Skip to main content

How the PsySec Program Audit works

The free audit, built on PsySec (psychological security, Hook Security's approach of treating People as partners), reads what is already public about your company, asks 10 questions about your security awareness Program, and scores the Program. Never the People in it. This page lists exactly what the scan does, what it never does, and which frameworks the compliance table is scored against.

What the scan does

The scan is passive. It only reads sources that anyone on the internet can read, the same sources an attacker reads before writing a first email.

  • Reads up to 15 public pages of your website (home, about, team, contact, careers, security, privacy and similar), honouring robots.txt.
  • Looks up public DNS records for your domain: MX (which says where your email is delivered), SPF and DMARC (which say who may send email as you), and MTA-STS and BIMI if you publish them. DKIM is not looked up: finding a DKIM key needs a selector name we would have to guess.
  • Checks whether common lookalike domains (a missing letter, a different ending, a “secure-” prefix) are live, and which of those have a mail record, which means they can already accept email. Nothing else is looked up on them.
  • Reads public certificate transparency logs (the open record of HTTPS certificates issued for your domain) to find login portals under your domain.
  • Checks for a public security.txt file (a standard contact file security researchers look for) and a place to report someone impersonating you.
  • Records roles and job functions your site advertises. Roles only, never a person’s name.
  • Infers the shape of your email addresses (first.last@, flast@ and the like) from addresses already published on your site, and notes the tools your pages name by brand. The shape only: the addresses are read, counted and dropped.
  • Reads your pages for a rough industry, a size band and the regions they mention, so the advice fits a company your size.
  • Reads the name your organization gives itself — the registered entity in your site’s own schema.org data, its og:site_name, or its copyright line — so the report is addressed to your organization rather than to a bare domain.
  • Asks Have I Been Pwned, a public breach-record service, whether it has catalogued a breach at your domain. This is a lookup about your organization, never about a Person: we do not ask it about any individual address, and the audit never scores People on it. What it changes is the pretext an attacker can use, so it changes what is worth practising.

What the scan never does

  • Never logs in to anything, submits a form, or follows a link that needs a password.
  • Never scans ports, probes services, or touches your mail server beyond a public DNS lookup.
  • Never sends email to your domain or to your People.
  • Never asks a breach service about an individual email address. The breach lookup is by domain only, and the paid per-person endpoints are not used.
  • Never names a Person. The results describe the Program, not the People in it.
  • Never ranks employees or produces an individual score of any kind.

What we keep

  • Scan results are cached for 24 hours so a repeat run of the same domain is fast, then discarded. Nothing else about the scan is stored.
  • Your answers stay in your browser until you ask for the PDF. Clearing site data removes them.
  • We ask for an email address so we can email you the report. It arrives as a PDF attached to one email from Zach (zach@audit.hooksecurity.co, with replies going to zach@hooksecurity.co), and the same PDF downloads in your browser at the same time. The message itself says nothing about your answers, your score or what the scan found — all of that is in the attachment.
  • With that address we keep your name, company, role, industry, a rough size band, whether you told us you are an MSP auditing a client, and your overall level, in our CRM under our privacy policy. Never your answers, and never the scan findings. The submission also carries the network address you sent it from, and our CRM cookie if your browser has one.
  • The box you have to tick to get the report also lets Hook send occasional PsySec content. Unsubscribe any time. Someone from Hook reaches out about your Program only if you tick the second, optional box.
  • Each network address may start five scans per hour, and we email any one address at most three reports a day.

Frameworks the compliance table is scored against

Every requirement was last verified against its primary source on September 25, 2026. Frameworks require training. None of them explicitly require Simulations; Simulations reinforce the training and give you the effectiveness evidence auditors ask for.

FrameworkClauseLast verified
HIPAA Security Rule45 CFR 164.308(a)(5)September 25, 2026
HIPAA proposed rule (watch)proposed 164.308(a)(11)September 25, 2026
PCI DSS v4.0.112.6.1 to 12.6.3.2, 5.4.1September 25, 2026
SOC 2CC1.4, CC2.2September 25, 2026
ISO/IEC 27001:20227.2, 7.3, A.6.3September 25, 2026
NIST CSF 2.0PR.AT-01, PR.AT-02September 25, 2026
NIST SP 800-50r1Whole documentSeptember 25, 2026
CMMC 2.0 Level 2AT.L2-3.2.1, 3.2.2, 3.2.3September 25, 2026
FTC Safeguards Rule16 CFR 314.4(e)September 25, 2026
NYDFS Part 50023 NYCRR 500.14(a)(3)September 25, 2026
CJIS Security Policy v6.15.2 AT-2, AT-2(2), AT-2(3), AT-3, AT-4September 25, 2026
FERPA34 CFR Part 99September 25, 2026
GDPRArt. 5(1)(f), 32, 39(1)(b)September 25, 2026
NIS2Art. 20(2), 21(2)(g); IR 2024/2690 section 8September 25, 2026
DORAArt. 5(4), 13(6)September 25, 2026
UK Cyber Essentials v3.3NoneSeptember 25, 2026
AU Essential EightNone in E8; ISM-0252, ISM-2071, ISM-1565September 25, 2026
Cyber insuranceMarsh 12 Controls #8; Beazley, Chubb, Travelers applicationsSeptember 25, 2026

Not legal advice

The compliance table cites each requirement and shows the date we last verified it. It is a reading aid, not a legal opinion, and it does not replace your auditor, assessor, insurer or counsel. Frameworks change; check the cited source before you rely on a row.

Run it

Start the free PsySec Program Audit. About five minutes, no login, no install.