Skip to content
CyberPost Advisory

Step one

Assess My Organization

Begin with a limited external exposure check. It uses passive, publicly available information only — the same starting point an attacker would use.

The initial check is designed around passive, publicly available information. No intrusive testing is performed against any domain without written authorisation.

Authorised security testing

Nothing intrusive happens without your authorisation.

The initial check never performs active or intrusive testing against a domain. Deeper assessment and penetration testing require the following before work begins.

Customer authorization

Active testing begins only after written authorisation from an authorised representative.

Defined scope

Targets, systems and boundaries are agreed and confirmed before any testing.

Rules of engagement

Timing, intensity, contacts and escalation paths are documented up front.

Appropriate safeguards

Findings and evidence are handled under controlled disclosure to named contacts.

Prefer to speak with someone first? Talk to a Security Advisor.

What happens next

From exposure to a decision

  1. 01

    Initial findings

    You see a snapshot of what is publicly visible.

  2. 02

    External Exposure Assessment

    We validate, prioritise and report against business risk.

  3. 03

    Remediation & monitoring

    We help reduce exposure, then watch it for change.

Request Assessment