Skip to content
CyberPost Advisory

Insights

Perspectives from the outside in.

Short, practical writing on external exposure and how organizations reduce it.

Latest

Reading for security and technology leaders

Attack surface

Why your attack surface is larger than your asset inventory

Marketing subdomains, staging environments and forgotten integrations rarely appear on the CMDB — but they always appear to an attacker.

Full article coming soon

Credentials

Breached credentials are an availability problem, not just an identity one

How exposed corporate credentials move from third-party breach dumps into targeted access attempts against your perimeter.

Full article coming soon

Third party

Your supplier's exposure is part of your risk picture

A practical way to assess vendor exposure externally, without waiting on a questionnaire cycle to complete.

Full article coming soon

Prioritisation

Severity is not priority

Why a medium-severity finding on an internet-facing authentication path often outranks a critical on an isolated host.

Full article coming soon

Testing

What a good rules-of-engagement document actually contains

Scope boundaries, escalation contacts, testing windows and evidence handling — the parts that prevent an incident during an assessment.

Full article coming soon

Monitoring

Exposure drifts. A yearly test cannot see it.

How change in cloud, DNS and third-party services reintroduces exposure between assessment cycles.

Full article coming soon

Want this applied to your organization? Start an exposure check

Let's find out what your organization is exposing.

One assessment. A clearer understanding of your external risk.