External Attack Surface Assessment

See what attackers see.

We map your internet-facing attack surface, uncover unknown and forgotten assets, identify external exposures, and manually validate the risks that actually matter.

No agents. No internal access required. An independent outside-in assessment of your organization, performed the way an attacker would actually approach it.

The problem

Do you know everything your organization exposes to the internet?

Known assets are only part of your attack surface. Your security team protects what it knows about. Attackers look for what it doesn't.

Modern organizations accumulate domains, subdomains, cloud infrastructure, public IP addresses, web applications, APIs, authentication portals, VPN and remote-access systems, development and staging environments, acquired-company infrastructure, and forgotten systems — often faster than any inventory can track.

Traditional vulnerability scanning usually starts with a known list of assets. Our assessment starts from the opposite direction: what can an attacker discover about you from the outside? Then: which of those discoveries actually matter? And finally: can any of them contribute to a meaningful attack path?

The product

The External Attack Surface Check

Discovery is only the beginning. Automated tools find assets and observations. We add human offensive-security analysis to determine what actually matters — and whether it forms a real attack path.

01

Define

Scope, boundaries, and written authorization.

02

Discover

Map the externally observable footprint.

03

Analyze

Identify meaningful exposure.

04

Validate

Human offensive-security review.

05

Connect

Investigate realistic attack paths.

06

Report

Evidence-based, actionable findings.

Automated discovery

Scale and coverage: reconnaissance across domains, certificates, DNS, cloud ranges and technology fingerprints.

Human validation

Context and judgement: separating noise from real exposure from meaningful security risk — and testing whether it can be chained into an attack path.

Why this is different

Scanners find findings. Attackers find paths.

We don't report scanner output. An experienced offensive-security professional manually reviews and validates the observations that matter, distinguishing noise from real exposure from meaningful security risk — and, where authorized, investigates whether individual exposures combine into a realistic attack path.

Scope

What we actually test

Depending on agreed scope. We do not imply every assessment includes every possible test — scope is agreed with you upfront.

  • Domains, subdomains & DNS infrastructure
  • Cloud-facing assets & hosting infrastructure
  • Web applications & APIs
  • Authentication & VPN / remote-access portals
  • Mail infrastructure & email-security posture
  • Development & staging environments
  • Legacy & forgotten internet-facing systems
  • Public information useful to an attacker
Fictional demonstration data — Northstar Industries is not a real client.
Sample assessment

What you'll actually receive

A real External Attack Surface Check produces evidence, not a scanner dump. Here is what that looked like for a fictional demonstration organization, Northstar Industries.

214
Assets identified
31
Assets requiring ownership review
17
Externally exposed services reviewed
9
Attack hypotheses tested
4
Validated security findings
1
Viable attack path demonstrated
Attack path AP-01 · fictional example

From an unknown asset to business impact

Discovery
Legacy customer portal
An unexpected asset, not present in the known inventory.
Exposure
Outdated internet-facing component
A technology fingerprint flagged the component as out of date.
Weakness
Authentication control weakness
Manually validated — not scanner output.
Access
Unauthorized application access
Impact
Potential access to sensitive business data
Validated — Fictional Example

This is an illustrative attack-path model. Not every assessment identifies a viable attack path — see below.

Attack hypothesis AH-04 · fictional example

Can the externally exposed remote-access infrastructure provide a viable initial-access path?

Not validated during the assessment
  • Expected authentication controls present
  • No material externally exploitable weakness identified within scope
  • No viable attack path demonstrated

An assessment does not need a critical finding to provide value. Knowing which attack scenarios were tested and resisted provides evidence about your external security posture. We do not claim absolute security — only what was tested, and what the evidence shows.

Deliverables

What you receive

Executive Summary

A clear, non-technical overview for leadership and stakeholders.

External Attack Surface Overview

The full discovered footprint, organized and explained.

Unknown / Unexpected Asset Observations

What we found that your inventory didn't account for.

Human-Validated Findings

Evidence, affected assets, risk explanation, and clear reproduction steps.

Attack Paths, If Identified

How exposures could realistically be chained together.

Prioritized Remediation

What to fix first, and why — not a raw findings dump.

Positive Security Observations

What is already working, not only what isn't.

Assessment Limitations

An honest account of what was and wasn't covered.

Debrief / Results Call

A live walkthrough with the person who did the work.

Who this is for

Built for security leaders who need an outside-in view

  • Don't fully trust their current asset inventory
  • Have rapidly changing cloud infrastructure
  • Recently completed an acquisition or merger
  • Manage multiple brands or domains
  • Want an independent outside-in view
  • Need periodic external security validation
  • Want to complement existing vulnerability management
  • Want more than automated scanner results
Getting started

How an engagement starts

01

Request

Tell us about your organization and objectives.

02

Scope

A short conversation to agree an appropriate scope.

03

Proposal

A straightforward, itemized proposal — no surprises.

04

Authorize

Written scope, authorization and Rules of Engagement.

05

Assess

Discovery, analysis, validation and attack-path work.

06

Report

A clear, evidence-based report — not a scanner dump.

07

Review

A live debrief with the person who did the work.

FAQ

Common questions

How is this different from a penetration test?
A penetration test validates a known, predefined scope in depth. An External Attack Surface Check starts by discovering what's actually internet-facing — including assets you didn't know about — then applies offensive-security validation to what matters. Read the full comparison →
How is this different from an automated EASM tool?
Automated EASM platforms run continuously and surface findings at scale. We use similar discovery techniques, but every meaningful observation is manually reviewed by an offensive-security professional and — where authorized — tested for real attack-path potential.
What does it cost?
Focused External Attack Surface Checks typically start from €3,950. Final pricing depends on your footprint and required depth. See pricing factors →
Will you test without our permission?
No. Submitting an enquiry never authorizes testing. Active security testing only begins after written scope, authorization and Rules of Engagement are agreed.
Get started

What does your organization look like from the outside?

Request an External Attack Surface Check and find out what an attacker can see before they do.