● External Attack Surface Assessment

Your attack surface is larger than your team knows

Shadow IT, forgotten subdomains, exposed credentials, misconfigured cloud assets — most organizations carry significant external exposure they have never mapped. This assessment finds it before someone else does.

The Problem

What you don't know is what attackers exploit

Your security team protects what it knows about. But organizations accumulate digital exposure they never intended — from cloud experiments that became permanent, to contractor environments that were never decommissioned, to employee credentials that appeared in breach databases months ago.

🔍

Shadow IT

Unauthorized services, personal cloud accounts, and developer tooling used without security oversight — exposed to the internet and invisible to your team.

🔑

Leaked Credentials

Employee email addresses and passwords appear in breach databases daily. Attackers use these for credential stuffing before you even know they're out there.

🌐

Forgotten Assets

Old subdomains, decommissioned servers, and test environments that still accept connections — often without the security controls applied to your main infrastructure.

☁️

Cloud Misconfigurations

Publicly accessible storage buckets, open APIs, and misconfigured permissions that expose sensitive data or provide an attacker a foothold.

Who This Is For

Built for organizations that need clarity, not another compliance checkbox

This assessment is most valuable when your external exposure is genuinely unknown — and the stakes of getting it wrong are high.

CISOs & Security Leaders

New to the role and need a baseline. Or responsible for an environment that has grown faster than your visibility into it.

Pre-Investment / Pre-IPO

Investors, acquirers, and underwriters increasingly require independent security assessment. Find the gaps before they do.

Post-Incident Organizations

After a breach, the critical question is: what else is exposed? This assessment answers it without expanding the footprint of the incident.

M&A Due Diligence

Acquiring a company means inheriting their attack surface. Know what you're buying before the deal closes.

This assessment is also commonly commissioned by law firms handling cyber disputes, regulated financial institutions ahead of audits, and technology companies preparing for enterprise customer security reviews.

What We Investigate

Entirely passive. No intrusion. No agent required.

Everything in this assessment is conducted through external open-source intelligence — the same methods an attacker would use in reconnaissance, before touching your systems. We require no internal access.

What You Receive

A complete picture — not a raw data dump

Every finding is risk-rated, contextualized, and tied to a specific recommended action. The executive summary is designed to be shared with board members and non-technical stakeholders.

How It Works

A defined process. A fixed scope. A clear outcome.

Duration: 2–4 weeks
📋 Engagement type: Fixed-fee project
🔒 Access required: None
1

Scoping call (30 minutes)

We establish your seed assets (primary domains, known IP ranges, key subsidiaries) and agree on scope. This call is free and confidential.

2

Passive reconnaissance

External discovery of your entire digital footprint — subdomains, IP ranges, cloud assets, technology stack, and exposed services — using OSINT methodology.

3

Breach & dark web investigation

Cross-referencing your domains, email patterns, and employee identifiers against breach databases and dark web sources for leaked credentials and active targeting.

4

Analysis and risk rating

Every finding is assessed for actual risk, not just theoretical severity. We distinguish between technically interesting and genuinely exploitable.

5

Report delivery and walkthrough

You receive both the executive summary and technical report simultaneously. We schedule a walkthrough to explain findings and prioritize your remediation response.

Anonymized Example

What we typically find

The following is based on a real engagement. Details have been modified to protect client confidentiality.

Fintech company · Series B preparation · 180 employees

A fintech platform preparing for a Series B round engaged us at the recommendation of a lead investor who wanted independent security diligence. The company had a full-time security engineer and believed their external exposure was well-managed.

The assessment identified three forgotten development servers that had been running for over two years — two with valid production API keys embedded in their configuration. A separate investigation found 47 employee credentials in public breach databases, 11 of which matched the company's current active directory password policy, suggesting they were still in use. A wildcard subdomain pointed to a decommissioned third-party service that was still resolving and returning a valid authentication page.

All three issues were remediated within 72 hours of report delivery. The Series B closed on schedule.
FAQ

Common questions

Is this intrusive or disruptive to our systems?
No. This assessment is entirely passive — we use the same open-source intelligence techniques an attacker would use in initial reconnaissance, before touching your systems. No scanning, no exploitation, no impact on system performance or availability.
How is this different from a penetration test?
A penetration test is active — it involves attempting to exploit vulnerabilities with explicit permission. This assessment is passive intelligence. We map what is exposed and what has leaked, rather than testing whether specific vulnerabilities are exploitable. They serve different purposes and are often complementary.
What if you find something critical during the assessment?
We don't wait until the final report. If we identify an active threat — credentials actively being used, an open port with a known critical vulnerability, or evidence of current targeting — we contact you the same day.
Do you need access to our internal systems or networks?
No. We need only a list of your primary domains and an NDA. Everything we do is from the outside, using publicly available information and breach data.
How is engagement pricing structured?
Engagements are fixed-fee, scoped to the size and complexity of your environment. Pricing is agreed during the scoping call. We don't do time-and-materials for this type of assessment.
Can the report be provided under NDA and remain confidential?
Yes. A mutual NDA is standard before any engagement begins. The report and all findings are confidential. We do not retain client data after delivery.

Know your exposure before an attacker does

A 30-minute scoping call is free, confidential, and comes with no obligation. We'll tell you what we'd look for and what it would cost.