What RiskLens Pro checks

Every finding is tied to the exact line in your configuration, with why it matters and how to fix it.

35 security checks across seven areas

Administrative access

Multi-factor authentication, default and shared accounts, password and lockout policy, session timeouts.

Management plane

Telnet and HTTP administration, unrestricted management access, SNMP versions, time synchronisation, login banners.

Firewall policy

Overly permissive "any" rules, risky services exposed to the internet, overly broad networks, shadowed, redundant and undocumented rules.

Internet exposure through NAT

Services such as remote desktop or file sharing published to the internet through port forwarding.

Threat prevention

Allowed traffic that is not inspected for intrusions or malware.

Logging and monitoring

Missing traffic logging, no central log server, unprotected log transport.

Encryption and VPN

Weak algorithms (DES, 3DES, MD5, SHA-1), weak key exchange, IKEv1 and aggressive mode.

Every finding shows which rule or setting is affected, where it is in your configuration, why it matters and how to fix it, with vendor-specific commands where available.

Results you can rely on

Many tools count a missing setting as a pass. RiskLens Pro doesn't. When your export doesn't contain what's needed to decide a check, it says so and tells you what evidence to look at instead.

Security score

Based on the severity, exposure and breadth of the real weaknesses found.

Compliance score

Calculated only from checks that could actually be concluded.

Coverage and confidence

How much of the picture the result is based on, so a score is never read out of context.

Supported firewalls

Supported firewall vendors and the configuration export each needs
VendorWhat to export
Palo Alto Networks (PAN-OS, Panorama)Configuration XML, or CLI output
Fortinet FortiGate (FortiOS, including VDOMs)Full configuration backup, unencrypted
Cisco ASARunning configuration
Juniper SRX (Junos)show configuration output
Check PointManagement API JSON export
Sophos FirewallConfiguration XML (Entities.xml)

Mapped to the frameworks you report against

  • NIST Cybersecurity Framework 2.0
  • NIST SP 800-53 Rev. 5
  • ISO/IEC 27001:2022
  • PCI DSS 4.0.1
  • CIS Critical Security Controls 8.1
  • CISA Zero Trust Maturity Model 2.0
  • Vendor CIS Benchmarks

Framework results cover only the controls a firewall configuration can evidence. They support your compliance work but are not a certification or a compliance opinion.

Reports for every audience

  • HTML: executive, auditor and engineer views in one document
  • PDF: for formal distribution
  • Excel: findings, evidence, control matrix and remediation plan
  • JSON and SARIF: for integration with other tools

Try it on your own configuration

The free trial assesses your configuration and shows every finding.