Free tools
Answers to the security questions boards and regulators ask
Five free tools for financial institutions in Thailand. See where you stand, what your regulator requires you to test, how serious a finding is, and what an incident could cost.
- Free to use
- Results on screen
- No sign-up to see results
Start with your question
Know where we stand
For CISOs and IT heads preparing a board or budget update
Your NIST CSF 2.0 tier, your strongest and weakest areas, and what good looks like for your top 3 gaps.
Know what our regulator requires
For compliance and IT risk teams at firms regulated by BOT, the SEC, or OIC
The Thai rules that set your security testing, a timeline of what is due when, and a checklist for your testing provider.
Rate a finding and decide what to fix first
For security engineers and development leads working from a pentest report
A CVSS 4.0 or OWASP risk rating, the finding in plain words, and the changes that would lower it.
Estimate what an incident could cost
For budget owners weighing security spend
An estimated breach cost range and yearly loss exposure for your industry, records held, and revenue.
Not sure where to start?
Most teams go in this order.
Your answers stay in your browser
The scan, checker, and calculators show results on screen and send nothing unless you ask for the emailed report.
Every result shows its source
NIST CSF 2.0, FIRST CVSS 4.0, OWASP, and the regulator clause behind each rule.
Built by an offensive security team
The calculator uses the rating methods in our pentest reports: CVSS 4.0 and the OWASP Risk Rating Methodology.
A self-assessment shows gaps. A test proves them.
Every finding in a Reconix test comes with a proof of concept, and the standard engagement includes a retest of your fixes.