We ran an external security check on 21 clinics in Bangalore using nothing but public records and a single visit to each homepage. Here is what we found.
The check is free, takes about a minute, and needs nothing but your web address. No signup.
Email impersonation is the expensive one. If a domain has no DMARC record, anyone can send email that appears to come from that business. The standard attack is a fake invoice sent to a customer with the criminal's bank details on it — the customer has no way to tell, and the money is rarely recovered.
Most of what we find takes an afternoon to fix and costs nothing. The problem is not difficulty, it is that nobody is looking.
Method: each business was assessed from public DNS and domain registration records, a standard HTTPS connection, and one ordinary request for the homepage — the same thing any visitor's browser does. No ports were scanned and no logins were attempted. We publish aggregate figures only and never name an individual business. Groups smaller than 8 are not published at all. Full scanning policy.