CBWATCH
← CBWatch

About CBWatch

A straightforward answer to "how secure is our website, really?" — without hiring a security firm to find out.

Why CBWatch exists

Most small and mid-sized businesses have no realistic way to answer a basic question: is our website and email setup actually secure? A proper penetration test costs thousands of pounds and is usually aimed at companies far larger than theirs. Meanwhile the things that actually cause the most common incidents — a missing SPF/DMARC record that lets someone spoof your domain in a phishing email, an expired TLS certificate, an exposed admin port, a WordPress install three versions behind — are all things a scanner can check from the outside in seconds, for free.

CBWatch started from that gap. It runs the checks a competent security-minded developer would run by hand — email authentication, TLS/SSL, HTTP security headers, breach exposure, open ports, and software currency — and turns the result into a single 0–100 score and a plain-English list of what to fix and why, not a wall of jargon.

What we believe

Passive by design

Every check reads publicly available information — DNS records, TLS certificates, HTTP headers. Nothing logs in, guesses passwords, or probes for vulnerabilities. See the methodology for the full detail.

Plain English, not jargon

A finding isn't useful if you need a security background to understand it. Every result explains what's wrong and what to actually do about it.

Honest about limits

An automated external scan is not a penetration test or a compliance audit, and we say so directly rather than overselling what it covers.

Who it's for

Small business owners who want a baseline without commissioning a full audit; developers and IT contractors who want a quick, shareable report to hand a client; and anyone who wants ongoing monitoring rather than a one-off snapshot — the paid tier tracks a domain over time, alerts on regressions, and adds depth (Cyber Essentials readiness, AI-agent exposure, deep SSL/subdomain scans) that a single free scan deliberately leaves out.

Who's behind it

Hi, I'm Connor — a recent law graduate who also works in cyber. Spending time around both kept pointing me at the same gap: small businesses have no easy, affordable way to find out where they actually stand on security. A proper audit is priced for companies far bigger than most of them, so a lot of them just go without any answer at all. CBWatch is my attempt to close that gap — no team, no sales department, just me building the tool I thought should already exist.

If something looks wrong, or you think a check is missing something important, I'm the one reading the contact page — not a queue.