
Misconfiguration tools compare your systems and cloud services against hardened baselines such as the CIS Benchmarks and flag insecure defaults. The free options in this category help small businesses fix the settings behind a large share of avoidable breaches.
Security Checkup is a tool inside Google Account Manager. Security Checkup automatically reviews users' security settings and configuration. If there's anything concerning, Google will recommend changes and features to turn on. This will increase the security of your account.
Facebook's Security Checkup tool automatically reviews users' current security settings. It reviews a user's current configuration and recommends changes to increase the security of your account.
Security misconfiguration tools find the settings that are wrong rather than the software that is vulnerable: default credentials left in place, directory listing enabled, verbose error pages, unnecessary services running, cloud storage open to the world, security headers missing, and TLS configured with obsolete protocols. Misconfiguration is a standing entry in the OWASP Top 10 for good reason.
These issues are cheap to find and cheap to fix, which makes them the fastest security improvement available to a small team. The free tools on this page cover web server and TLS configuration checkers, cloud configuration scanners, hardening benchmark auditors for operating systems, and header analysers that show in seconds what an attacker sees.
Need help with Security Mis-Configuration?
IRM audits cloud and application configuration against CIS Benchmarks and framework controls.
Cloud Security ControlsCheck your readiness first
Free, no signup, runs in your browser. Score your gaps and download a remediation roadmap.
Free CIS Controls Gap AssessmentDefault or shared admin credentials, cloud storage or databases exposed to the internet, missing MFA on admin consoles, outdated TLS versions, missing security headers, verbose error messages, and unused services left running. All are detectable with the free tools on this page.
HTTP response headers such as Content-Security-Policy, Strict-Transport-Security, X-Frame-Options, and Permissions-Policy that tell the browser how to protect the page. They are set in the web server or CDN configuration and are one of the quickest fixes on any web application security report.
Vulnerability scanners look for known flaws in software versions. Misconfiguration scanners check settings against a secure baseline. A fully patched server with an open admin port and a default password passes the first and fails the second.
Our diverse industry experience and expertise in AI, Cybersecurity & Information Risk Management, Data Governance, Privacy and Data Protection Regulatory Compliance is endorsed by leading educational and industry certifications for the quality, value and cost-effective products and services we deliver to our clients.

