Tools
Free security tools worth knowing about, organised around the problem you are trying to solve.
Security guidance often starts in the middle. It assumes you already know what applies to your company, what to check and where the gaps are. If you are not there yet, start with the section closest to the question in front of you.
Useful security tools
These are free tools and resources from government agencies, standards bodies and open-source projects. We chose the ones listed here and checked the details against each publisher's own site on the date shown.
We have not independently tested every tool, and Digital Consulting, Inc. has no relationship with the publishers.
Where to start
-
CISA's no-cost cybersecurity services and tools catalog
- Good starting point for
- Almost any organisation
CISA maintains a searchable catalog of free security tools and services from government, open-source projects and private companies. If you know the problem you are trying to solve but not the tool you need, this is a useful place to start.
- Access
- Nothing to sign up for
- Cost
- Free, in CISA's own words
- Checked
When a customer asks about your security
-
CSA CAIQ-Lite
- Useful for
- Vendors selling to enterprise customers
A shorter version of the Cloud Security Alliance questionnaire used in vendor security reviews. Completing it ahead of time can save work when customers start sending their own questionnaires.
- Access
- Account required to download
- Cost
- Not stated by the maintainer
- Checked
-
CSA STAR Registry
- Useful for
- Checking a cloud vendor before starting a security review
A public registry of cloud providers that have published security self-assessments or independent attestations. Worth checking before asking a vendor for material they may already have made public.
- Access
- No account stated; entries are available on the site
- Cost
- Not stated by the maintainer
- Checked
Assessments that produce a report
-
CISA CSET, the Cyber Security Evaluation Tool
- Useful for
- IT or security teams that need a documented assessment
A desktop assessment tool that lets you work against a framework and produce a report. It also includes assessments for ransomware readiness and CISA's Cybersecurity Performance Goals.
- Access
- Download and run it on your own machine
- Cost
- Free and open source; MIT and Apache 2.0
- Checked
-
HHS and ASTP Security Risk Assessment Tool
- Useful for
- Organisations that handle protected health information
A guided security risk assessment built around the HIPAA Security Rule's risk analysis requirement. It runs locally and produces a report. The release listed when we checked was version 3.7, September 2026.
- Access
- Download; available as a Windows desktop application or Excel workbook
- Cost
- Free
- Checked
-
OWASP SAMM assessment toolbox
- Useful for
- Software teams that want a baseline of their security practices
A self-assessment workbook for OWASP SAMM. Your team works through the questions and scores the maturity of its software security practices across the SAMM business functions.
- Access
- Download the toolbox; no account required
- Cost
- Free; CC BY-SA 4.0, with commercial use permitted under the licence terms
- Checked
Quick checks
-
MDN HTTP Observatory
- Useful for
- Website owners
Checks the HTTP security headers returned by a site, gives the site a grade, and explains what to change for each finding.
- Access
- No account required; one scan per minute per domain
- Cost
- Free
- Checked
-
internet.nl
- Useful for
- Anyone responsible for a company's domain, website or email
Checks a domain's web and mail configuration against modern internet standards, including IPv6, DNSSEC, HTTPS, DMARC, STARTTLS and DANE. Run by the Dutch Internet Standards Platform and not by a commercial security vendor.
- Access
- No account required; enter a domain and run the tests
- Cost
- Not stated by the maintainer
- Checked
-
Have I Been Pwned domain search
- Useful for
- Companies that want to see whether addresses on their domain appear in known breaches
After you prove control of the domain, Have I Been Pwned shows which email addresses on it appear in known breach data.
- Access
- Sign in and verify control of the domain
- Cost
- Free below ten breached addresses; subscription required above that
- Checked
If you build software
-
OWASP Threat Dragon
- Useful for
- Teams getting started with threat modelling
A visual threat-modelling tool for drawing the system, its components and data flows, then recording what could go wrong. It supports STRIDE, CIA, LINDDUN, DIE and PLOT4ai.
- Access
- Use it in a browser or install the desktop version; no account required
- Cost
- Free and open source; Apache License 2.0
- Checked
-
OpenSSF Scorecard
- Useful for
- Repository maintainers
Runs automated checks against a repository's security practices and gives each check a score out of ten. Useful for spotting basic supply-chain and repository hygiene issues that are easy to miss.
- Access
- The command-line tool and GitHub Action use a GitHub personal access token
- Cost
- Not stated by the maintainer
- Checked
-
OpenSSF Best Practices Badge
- Useful for
- Open-source projects
A self-certification against published open-source development and security criteria. Projects that meet the requirements can display the resulting badge in their repository.
- Access
- Account required
- Cost
- Free
- Checked
Practising for an incident
-
CISA Tabletop Exercise Packages
- Useful for
- Organisations that have not run a security tabletop exercise before
Ready-made exercise material from CISA, including a scenario, discussion questions, slides, invitations and an after-action report template. Enough structure to run a basic exercise without building one from scratch.
- Access
- Available by request from CISA rather than as a direct download
- Cost
- Not stated by the maintainer
- Checked
Already included in what you pay for
-
Microsoft Secure Score
- Useful for
- Microsoft 365 administrators
Shows how your Microsoft 365 environment is configured and recommends changes that can improve its security posture. Recommendations can cover Entra ID, Exchange Online, SharePoint, Teams, Defender and other products in your licence.
- Access
- Microsoft Defender portal; Security Reader can view the score, while Security Administrator is required for changes
- Cost
- No separate price; recommendations depend on the products you are licensed for
- Checked
-
Google Workspace security health page
- Useful for
- Google Workspace administrators on supported editions
Brings the main Workspace security settings into one view, showing their current state and Google's recommendation. It covers areas including Gmail, Drive, devices, Groups, Marketplace apps, Calendar and Sites.
- Access
- Admin console with the Security center administrator privilege. Available on Frontline, Enterprise and Education editions, plus Enterprise Essentials Plus; Business editions do not include it
- Cost
- No separate price on editions that include the feature
- Checked
-
AWS Trusted Advisor
- Useful for
- AWS account holders
Checks an AWS account against security, cost, performance and resilience rules. Security checks include issues such as open security groups, public snapshots, and a root account without MFA.
- Access
- AWS console; no separate enrolment required
- Cost
- 56 checks are available on every AWS account plan; Business Support+ adds the remaining checks and API access
- Checked
-
GitHub Dependabot alerts
- Useful for
- Anyone maintaining code in GitHub
Alerts you when a dependency used by the repository has a known vulnerability. Where a fix is available, it identifies the fixed version and can open a pull request to perform the upgrade.
- Access
- Enabled in repository settings by a repository administrator or organisation owner
- Cost
- Free on all plans for public and private repositories
- Checked