Your own enterprise,
seen the way attackers see it.
Rate your own external attack surface and every subsidiary you are accountable for. It is free to start, and it is how most evaluations begin: on data you can verify yourself.
Own Enterprise, step by step
Inside-out only
Internal tooling shows you what you already know about. The forgotten staging subdomain is not in it.
Outside-in view
The same scan an attacker or an insurer would run, across the parent company and every subsidiary.
Find it before someone else does
Exposed infrastructure and weak mail records surface on your terms rather than during an incident.

Every vendor discovered and rated, grouped by risk tier so the ones that need attention stand out
You cannot defend what you do not know you own
Ask a security team to list their internet-facing assets and you will get an answer. Compare that answer to what is actually reachable and the gap is routinely thirty to fifty per cent, and it is always in the same direction: there is more exposed than anybody thought.
The extra assets are not exotic. A staging environment stood up for a launch three years ago. A subdomain from a marketing campaign that ended. Infrastructure inherited in an acquisition and never inventoried. A developer's proof of concept on a cloud account nobody is watching. A vendor-hosted portal on your domain that your team has never logged into.
These are the assets that get compromised, precisely because nobody owns them. They do not get patched, they do not appear in scanning scope, and they do not have a named owner to escalate to. An attacker enumerating your domain finds them in minutes, because they are looking at what exists rather than at what your CMDB says exists.
Why the attacker's vantage point finds what internal tooling misses
Internal vulnerability scanning starts from a list. It tests the hosts you tell it about, usually with credentials, and it is genuinely good at what it does, depth on known assets. What it cannot do is find something nobody put on the list.
External attack surface management starts from the opposite end. It begins with what an attacker begins with, a company name and a domain, and discovers outward: subdomains from certificate transparency and DNS, services from what responds, cloud assets from attribution, mail configuration from published records. The output is what is actually reachable, which is a different set from what is documented.
The two are complementary rather than competing. Discovery tells you the scope; internal scanning gives you depth within it. Running only the second means running deep tests on an incomplete list, which is how organisations end up confident and wrong at the same time.
What the same score does when pointed inward
The rating that assesses your vendors works identically on your own domains, and there is a specific reason to run it: it tells you what a prospective customer sees when they rate you.
That question is now commercially live. Enterprise buyers increasingly rate suppliers before they sign, and a bad external posture costs deals with people who never tell you why. Seeing your own score before a procurement team does is the difference between fixing a lapsed certificate on a payment subdomain and losing a tender for reasons nobody ever explains.
It is also the honest way to evaluate a ratings platform. Rate your own organisation first, where you can check every finding against what you know to be true. If the findings are accurate on the environment you understand best, the ratings on your vendors are worth acting on. If they are not, you have learned that cheaply.
Discovery is continuous, because exposure is
A one-off discovery exercise produces a report that is wrong within a month. Assets appear constantly: a new campaign subdomain, a cloud resource spun up for a test, a certificate issued by a team you did not know was issuing certificates.
Continuous discovery turns that into an event stream (this appeared, this changed, this became reachable) which is actionable in a way a quarterly report never is. The useful discipline is attribution and ownership: every discovered asset gets assigned to a team, and unattributed assets are themselves the finding worth chasing.
Then the rating gives you a trend rather than a snapshot. Posture improving or degrading over quarters is a far more meaningful board metric than a count of open findings, which mostly measures how hard you looked.
Internal scanning vs external attack surface management
| Internal vulnerability scanning | External ASM | |
|---|---|---|
| Starts from | A list of known hosts | A company name and a domain |
| Finds unknown assets | No | Yes, that is the point |
| Needs credentials | Usually | No |
| Needs network access | Yes | No |
| Depth on known hosts | High | Moderate, what is externally observable |
| Matches attacker's view | Partly | Yes, by construction |
Discovery sets the scope; internal scanning gives depth inside it. Running only the second means testing an incomplete list thoroughly.
“The first scan of our own group found two subsidiaries nobody had inventoried.”
Own Enterprise | common questions
How is this different from a vulnerability scanner?
A vulnerability scanner tests hosts you already know about and usually needs credentials or network access. External attack surface management starts by discovering assets you did not know were exposed (forgotten staging hosts, acquired-company domains, shadow cloud accounts) and then assesses them. It needs no access to your environment at all.
How much do organisations typically find that they did not know about?
Thirty to fifty per cent more internet-facing assets than the internal inventory lists, and it is always in that direction. The gap is usually staging environments, campaign subdomains, acquired infrastructure and cloud resources without a named owner.
Why rate ourselves if we already run internal scanning?
Two reasons. Discovery finds what the scanner's scope is missing. And the score is what a prospective enterprise customer sees when they rate you before signing, which is now a live commercial risk, and one you will never be told about directly.
Do you need access to our systems?
No. Assessment observes only what is published to the public internet. The single optional exception is cloud posture, which uses read-only scoped access to an account you choose to connect.
How often does discovery run?
Continuously. A one-off discovery report is stale within a month, because assets appear constantly, campaign subdomains, test resources, certificates issued by teams you did not know were issuing them.
What do we do with assets nobody owns?
Attribute them. An unattributed internet-facing asset is itself the finding: it will not get patched, it will not appear in scanning scope, and there is nobody to escalate to when it breaks.
Where this connects
Attack surface management →
How assets are discovered, attributed and continuously monitored.
Board reporting →
Turning posture trend into something a board can act on.
How scoring works →
The deterministic model, and how to refute a finding.
Put your vendors on the board
Start with ten vendors. Expand when the first alert pays for the year.