First, The Diagnosis
Your estate grew. Nobody kept the list.
Almost every breach we are called to started somewhere the business had stopped looking. Not a clever exploit — a forgotten door.
The old site nobody killed
A previous website, staging copy or campaign microsite still online, still running the software it shipped with years ago, still carrying your brand and sometimes your client data.
Subdomains pointing nowhere
A DNS record aimed at a cloud service you cancelled. Anyone can re-register that service and serve their own content from your domain. It is called subdomain takeover and it is common.
Admin panels on the open internet
Router, CCTV, NAS, database or CMS logins reachable from anywhere, often with the credentials they shipped with.
Certificates quietly expiring
A lapsed certificate throws a browser warning at every client on the day it expires. It is entirely avoidable and entirely visible from outside.
Cloud storage left open
A storage bucket set to public during a migration and never set back. Its contents are indexable.
Shadow systems
Tools a department signed up for on a company card, holding company data, that IT has never heard of and no one has assessed.
The Work
Find it, write it down, then watch it.
Discovery is done from the outside, the way an attacker sees you — with your written authorisation, and nothing intrusive without it.
1 · Discovery
Domains and subdomains, hosts, open ports and services, certificate inventory and expiry, exposed interfaces, cloud storage, technologies in use, and third-party services carrying your name.
2 · Verification
Automated findings are confirmed by a person before they reach you. A list of maybes is noise; an engineer confirms what is real and what it would actually cost you.
3 · Prioritised register
One document: every asset, who owns it, what is wrong, ranked by what an attacker would reach for first. Written so a director can read it and an engineer can act on it.
4 · Continuous monitoring
The map is re-checked on a schedule. New host, new open port, new subdomain, certificate about to lapse — you hear about it when it appears, not at the next audit.
Where this sits against the standards. Asset inventory is the first thing every serious framework asks for, because nothing else works without it: CIS Controls v8 opens with Control 1 and 2, inventory of enterprise and software assets. NIST Cybersecurity Framework puts it under Identify (ID.AM). MITRE ATT&CK catalogues this as Reconnaissance (TA0043) — the tactic an attacker runs first. We are simply running it before they do, and giving you the results.
Honest Scoping
This is not a penetration test, and it does not replace one.
A penetration test goes deep on systems you already know about, and proves whether they can be broken into. Attack surface discovery goes wide on systems you may not know about at all, and proves what exists. Most businesses need the wide view first — there is little sense in testing three applications in depth while a fourth nobody remembered sits unpatched on the internet.
It also differs from dark web monitoring, which watches for your data after it has left. This watches the doors while they are still yours to close. Together they cover both directions; separately, each has a blind spot.
Choose Your Level
Three levels, depending on how much has been left unattended.
Surface Review
A one-off map of what you expose today.
- Full external discovery
- Engineer-verified findings
- Prioritised asset register
- Walkthrough of the results
Monitored Surface
The map, kept current, with alerts on change.
- Everything in Level 01
- Scheduled re-discovery
- Alerts on new exposure
- Certificate expiry warnings
- Quarterly review with an engineer
Managed Reduction
We close what we find, not just report it.
- Everything in Level 02
- Remediation carried out by us
- Decommissioning of dead assets
- DNS and certificate hygiene
- Evidence pack for audits and insurers
Authorisation first, always. Discovery runs only against assets you confirm in writing that you own or control. Unauthorised scanning of third-party systems is an offence under the Cybercrimes Act 19 of 2020, and we will not do it — including against a competitor, a supplier or a former provider, however the request is framed.
Straight Answers
Common questions.
We are a small practice. Is our attack surface not tiny?
It is smaller than a bank's, and it is almost never as small as the owner expects. A typical small practice we review has a website, a mail platform, a booking or portal tool, a cloud drive, a router with a public interface, a CCTV or alarm system on the network and two or three services signed up for and forgotten. That is eight doors, and attackers scan every address on the internet regardless of who is behind it.
Will this disrupt anything?
No. Discovery is passive and external by default — the same view anyone on the internet has of you. Anything more intrusive than that is quoted, scheduled and authorised separately.
How is this different from a vulnerability scan?
A vulnerability scan looks for known weaknesses in systems you point it at. This finds the systems to point it at in the first place, which is the step most businesses skip.
What do we actually receive?
An asset register listing everything found, what it is, who owns it, what is wrong with it and what to do about it, ranked by risk. On the monitored levels, alerts when that picture changes, and a review with an engineer rather than a dashboard you are left to interpret.
Do you need access to our systems?
Not for discovery. We need written confirmation of which domains and assets are yours, and nothing else. Remediation work on Level 03 needs access, scoped to the task.
Start Here
Find out what you are exposing.
A Surface Review takes days, not months, and it ends with a list you can act on. If nothing serious is found, you have documented that — which is itself worth having when an insurer or a client asks.