Skip to content

FAQ

Frequently asked questions

Clear answers about CyberBit's website setup, secure redesign, takeover sprint, supporting Workspace/M365 baseline, public-signal checks, Website, Email & Domain Security Snapshots, External Security Watch, and safe engagement rules.

Starting point

Where should I start?

+

Use the Free Website, Email & Domain Check for an automated preview. Choose the Website, Email & Domain Security Snapshot when you need human verification and a prioritized report. Focused Security Cleanup fixes one defined email-trust or website-trust module; Business Security Remediation Sprint covers broader implementation. External Security Watch provides automated or human recurring external oversight after a baseline. Practice Security Baseline and the two evidence-support packages remain available for their specific triggers.

What is the difference between Snapshot, Focused Security Cleanup, Business Security Remediation Sprint, External Security Watch, and evidence support?

+

The $199 Snapshot manually verifies public website, email, and domain controls and provides a prioritized report without implementation. Focused Security Cleanup is one $750 Email Trust Setup or Website Trust Cleanup module. The From $1,500 Business Security Remediation Sprint covers broader work across modules, authenticated workspaces, accounts, providers, networks, backups, or ownership. External Security Watch separates a $99/month automated tier from human monthly validation starting at $499/month. Cyber Insurance Evidence Review is for an insurance application or renewal; Client/Vendor Security Questionnaire Support is for one non-insurance due-diligence questionnaire.

Does CyberBit implement fixes?

+

Yes, when implementation is explicitly scoped. Focused Security Cleanup covers one Email Trust Setup or Website Trust Cleanup module within its hard one-domain, one-environment scope. A Business Security Remediation Sprint covers broader work such as multiple modules, authenticated workspace controls, accounts, providers, migrations, backups, Wi-Fi, or network work. Implementation is not unlimited IT support and is confirmed before payment.

Does CyberBit guarantee security, compliance, insurance approval, or questionnaire approval?

+

No. CyberBit provides practical review, documentation, and fixed-scope hardening support. It does not guarantee security, breach prevention, compliance certification, cyber insurance approval, lower premiums, client approval, vendor approval, or account recovery.

What does CyberBit Solutions actually do?

+

CyberBit provides fixed-scope cybersecurity help for small professional-service firms and individuals. The focus is practical: public-signal scans, DNS/email/security-header review, plain-English reports, cyber insurance readiness, questionnaire support, workspace/access hygiene, and basic hardening.

Is this a full security audit?

+

No. CyberBit's entry offers are fixed-scope reviews and hardening services. They are not full compliance audits, SOC monitoring, MDR, or breach-response retainers. CyberBit's separately scoped Authorized Web Application Penetration Test performs active testing only after qualification, an executed agreement, verified scope, written authorization, and agreed Rules of Engagement.

View authorized Pentest details

Authorized web application penetration testing

When is a web application penetration test appropriate?

+

It is intended for one customer-controlled custom application, portal, SaaS product, e-commerce application, or meaningful authenticated workflow that needs active, authorized testing. A brochure site or ordinary managed WordPress site usually belongs on the Snapshot and Cleanup path.

View the Pentest scope

Does submitting the Pentest qualification form authorize testing?

+

No. The form starts a fit and scoping review only. It does not authorize, schedule, or begin testing, and no payment is collected from that form.

Review the qualification request

What authorization is required before testing?

+

CyberBit requires an executed agreement, verified scope, written authorization from an entity able to grant it, and agreed Rules of Engagement. Every asset must be customer-controlled or covered by separately verified owner permission.

What does the starting Pentest scope cover?

+

The starting scope covers one agreed custom application in one environment, unauthenticated testing, authenticated testing for up to two approved user roles, and the application's primary APIs. Exact assets, techniques, schedule, price, evidence handling, contacts, and stop procedures are confirmed before payment or testing.

Do you test production systems?

+

Staging or a production-like environment is preferred. Production testing is considered only when explicitly approved in the signed scope and Rules of Engagement, with agreed constraints, contacts, and stop procedures.

