
A clear path to NIS2 compliance
What we do and what it costs, in writing before we start

Three fair objections. Three honest answers.

“We’re too small for anyone to care.”

Nobody picks you: attacks are automated and try everyone, one after another. Small companies are the easiest, because nobody is watching them.

“We already have antivirus and an IT person.”

Good: they protect your computers from the inside. We look at what can be seen from the outside: forgeable email, certificates, company passwords leaked online. Two different jobs.

“NIS2 doesn’t apply to us.”

Maybe not directly. But companies covered by NIS2 must secure their supply chain: if you work for them, sooner or later they will ask you.

What actually happens.

From the first check to continuous monitoring. Every step is declared to you in advance, in writing.

  1. Passive assessment

    We only read public information: DNS, certificates, data breach archives. Just as an attacker would, without touching anything.

  2. Report and priorities

    A grade from A to F, issues ranked by severity and what to do about each one, in plain language.

  3. In-depth analysis

    With your signed authorisation we actually test the weak points. Never before that signature.

  4. Continuous monitoring

    We alert you when something changes: a password in a new data breach, a certificate about to expire, an exposed service.

The report you receive

Ask for a sample report
Score by area
Email45
Passwords and data breaches55
Internet exposure70
Website and certificates85
Priority number 1

Turn on DMARC

Today anyone can send emails that look like yours: fake invoices to customers, payment requests to suppliers. One DNS record fixes it, in an afternoon.

What’s inside
  • Overall grade and score by area
  • Every issue with its severity and fix
  • What an attacker saw, with evidence
  • A PDF to hand to your IT person

NIS2: find out in two minutes whether it applies to you.

The EU NIS2 directive, implemented in Italy by Legislative Decree 138/2024, requires companies in many sectors to manage cyber security. And to look after their suppliers’ security too.

€10 million
or 2% of total worldwide annual turnover, whichever is higher: the maximum fine for essential entities. For important entities, €7 million or 1.4%.
24 hours
to send an early warning to CSIRT Italia after becoming aware of a significant incident. The full notification within 72 hours.
Personally
management bodies approve the security measures and are liable for breaches.

Source: Legislative Decree no. 138 of 4 September 2024, arts. 23, 24, 25 and 38.

Are you subject to NIS2?Question 1 of 6
Instant result, no sign-up.

A typical scenario: 90 days to answer your customer.

A 25-person company makes components for a customer that falls under NIS2 and is now asking its suppliers for guarantees. Illustrative example, not a real case.

  1. Day 1Passive assessmentReport with grade and priorities.
  2. Week 2Urgent fixesEmail protected, exposed passwords changed, certificates in order.
  3. Month 1In-depth analysisWith signed authorisation: exposed services and real weak points.
  4. Month 3Documents for the customerMeasures adopted, incident procedure, improvement plan.
  5. ThenContinuous monitoringAlerts when something changes, periodic reports.

Who is behind Resilience.

Resilience is led by a Cybersecurity Analyst and Penetration Tester. Our job is to look at companies the way attackers do, and close the doors before anyone opens them. No products to sell you, no off-the-shelf packages: only what your company needs.

  • Cybersecurity Analyst
  • Penetration Tester

Based in Monza, working remotely with clients across Italy.

Hack The Box Academy Hybrid Analyst badge
Hack The Box Academy Junior Cybersecurity Analyst path Completed. “Hybrid Analyst” badge: attack and defence. Hack The Box rank: Professional

Completed modules

  • SQL Injection Fundamentals
  • SQLMap Essentials
  • Cross-Site Scripting (XSS)
  • Web Fuzzing
  • Attacking Web Applications with Ffuf
  • Using Web Proxies
  • Login Brute Forcing
  • Windows Event Logs & Finding Evil

Skills

  • Vulnerability assessment
  • Penetration testing
  • Network security
  • Cybersecurity operations
  • Troubleshooting

Our commitments

  • Never an active test without your signed authorisation.
  • What we do and what it costs, in writing and before we start.
  • Plain language, not tech jargon.

Frequently asked questions.

Is it legal to analyse my company?

Yes. The first assessment uses only public information, the same anyone on the internet can see. Active tests happen only after a written authorisation signed by you.

Do you need to install anything or get into our computers?

No. For the assessment and the report, your domain name is all we need.

How much does it cost?

It depends on what you need and how big your company is. The email check here on the site is always free. For everything else we tell you first, in writing, what we will do and what it costs: nothing starts without your go-ahead.

What happens after I get in touch?

We get back to you to understand what you need: your domain, how many people you are, whether a customer is asking for guarantees. Then you receive a written proposal with what we will do, how long it takes and the price. No obligation.

How long does the report take?

You receive it within 3 working days of the go-ahead.

Will you slow down our staff?

No. The assessment does not touch your systems. For the in-depth analysis we agree times and scope together.

See what can be seen of your company. Before anyone else does.

Tell us about your company: we’ll tell you what we can do and what it costs, in writing and with no obligation. The report arrives within 3 working days of the go-ahead.

Request an assessment

The form opens your email app with the request already written: the site stores nothing. We use your details only to reply to you.