When a threat actor targets a business, they rarely start by trying to crack the main firewall. They walk the perimeter looking for an unlocked window: an unpatched server, a misconfigured cloud app, or a password already leaked online.
That is exactly what a 30-minute cyber risk diagnostic is designed to find — and help you fix — before anyone else does. In the short video below, James Thompson of Atlas Cloud explains how it works.
What is a cyber risk diagnostic?
A cyber risk diagnostic is a rapid, non-invasive assessment of your organisation’s external attack surface. We look at your business from the outside — the same perspective an attacker gets when scouting a target — and identify the weaknesses automated scans would find first.
Nothing to install, no access to grant, no downtime. Everything is assessed externally, exactly as a criminal would see it.
The two areas we check
External vulnerabilities
Unpatched external systems, misconfigured cloud applications and forgotten entry points left open to the public internet. The uncomfortable truth: if we can spot them in minutes, automated hacker scans already have.
Credentials exposed on the dark web
We check whether your team’s corporate email addresses and passwords have surfaced in third-party breaches. Leaked credentials let attackers walk in without ever “hacking” anything.
Why a quick check matters
Effective security is not about being bulletproof. It is about eliminating the easy wins.
Most attacks are opportunistic rather than targeted. Criminals scan thousands of businesses at once and pursue the ones with obvious gaps. Mapping your external footprint lets you close those gaps first — and quietly removes your business from the easy-target list.
Turning a 30-minute check into lasting protection
A diagnostic tells you where you stand today. Staying secure means putting the right layers in place. These are the four services UK businesses most often move on to after their results.
Cyber Security MOT →
A full security audit that goes far deeper than the external view — assessing your internal systems, policies and controls against where real risk sits.
Managed Detection & Response →
MDR watches for threats that slip past preventative tools and responds to them around the clock, so an intrusion is contained in minutes rather than discovered weeks later.
Security Operations Centre →
Our UK-based SOC gives you a team of analysts monitoring your environment 24/7 — the capability most mid-sized businesses could never staff in-house.
Cyber Essentials & CE Plus →
Government-backed certification that proves your baseline controls to clients and insurers. Worth reading our guide to the April 2026 Cyber Essentials changes before you certify.
Frequently asked questions
How long does a cyber risk diagnostic take?
Around 30 minutes. Because everything is assessed from the outside, we do not need access to your systems and there is nothing for your team to prepare.
Will it disrupt our systems or our people?
No. The diagnostic is completely non-invasive. We only look at what is already visible to the public internet, so there is no impact on day-to-day operations.
What do we need to provide?
Very little — typically just your organisation’s name and primary web domain. We take care of the rest.
How is this different from a penetration test?
A diagnostic is a fast external snapshot. Penetration testing is a deeper, authorised attempt to exploit weaknesses across your estate. The diagnostic is usually the sensible first step.
What happens after the diagnostic?
We talk you through the findings in plain English, prioritised by risk, and advise on the fastest route to closing any gaps — whether that is with your existing IT team or our cyber security services.
See what an attacker sees
Your external footprint is being scanned whether you check it or not. The only question is whether you see the gaps before someone else does.
Book your 30-minute diagnostic Book a 15-minute call