Should I send test credentials in the public form or email?

+

No. Do not submit passwords, MFA codes, API keys, tokens, recovery codes, private keys, or private credentials. If approved test accounts are needed after contracting, CyberBit arranges an agreed secure transfer method.

Does a Pentest report prove the application is secure?

+

No. It is a point-in-time assessment of the agreed scope. It cannot prove that every vulnerability was found, represent the company's complete security posture, provide certification, or guarantee a future outcome.

What does the focused retest include?

+

One focused retest may verify requested original findings within 30 calendar days of final report delivery. It excludes a new assessment, new functionality, new assets, expanded roles or APIs, and certification.

Who can remediate Pentest findings?

+

The client may use its internal team, existing developer or IT provider, another qualified provider, or separately scoped CyberBit help. Purchasing remediation from CyberBit is not required.

How is Pentest pricing confirmed?

+

The Authorized Web Application Penetration Test is From $4,500. Application size, workflows, roles, APIs, integrations, data sensitivity, environment constraints, reporting, and retest scope affect the final price. Exact scope and price are confirmed before payment.

How do I report a possible issue in CyberBit's public website?

+

Use the Security Disclosure Policy and security contact. Responsible disclosure is separate from the commercial Pentest process and does not authorize testing of customer, vendor, third-party, private, or unspecified systems.

Read the Security Disclosure Policy

Website, setup, and External Security Watch

Do you build websites?

+

Yes. CyberBit can help small businesses set up or rebuild practical websites with the security, domain, email, form, and handoff basics handled correctly.

View New Business Tech Setup

Do you redesign existing websites?

+

Yes. Secure Website Redesign is for outdated, confusing, or weak websites that need a cleaner structure and better public-facing security basics.

View Secure Website Redesign

Can you take over from another web vendor?

+

Yes, if the business owns or is authorized to manage the website, domain, email, and related accounts. CyberBit does not bypass authentication or access systems without authorization.

View Business Security Remediation Sprint

Do you set up Google Workspace or Microsoft 365?

+

Yes. CyberBit can help with baseline setup or review for business email, MFA, admin recovery, DNS/email authentication, and account ownership documentation.

View Workspace/M365 supporting path

Is this managed IT?

+

No. CyberBit External Security Watch is scoped website, domain, email, and public-facing security oversight. It is not full managed IT, 24/7 helpdesk, SOC, MDR, or unlimited support.

View External Security Watch

Do you provide 24/7 support?

+

No. Support is scoped by project or monthly plan. Emergency response and 24/7 coverage are not included unless separately contracted.

Do you need my passwords?

+

Do not send passwords through website forms. When access is required, CyberBit prefers delegated access, screen share, temporary vendor access, or a secure handoff process.

Can you guarantee my website will be secure?

+

No one can guarantee perfect security. CyberBit helps reduce obvious risk, improve configuration, document ownership, and create a stronger foundation.

Should I start with the $199 Snapshot or request a rebuild?

+

If you are unsure what is wrong, start with Snapshot. If you already know the site needs to be rebuilt or the setup is messy, request redesign or a Business Security Remediation Sprint.

What if I do not know who controls my domain or email?

+

That is a common takeover and cleanup issue. CyberBit can help map ownership and recommend safe next steps, but the client must be authorized to manage the assets.

Website, Email & Domain Security Snapshot

What is the Website, Email & Domain Security Snapshot?

+

A $199 plain-English PDF report that reviews public-facing domain, DNS, email-authentication, TLS, and website security-header signals. It summarizes visible gaps, ranks priority fixes, and gives a checklist your web vendor, IT provider, or internal team can act on.

What do I get in the Snapshot?

+

The Snapshot is built to be useful to both non-technical owners and the vendor or IT team doing the work.

