The definitive guide

The External Attack Surface Check

AttackSurfaceCheck examines your organization from the public internet, discovers your externally visible digital footprint, identifies meaningful exposures, manually validates the risks that matter, investigates realistic attack paths, and delivers a clear, evidence-based report.

What it is

An External Attack Surface Check is an independent, outside-in security assessment. Instead of starting from a list of assets you already know about, it starts from the opposite direction: what can an attacker discover about your organization from the public internet?

That discovery is then narrowed down through analysis and manual validation, and — where authorized — extended into attack-path investigation, so you understand not just what's exposed, but whether it actually matters.

Why organizations need it

Security teams generally know what they intend to expose to the internet. That is not necessarily the same as what is actually exposed. Domains, subdomains, cloud infrastructure, forgotten staging environments, acquired-company systems, and shadow-IT assets accumulate faster than most inventories can track. Known assets are only part of your attack surface — attackers look for what your team doesn't know about.

The six stages

What we discover, analyze, and test

01

Define

We agree the organization, seed domains, known IP ranges where relevant, subsidiaries and brands where applicable, exclusions, testing boundaries, and Rules of Engagement. No active security testing occurs before written authorization.

02

Discover

We map your externally observable digital footprint — domains, subdomains, IP addresses, hosting and cloud-facing infrastructure, websites, applications, APIs, certificates, DNS, mail infrastructure, authentication portals, VPN and remote-access systems, and development or legacy systems still reachable from the internet. We don't simply scan the asset list you already have — we investigate what an external attacker could discover.

03

Analyze

Depending on agreed scope, we analyze the discovered surface for exposed services, unexpected internet-facing systems, insecure configuration, obsolete technology, authentication exposure, information disclosure, cloud exposure, DNS and mail-security observations, and security-control weaknesses. Not every assessment includes every possible test — scope is agreed upfront.

04

Validate

This is the critical differentiator. We do not simply report scanner output. An experienced offensive-security professional manually reviews relevant observations to distinguish noise from real exposure from meaningful security risk. Automation provides scale and coverage; human offensive-security expertise provides context.

05

Connect

Where appropriate and explicitly authorized, we investigate whether individual exposures could combine into a realistic attack path — from an unknown asset, through an exposed application and a security weakness, to unauthorized access and potential business impact. Not every assessment identifies such a path, and we never claim otherwise.

06

Report

You receive actionable evidence, not a scanner dump: an executive summary, full asset overview, unknown-asset observations, human-validated findings with evidence, attack paths if identified, prioritized remediation, positive security observations, assessment limitations, a technical appendix, and a debrief call.

Comparison

How this differs from other approaches

vs. Vulnerability Scanning

Vulnerability scanners check known assets against a database of known weaknesses. An External Attack Surface Check starts by finding assets you didn't know were exposed, then applies human judgement to what's found — not just a CVE match.

vs. Penetration Testing

A penetration test validates a predefined, known scope in depth. An External Attack Surface Check begins with discovery of the unknown, then applies offensive-security validation and attack-path testing to what's found. The two are complementary, not competing.

vs. Automated EASM Platforms

Automated External Attack Surface Management tools run continuously and surface findings at scale — useful, but typically unvalidated. We use comparable discovery techniques, but every meaningful observation is manually reviewed and tested by an offensive-security professional.

If nothing critical is found

An assessment does not need a critical finding to provide value. Knowing which attack scenarios were tested and resisted is itself evidence about your external security posture. We report this as clearly as we report a validated finding.

Duration

Typically 1–3 weeks

Depending on the size of your footprint and agreed depth of testing.

Investment

From €3,950

Final pricing depends on footprint, applications and required depth. See pricing factors →

Authorization

Required before testing

Written scope, authorization and Rules of Engagement are always agreed before any active testing begins.

Ready to see what your organization exposes?

Request an assessment, or see exactly what you'll receive first.

Get started

What does your organization look like from the outside?

Request an External Attack Surface Check and find out what an attacker can see before they do.