Attack Surface Discovery & Monitoring

You cannot defend what you forgot you own.

The staging site from the last rebuild. The subdomain pointing at a service you stopped paying for. The admin login nobody closed when the contractor left. Attackers find these before you do, because finding them is the whole job.

Direct answer: Attack surface discovery maps everything your business exposes to the internet — domains and subdomains, servers and open services, certificates, cloud storage, login pages and third-party systems trading under your name. Monitoring then watches that map and tells you when it changes, because it changes without anyone deciding it should.
Start with a Surface Review Get a Quote
A data-centre aisle with server racks receding into the distance
Everything you expose to the internet, found and written down

First, The Diagnosis

Your estate grew. Nobody kept the list.

Almost every breach we are called to started somewhere the business had stopped looking. Not a clever exploit — a forgotten door.

The old site nobody killed

A previous website, staging copy or campaign microsite still online, still running the software it shipped with years ago, still carrying your brand and sometimes your client data.

Subdomains pointing nowhere

A DNS record aimed at a cloud service you cancelled. Anyone can re-register that service and serve their own content from your domain. It is called subdomain takeover and it is common.

Admin panels on the open internet

Router, CCTV, NAS, database or CMS logins reachable from anywhere, often with the credentials they shipped with.

Certificates quietly expiring

A lapsed certificate throws a browser warning at every client on the day it expires. It is entirely avoidable and entirely visible from outside.

Cloud storage left open

A storage bucket set to public during a migration and never set back. Its contents are indexable.

Shadow systems

Tools a department signed up for on a company card, holding company data, that IT has never heard of and no one has assessed.

The Work

Find it, write it down, then watch it.

Discovery is done from the outside, the way an attacker sees you — with your written authorisation, and nothing intrusive without it.

1 · Discovery

Domains and subdomains, hosts, open ports and services, certificate inventory and expiry, exposed interfaces, cloud storage, technologies in use, and third-party services carrying your name.

2 · Verification

Automated findings are confirmed by a person before they reach you. A list of maybes is noise; an engineer confirms what is real and what it would actually cost you.

3 · Prioritised register

One document: every asset, who owns it, what is wrong, ranked by what an attacker would reach for first. Written so a director can read it and an engineer can act on it.

4 · Continuous monitoring

The map is re-checked on a schedule. New host, new open port, new subdomain, certificate about to lapse — you hear about it when it appears, not at the next audit.

Where this sits against the standards. Asset inventory is the first thing every serious framework asks for, because nothing else works without it: CIS Controls v8 opens with Control 1 and 2, inventory of enterprise and software assets. NIST Cybersecurity Framework puts it under Identify (ID.AM). MITRE ATT&CK catalogues this as Reconnaissance (TA0043) — the tactic an attacker runs first. We are simply running it before they do, and giving you the results.

Honest Scoping

This is not a penetration test, and it does not replace one.

A penetration test goes deep on systems you already know about, and proves whether they can be broken into. Attack surface discovery goes wide on systems you may not know about at all, and proves what exists. Most businesses need the wide view first — there is little sense in testing three applications in depth while a fourth nobody remembered sits unpatched on the internet.

It also differs from dark web monitoring, which watches for your data after it has left. This watches the doors while they are still yours to close. Together they cover both directions; separately, each has a blind spot.

Choose Your Level

Three levels, depending on how much has been left unattended.

Level 01

Surface Review

A one-off map of what you expose today.

  • Full external discovery
  • Engineer-verified findings
  • Prioritised asset register
  • Walkthrough of the results
Get a Quote
Most chosen Level 02

Monitored Surface

The map, kept current, with alerts on change.

  • Everything in Level 01
  • Scheduled re-discovery
  • Alerts on new exposure
  • Certificate expiry warnings
  • Quarterly review with an engineer
Get a Quote
Level 03

Managed Reduction

We close what we find, not just report it.

  • Everything in Level 02
  • Remediation carried out by us
  • Decommissioning of dead assets
  • DNS and certificate hygiene
  • Evidence pack for audits and insurers
Get a Quote

Authorisation first, always. Discovery runs only against assets you confirm in writing that you own or control. Unauthorised scanning of third-party systems is an offence under the Cybercrimes Act 19 of 2020, and we will not do it — including against a competitor, a supplier or a former provider, however the request is framed.

Straight Answers

Common questions.

We are a small practice. Is our attack surface not tiny?

It is smaller than a bank's, and it is almost never as small as the owner expects. A typical small practice we review has a website, a mail platform, a booking or portal tool, a cloud drive, a router with a public interface, a CCTV or alarm system on the network and two or three services signed up for and forgotten. That is eight doors, and attackers scan every address on the internet regardless of who is behind it.

Will this disrupt anything?

No. Discovery is passive and external by default — the same view anyone on the internet has of you. Anything more intrusive than that is quoted, scheduled and authorised separately.

How is this different from a vulnerability scan?

A vulnerability scan looks for known weaknesses in systems you point it at. This finds the systems to point it at in the first place, which is the step most businesses skip.

What do we actually receive?

An asset register listing everything found, what it is, who owns it, what is wrong with it and what to do about it, ranked by risk. On the monitored levels, alerts when that picture changes, and a review with an engineer rather than a dashboard you are left to interpret.

Do you need access to our systems?

Not for discovery. We need written confirmation of which domains and assets are yours, and nothing else. Remediation work on Level 03 needs access, scoped to the task.

Start Here

Find out what you are exposing.

A Surface Review takes days, not months, and it ends with a list you can act on. If nothing serious is found, you have documented that — which is itself worth having when an insurer or a client asks.

General information, not legal advice. Discovery is performed only against assets you confirm you own or control.
ASi Imperium (PTY) LTD · Cyber Defence · Penetration Testing · Dark Web Monitoring