  • Domain reviewed
  • Public posture summary
  • Top findings and severity
  • Why each issue matters
  • Priority fix order
  • Exact DNS/email/security-header checklist
  • Plain-English next steps
  • Book a qualifying implementation engagement of $750 or more within 30 days of report delivery, and CyberBit will apply the $199 Snapshot fee once toward that engagement.

Can I see an example before ordering?

+

Yes. The sample report shows the style, prioritization, and plain-English handoff format using anonymized or fictional details.

View Sample Report

How long does a Snapshot take?

+

Your first human-reviewed Cyber Risk Snapshot PDF draft will be delivered within 24 hours after both payment is confirmed and the required intake is complete. This is an elapsed calendar-hour commitment that includes weekends and holidays. The 24-hour clock starts at the later of successful payment confirmation and CyberBit validating that the required intake is complete. Required intake is complete only after all required answers, usable materials, authorization, and any requested clarification have been received. If payment is not confirmed or the required intake is incomplete, the 24-hour delivery clock has not started. Once started, the delivery clock continues without being paused or restarted. If CyberBit misses that 24-hour delivery window, you may request a full $199 refund.

Is the $199 credited toward other services?

+

Book a qualifying implementation engagement of $750 or more within 30 days of report delivery, and CyberBit will apply the $199 Snapshot fee once toward that engagement. The credit is non-cash, non-transferable, applied once, and cannot be stacked with another promotion, refund, or credit. It excludes subscriptions, recurring services, taxes, and third-party costs and is subject to confirmed scope and written acceptance.

Do you need passwords for a Snapshot?

+

No. The Snapshot is based on public signals and context you provide. Do not send passwords, private keys, backup codes, seed phrases, recovery codes, API keys, full payment card numbers, or private credentials.

Free Website, Email & Domain Check

What does the Free Website, Email & Domain Check scan?

+

It checks 11 defined public controls: HTTPS reachability, HTTP-to-HTTPS redirect, HSTS, directive-aware Content Security Policy, clickjacking protection, MIME sniffing protection, Referrer Policy, Permissions Policy, valid MX records, a bounded SPF hardfail policy, and an enforced DMARC policy. Optional context such as DNSSEC, cookies, security.txt, server/provider disclosure, CAA, and CORS remains outside the score; the paid Snapshot adds human verification, business context, and prioritized next steps.

Is the free scan safe?

+

Yes. The scan is public-signal only. It does not attempt logins, credential testing, exploit testing, port scanning, or account access.

What is the IP, DNS & WebRTC Connection Check?

+

It shows the request-visible public IP and limited browser connection signals, offers a user-initiated no-STUN WebRTC check, and can compare factual before-and-after network changes in the current tab. It does not scan your device, prove anonymity, classify a VPN as safe or unsafe, or perform a definitive DNS leak test because CyberBit does not operate controlled authoritative DNS observation infrastructure.

IP, DNS & WebRTC Connection Check

What is the Business Email Trust Check?

+

It passively reviews public MX, SPF, DMARC, TLS-RPT, DNSSEC, and optional known-selector DKIM signals. When a valid MTA-STS DNS marker is found, it also retrieves the domain's fixed canonical public policy file, validates its syntax and mode, and compares its MX patterns with current public MX records. Because DKIM selectors cannot be discovered universally, an unknown selector is labeled as needing provider or selector verification rather than failed.

Business Email Trust Check

What is the Vendor Access & Ownership Check?

+

It is a browser-only ownership checklist for domain, DNS, website, workspace, recovery, vendor, backup, and emergency-contact responsibility. Answers stay in the browser unless you explicitly choose to send them, and the result is a handoff checklist rather than a risk or compliance score.

Vendor Access & Ownership Check

Why doesn't the free scan show exact DNS records to paste?

+

Because exact DNS and email-authentication changes depend on your provider, approved senders, and hosting setup. Incorrect copy-paste records can break email or websites. The paid Snapshot provides the exact checklist after context is confirmed.

What if my score is low?

