SOLUTION / 01
Exposure &External Risk
Know what the outside world can reach — before deciding what needs deeper testing.
The problem the organisation faces
Internet-facing assets change continuously. Domains, cloud endpoints, certificates and mail records accumulate faster than most teams can track — and an attacker only needs the one nobody remembered.
Who this is for
- 01SMEs building their first security programme
- 02Organisations whose internet-facing assets grow quickly
- 03Online businesses with annual review cycles
- 04Teams that have never mapped their external footprint
What the solution covers
External attack surface discovery
Every internet-facing asset an attacker could see: domains, subdomains, IPs, cloud endpoints, forgotten legacy.
Vulnerability assessment
Known weaknesses and weak configuration, validated by engineers instead of a raw scanner dump.
TLS, domain & email security
Certificate hygiene, DNS, SPF / DKIM / DMARC — the controls that stop impersonation and takeover.
Cloud exposure review
AWS, Azure and M365 identity, storage and network, checked from the outside in.
How the work runs
A continuous outside-in view, not a one-off scan.
- DISCOVER
- VALIDATE
- RATE
- TRACK
What the organisation receives
Executive view
Findings and risk in management language, mapped to the obligations they answer.
Technical findings
Reproduction steps, affected assets and root cause for every finding.
Evidence
Proof you can reproduce — payloads, logs and screenshots attached to the rating.
Priorities
A 30/60/90-day plan with owners, so work starts the week the report lands.
Retest status
Where retesting is in scope: Closed, Risk Accepted with an expiry, or Monitoring with a follow-up date.
Typical triggers
Related programme
Typically starts with Essential and extends to Enhanced as the business and its exposure grow.
Technical findings and recommendations reflect engineering judgement — they are not legal advice.
Discuss this requirement.
Tell us the system, the timeline and the worry — the answer will be a scope, not a sales deck.
Discuss this requirement ↗