Tools

Free security tools worth knowing about, organised around the problem you are trying to solve.

Security guidance often starts in the middle. It assumes you already know what applies to your company, what to check and where the gaps are. If you are not there yet, start with the section closest to the question in front of you.

Useful security tools

These are free tools and resources from government agencies, standards bodies and open-source projects. We chose the ones listed here and checked the details against each publisher's own site on the date shown.

We have not independently tested every tool, and Digital Consulting, Inc. has no relationship with the publishers.

Where to start

  • CISA's no-cost cybersecurity services and tools catalog

    Good starting point for
    Almost any organisation

    CISA maintains a searchable catalog of free security tools and services from government, open-source projects and private companies. If you know the problem you are trying to solve but not the tool you need, this is a useful place to start.

    Access
    Nothing to sign up for
    Cost
    Free, in CISA's own words
    Checked

When a customer asks about your security

  • CSA CAIQ-Lite

    Useful for
    Vendors selling to enterprise customers

    A shorter version of the Cloud Security Alliance questionnaire used in vendor security reviews. Completing it ahead of time can save work when customers start sending their own questionnaires.

    Access
    Account required to download
    Cost
    Not stated by the maintainer
    Checked
  • CSA STAR Registry

    Useful for
    Checking a cloud vendor before starting a security review

    A public registry of cloud providers that have published security self-assessments or independent attestations. Worth checking before asking a vendor for material they may already have made public.

    Access
    No account stated; entries are available on the site
    Cost
    Not stated by the maintainer
    Checked

Assessments that produce a report

  • CISA CSET, the Cyber Security Evaluation Tool

    Useful for
    IT or security teams that need a documented assessment

    A desktop assessment tool that lets you work against a framework and produce a report. It also includes assessments for ransomware readiness and CISA's Cybersecurity Performance Goals.

    Access
    Download and run it on your own machine
    Cost
    Free and open source; MIT and Apache 2.0
    Checked
  • HHS and ASTP Security Risk Assessment Tool

    Useful for
    Organisations that handle protected health information

    A guided security risk assessment built around the HIPAA Security Rule's risk analysis requirement. It runs locally and produces a report. The release listed when we checked was version 3.7, September 2026.

    Access
    Download; available as a Windows desktop application or Excel workbook
    Cost
    Free
    Checked
  • OWASP SAMM assessment toolbox

    Useful for
    Software teams that want a baseline of their security practices

    A self-assessment workbook for OWASP SAMM. Your team works through the questions and scores the maturity of its software security practices across the SAMM business functions.

    Access
    Download the toolbox; no account required
    Cost
    Free; CC BY-SA 4.0, with commercial use permitted under the licence terms
    Checked

Quick checks

  • MDN HTTP Observatory

    Useful for
    Website owners

    Checks the HTTP security headers returned by a site, gives the site a grade, and explains what to change for each finding.

    Access
    No account required; one scan per minute per domain
    Cost
    Free
    Checked
  • internet.nl

    Useful for
    Anyone responsible for a company's domain, website or email

    Checks a domain's web and mail configuration against modern internet standards, including IPv6, DNSSEC, HTTPS, DMARC, STARTTLS and DANE. Run by the Dutch Internet Standards Platform and not by a commercial security vendor.

    Access
    No account required; enter a domain and run the tests
    Cost
    Not stated by the maintainer
    Checked
  • Have I Been Pwned domain search

    Useful for
    Companies that want to see whether addresses on their domain appear in known breaches

    After you prove control of the domain, Have I Been Pwned shows which email addresses on it appear in known breach data.

    Access
    Sign in and verify control of the domain
    Cost
    Free below ten breached addresses; subscription required above that
    Checked

If you build software

  • OWASP Threat Dragon

    Useful for
    Teams getting started with threat modelling

    A visual threat-modelling tool for drawing the system, its components and data flows, then recording what could go wrong. It supports STRIDE, CIA, LINDDUN, DIE and PLOT4ai.

    Access
    Use it in a browser or install the desktop version; no account required
    Cost
    Free and open source; Apache License 2.0
    Checked
  • OpenSSF Scorecard

    Useful for
    Repository maintainers

    Runs automated checks against a repository's security practices and gives each check a score out of ten. Useful for spotting basic supply-chain and repository hygiene issues that are easy to miss.

    Access
    The command-line tool and GitHub Action use a GitHub personal access token
    Cost
    Not stated by the maintainer
    Checked
  • OpenSSF Best Practices Badge

    Useful for
    Open-source projects

    A self-certification against published open-source development and security criteria. Projects that meet the requirements can display the resulting badge in their repository.

    Access
    Account required
    Cost
    Free
    Checked

Practising for an incident

  • CISA Tabletop Exercise Packages

    Useful for
    Organisations that have not run a security tabletop exercise before

    Ready-made exercise material from CISA, including a scenario, discussion questions, slides, invitations and an after-action report template. Enough structure to run a basic exercise without building one from scratch.

    Access
    Available by request from CISA rather than as a direct download
    Cost
    Not stated by the maintainer
    Checked

Already included in what you pay for

  • Microsoft Secure Score

    Useful for
    Microsoft 365 administrators

    Shows how your Microsoft 365 environment is configured and recommends changes that can improve its security posture. Recommendations can cover Entra ID, Exchange Online, SharePoint, Teams, Defender and other products in your licence.

    Access
    Microsoft Defender portal; Security Reader can view the score, while Security Administrator is required for changes
    Cost
    No separate price; recommendations depend on the products you are licensed for
    Checked
  • Google Workspace security health page

    Useful for
    Google Workspace administrators on supported editions

    Brings the main Workspace security settings into one view, showing their current state and Google's recommendation. It covers areas including Gmail, Drive, devices, Groups, Marketplace apps, Calendar and Sites.

    Access
    Admin console with the Security center administrator privilege. Available on Frontline, Enterprise and Education editions, plus Enterprise Essentials Plus; Business editions do not include it
    Cost
    No separate price on editions that include the feature
    Checked
  • AWS Trusted Advisor

    Useful for
    AWS account holders

    Checks an AWS account against security, cost, performance and resilience rules. Security checks include issues such as open security groups, public snapshots, and a root account without MFA.

    Access
    AWS console; no separate enrolment required
    Cost
    56 checks are available on every AWS account plan; Business Support+ adds the remaining checks and API access
    Checked
  • GitHub Dependabot alerts

    Useful for
    Anyone maintaining code in GitHub

    Alerts you when a dependency used by the repository has a known vulnerability. Where a fix is available, it identifies the fixed version and can open a pull request to perform the upgrade.

    Access
    Enabled in repository settings by a repository administrator or organisation owner
    Cost
    Free on all plans for public and private repositories
    Checked