+

A low score means public controls are missing or could not be verified. It does not automatically mean you were hacked. It means there are visible items worth reviewing and prioritizing.

Focused Security Cleanup / Business Security Remediation Sprint

What is Focused Security Cleanup?

+

Focused Security Cleanup is a $750 fixed-scope cleanup for one business, one primary domain, and one website/email environment with known website, DNS, TLS, form, header, SPF, DKIM, DMARC, redirect, or public-configuration issues. Multi-system, multi-provider, migration, ownership-handoff, or broader hardening work routes to Business Security Remediation Sprint.

What is the Business Security Remediation Sprint?

+

A broader fixed-scope implementation service where CyberBit helps address priority fixes such as DNS setup, SPF/DKIM/DMARC, website security headers, Microsoft 365 or Google Workspace basics, MFA, backups, and access cleanup.

What is included in a Business Security Remediation Sprint?

+

The exact modules are confirmed before payment. Common modules include domain/email hardening, workspace access hardening, website/header hardening, WordPress hardening where applicable, MFA/admin access cleanup, and provider coordination.

  • Fixed-scope implementation or guided cleanup
  • Completed fix log
  • Before/after notes where applicable
  • Provider/admin handoff notes
  • Remaining recommendations for anything outside scope

What does "From $1,500" mean?

+

The final scope depends on the number of domains, platforms, users, and systems involved. CyberBit confirms scope before you pay. The public starting price remains From $1,500.

Do you make changes directly?

+

Depending on the platform and access model, CyberBit may guide the changes over screen share, work from a checklist, coordinate with your vendor, or use delegated access where available. Passwords should not be sent by email.

Is this penetration testing?

+

No. The Business Security Remediation Sprint is implementation and configuration cleanup. It is not exploit testing, unauthorized scanning, or a penetration test.

Client/Vendor Security Questionnaire Support

What is Client/Vendor Security Questionnaire Support?

+

Client/Vendor Security Questionnaire Support is from $1,500 for businesses that received a security questionnaire from a client, insurer, vendor-risk team, or partner and need credible responses fast. The named deliverable is a Client/Vendor Security Questionnaire Support Package.

What is included in Client/Vendor Security Questionnaire Support?

+

CyberBit reviews the questionnaire intake, groups questions by topic, drafts supportable answers, adds evidence notes for supported controls, adds gap notes for partial or missing controls, and includes one revision window for business-owner feedback.

  • Client/Vendor Security Questionnaire Support Package
  • Answer drafting based on the current setup
  • Evidence and gap notes
  • Safe wording for partial or planned controls
  • One revision window
  • Priority fixes that can be scoped separately

Do you fill out the questionnaire for us?

+

CyberBit helps organize accurate answers, identify gaps, and draft response language based on your current setup. The business owner or authorized representative should review and approve final answers.

Can you help if we do not have all controls in place?

+

Yes. CyberBit can distinguish between controls that are currently in place, partially in place, planned, or not applicable. The goal is credible answers, not false claims.

How fast is the first draft?

+

Typically 3-5 business days after receiving the questionnaire and required context.

Why is Client/Vendor Security Questionnaire Support listed as From $1,500?

+

Smaller questionnaires are scoped after intake. The standard minimum is $1,500, and large portal-heavy questionnaires may require a custom quote.

What will CyberBit not do for questionnaires?

+

CyberBit will not invent controls, provide legal attestation, provide compliance certification, guarantee approval by a client or vendor-risk team, or submit final answers without business approval.

Cyber Insurance Evidence Review

Is CyberBit an insurance broker?

+

No. CyberBit Solutions does not sell, place, underwrite, or broker insurance. The readiness review is a fixed-scope cybersecurity documentation and evidence-gap review.

What is included in Cyber Insurance Readiness?

+

The From $750 Cyber Insurance Evidence Review produces a Cyber Insurance Readiness Memo for common application or renewal topics such as MFA, backups, endpoint basics, admin access, incident response, domain/email evidence, and provider documentation.

