Taking new engagements — Q4 hello@datadefenz.com
ServicesAll servicesGRC & Compliance7Security Culture1Risk Management3Technical Security5Leadership Advisory1Fast-Turnaround1
ProductsResourcesPracticeAboutBook a 30-minute callContact

Tool

Check your own headers, right now

A small, genuinely real check against a domain you own. It looks at seven response headers and tells you which are missing. That is all it does — and it is the honest end of a spectrum whose other end is a scoped penetration test.

Tool · Security header checkRead-only · rate limited

Enter a domain you are responsible for. We make one request to its front page and report what its response headers say. It is a small check, but it is a real one — run against your own site, right now.

A read-only check of publicly served HTTP response headers. It is not a penetration test, a vulnerability scan, or a substitute for a VAPT engagement.

Walkthrough

What we are actually testing for

Security is abstract until you see the sequence. Two of them: how an intrusion unfolds, and how a response runs against the regulatory clock.

Walkthrough · Intrusion and responseClick a stage

Security operations

How mature is your SOC, actually?

We assess against the SOC-CMM — five domains, with maturity and capability scored separately. Owning a SIEM is not a capability; tuned, coverage-mapped, measured detection is. Explore what each domain covers.

0Non-existentNot performed at all.
1InitialHappens, but ad hoc and dependent on individuals.
2RepeatableRepeated with some consistency, largely undocumented.
3DefinedDocumented, standardised and actually followed.
4ManagedMeasured and controlled against defined metrics.
5OptimisingContinuously improved on the basis of those measurements.

Domain and element names follow the published SOC-CMM, an open model developed by Rob van Os from academic research. Maturity and capability are scored separately. DATADEFENZ is not affiliated with the model's author.