Step one
Assess My Organization
Begin with a limited external exposure check. It uses passive, publicly available information only — the same starting point an attacker would use.
Authorised security testing
Nothing intrusive happens without your authorisation.
The initial check never performs active or intrusive testing against a domain. Deeper assessment and penetration testing require the following before work begins.
Customer authorization
Active testing begins only after written authorisation from an authorised representative.
Defined scope
Targets, systems and boundaries are agreed and confirmed before any testing.
Rules of engagement
Timing, intensity, contacts and escalation paths are documented up front.
Appropriate safeguards
Findings and evidence are handled under controlled disclosure to named contacts.
Prefer to speak with someone first? Talk to a Security Advisor.
What happens next
From exposure to a decision
- 01
Initial findings
You see a snapshot of what is publicly visible.
- 02
External Exposure Assessment
We validate, prioritise and report against business risk.
- 03
Remediation & monitoring
We help reduce exposure, then watch it for change.