  • Insurer or broker questionnaire review
  • Evidence checklist
  • Control gap notes
  • Vendor-ready next steps
  • Priority fix plan
  • No guarantee of approval, lower premiums, legal advice, insurance advice, compliance certification, or fake attestations

Can CyberBit guarantee cyber insurance approval?

+

No. Approval depends on the insurer, broker, underwriting process, and the business's actual controls. CyberBit can help you understand common control questions, evidence gaps, and priority fixes, but it cannot guarantee approval or lower premiums.

Can CyberBit help answer cyber insurance questionnaires?

+

CyberBit can help interpret questions, identify evidence, and draft supportable response language. Final answers should be reviewed and approved by the business owner, broker, legal advisor, or insurance professional where appropriate.

What happens if a required control is missing?

+

CyberBit will not fabricate controls or tell you to claim a control exists if it does not. The readiness review documents the gap and recommends a practical fix plan, which can be scoped into Focused Security Cleanup or a Business Security Remediation Sprint when implementation help is needed.

Is Cyber Insurance Readiness a compliance audit?

+

No. It is a fixed-scope readiness review and action plan, not a formal audit, certification, legal opinion, or insurance advice.

External Security Watch

What is included in External Security Watch?

+

External Security Watch has two tiers. Automated External Monitor provides agreed uptime, key-page, SSL/TLS-expiration, DNS-availability, and public-signal alerts with an automated summary. Human External Security Watch adds monthly human external-drift validation, a briefing, evidence history, one prioritized provider escalation note, and a quarterly owner/provider review.

What is the External Security Watch Brief?

+

The brief shows meaningful changes since the prior review, open review items, website/header/TLS observations, email/domain/SPF/DKIM/DMARC/MX/DNS observations, a priority rating, and one vendor-ready note.

Is External Security Watch a SOC/MDR service?

+

No. External Security Watch is not a 24/7 SOC, MDR, endpoint monitoring, SIEM/log monitoring, emergency incident response, penetration testing, breach investigation, or compliance certification service.

Does External Security Watch include implementation?

+

No. The automated tier has no human remediation. The human tier provides review, guidance, and one prioritized provider escalation note; implementation is scoped separately.

Do I need a Snapshot or Business Security Remediation Sprint first?

+

A Website, Email & Domain Security Snapshot, cleanup, rebuild, takeover, or agreed baseline is strongly recommended first. External Security Watch is most useful when there is a clear before-state to compare against each month.

How often are checks performed?

+

Automated checks run on the agreed monitor schedule. Human External Security Watch performs its documented external-drift validation monthly.

What happens if CyberBit finds a serious public-facing change?

+

For Human External Security Watch, CyberBit records the change in the monthly briefing and provides one prioritized provider escalation note. Automated External Monitor sends the agreed alert and status information without human remediation. Any implementation is scoped separately.

Practice Security Baseline

What is included in Practice Security Baseline?

+

The From $1,250 Practice Security Baseline is a focused path for Microsoft 365 or Google Workspace security, secure remote-access basics, or both. It can cover MFA, admin accounts, access, sharing, recovery, email authentication, and agreed remote-access basics.

  • Practice Security Baseline Report
  • MFA, admin, access, sharing, recovery, and email-auth review notes
  • Priority fix list
  • Provider/admin handoff notes
  • Remote-access checklist and MFA/device notes when included
  • Fit check for New Business Tech Setup, Focused Security Cleanup, or Business Security Remediation Sprint if hands-on cleanup is requested

Does the Workspace Baseline include endpoint monitoring or email content review?

+

No. The baseline is a focused configuration and access-hygiene review. It is not endpoint monitoring, SOC/MDR, email content review, legal/compliance audit, emergency incident response, complex VPN architecture, migration, multi-site networking, or large device deployment. Broader work requires Sprint or custom scope.

Personal Cybersecurity

Is Personal Cyber Lockdown the same as personal cyber insurance?

+

No. CyberBit does not sell, broker, underwrite, or recommend insurance policies. Personal Cyber Lockdown is a cybersecurity setup and guidance service that helps reduce common personal digital risks.

Do I have to send you my passwords?

+

No. Do not send passwords, private keys, backup codes, seed phrases, recovery codes, SSNs, bank details, full payment card numbers, or private credentials. You stay in control of your accounts during the guided session.

What is included in Personal Cybersecurity?

+

The exact checklist depends on the selected path, but Personal Cybersecurity can include password manager setup, MFA, account recovery cleanup, credit freeze or fraud alert guidance, family safety setup, and suspicious-login triage.

What if I think my account was hacked?

+

Choose Account Compromise Triage. CyberBit prioritizes securing your primary email, identity accounts, login sessions, MFA, recovery settings, and high-risk accounts first. CyberBit does not guarantee account recovery or provide law-enforcement, private investigation, forensic, legal, financial, insurance, or credit-repair services.

What is the difference between Personal Cyber Lockdown and Password Manager + MFA Setup?

+

Password Manager + MFA Setup is narrow and focused on login security. Personal Cyber Lockdown is broader and includes account recovery settings, device basics, privacy exposure, and a wider personal risk checklist.

What is the difference between Personal Cyber Lockdown and Family Cyber Safety Setup?

+

Personal Cyber Lockdown is for one person. Family Cyber Safety Setup adds household context, shared devices, parent/child accounts, location-sharing, and family recovery planning.

Can you guarantee I will not be hacked?

+

No. No legitimate cybersecurity service can guarantee that. CyberBit reduces common risks and gives you practical next steps.

Safety, access, and privacy

Should I send passwords?

+

No. Never send passwords, private keys, backup codes, seed phrases, recovery codes, API keys, full payment card numbers, or sensitive credentials through the site or by email.

How do you handle access if changes are needed?

+

Preferred options include screen share while you log in, delegated access where the platform supports it, or a checklist your IT/web provider implements.

Do you work on accounts you do not own?

+

No. CyberBit only works on accounts, domains, and systems you own or are authorized to manage.

Is CyberBit affiliated with NIST or any government agency?

+

No. CyberBit Solutions is not affiliated with, endorsed by, or certified by NIST or any government agency. CyberBit may reference public guidance from NIST, CISA, and platform providers when creating plain-English recommendations.

What is not included?

+

Unless a separate written scope says otherwise, CyberBit does not provide penetration testing, exploit testing, credential testing, social engineering, unauthorized scanning, emergency incident response, breach investigation, 24/7 monitoring, SOC/MDR, endpoint monitoring, unlimited implementation, legal advice, insurance advice, financial advice, compliance certification, insurance approval guarantees, or questionnaire approval guarantees.

Do you store scan data?

+

Free scan results are generated from public signals and returned in your browser. CyberBit may also store the submitted domain and scan summary internally to review scan activity and identify follow-up opportunities. The scan does not require account login or private credentials. Do not submit private credentials or sensitive data.

Pricing and delivery

Why fixed-fee instead of hourly?

+

Small businesses need clear scope, clear price, and clear deliverables. Fixed-fee services avoid open-ended discovery and make it easier to decide.

Can you customize a service?

+

Yes, but CyberBit confirms scope before payment when work falls outside a listed fixed-scope offer.

Do you work remotely?

+

Yes. CyberBit is New York-based and supports small businesses remotely across the United States, with international work where appropriate.

What happens after I pay?

+

You will receive or complete the relevant intake path first. After checkout, Stripe sends a receipt to the email used during payment. CyberBit follows up using that email with the next step, report, or scope confirmation depending on the service.

Still deciding?

Still not sure where to start?

Run the Free Website, Email & Domain Check if you are unsure. Start the Website, Email & Domain Security Snapshot if you need a vendor-ready action plan before cleanup, redesign, supporting workspace setup, External Security Watch, or questionnaire support.