Use case · Enterprise

Your own enterprise,
seen the way attackers see it.

Rate your own external attack surface and every subsidiary you are accountable for. It is free to start, and it is how most evaluations begin: on data you can verify yourself.

How it works

Own Enterprise, step by step

Before

Inside-out only

Internal tooling shows you what you already know about. The forgotten staging subdomain is not in it.

With GuardianGaze

Outside-in view

The same scan an attacker or an insurer would run, across the parent company and every subsidiary.

Result

Find it before someone else does

Exposed infrastructure and weak mail records surface on your terms rather than during an incident.

Third-party vendor inventory scored by security rating, tier and risk category

Every vendor discovered and rated, grouped by risk tier so the ones that need attention stand out

The premise

You cannot defend what you do not know you own

Ask a security team to list their internet-facing assets and you will get an answer. Compare that answer to what is actually reachable and the gap is routinely thirty to fifty per cent, and it is always in the same direction: there is more exposed than anybody thought.

The extra assets are not exotic. A staging environment stood up for a launch three years ago. A subdomain from a marketing campaign that ended. Infrastructure inherited in an acquisition and never inventoried. A developer's proof of concept on a cloud account nobody is watching. A vendor-hosted portal on your domain that your team has never logged into.

These are the assets that get compromised, precisely because nobody owns them. They do not get patched, they do not appear in scanning scope, and they do not have a named owner to escalate to. An attacker enumerating your domain finds them in minutes, because they are looking at what exists rather than at what your CMDB says exists.

Outside-in

Why the attacker's vantage point finds what internal tooling misses

Internal vulnerability scanning starts from a list. It tests the hosts you tell it about, usually with credentials, and it is genuinely good at what it does, depth on known assets. What it cannot do is find something nobody put on the list.

External attack surface management starts from the opposite end. It begins with what an attacker begins with, a company name and a domain, and discovers outward: subdomains from certificate transparency and DNS, services from what responds, cloud assets from attribution, mail configuration from published records. The output is what is actually reachable, which is a different set from what is documented.

The two are complementary rather than competing. Discovery tells you the scope; internal scanning gives you depth within it. Running only the second means running deep tests on an incomplete list, which is how organisations end up confident and wrong at the same time.

Rating yourself

What the same score does when pointed inward

The rating that assesses your vendors works identically on your own domains, and there is a specific reason to run it: it tells you what a prospective customer sees when they rate you.

That question is now commercially live. Enterprise buyers increasingly rate suppliers before they sign, and a bad external posture costs deals with people who never tell you why. Seeing your own score before a procurement team does is the difference between fixing a lapsed certificate on a payment subdomain and losing a tender for reasons nobody ever explains.

It is also the honest way to evaluate a ratings platform. Rate your own organisation first, where you can check every finding against what you know to be true. If the findings are accurate on the environment you understand best, the ratings on your vendors are worth acting on. If they are not, you have learned that cheaply.

Operating it

Discovery is continuous, because exposure is

A one-off discovery exercise produces a report that is wrong within a month. Assets appear constantly: a new campaign subdomain, a cloud resource spun up for a test, a certificate issued by a team you did not know was issuing certificates.

Continuous discovery turns that into an event stream (this appeared, this changed, this became reachable) which is actionable in a way a quarterly report never is. The useful discipline is attribution and ownership: every discovered asset gets assigned to a team, and unattributed assets are themselves the finding worth chasing.

Then the rating gives you a trend rather than a snapshot. Posture improving or degrading over quarters is a far more meaningful board metric than a count of open findings, which mostly measures how hard you looked.

Comparison

Internal scanning vs external attack surface management

Internal vulnerability scanningExternal ASM
Starts fromA list of known hostsA company name and a domain
Finds unknown assetsNoYes, that is the point
Needs credentialsUsuallyNo
Needs network accessYesNo
Depth on known hostsHighModerate, what is externally observable
Matches attacker's viewPartlyYes, by construction

Discovery sets the scope; internal scanning gives depth inside it. Running only the second means testing an incomplete list thoroughly.

“The first scan of our own group found two subsidiaries nobody had inventoried.”
CISO · Mid-market financial services group
FAQ

Own Enterprise | common questions

How is this different from a vulnerability scanner?

A vulnerability scanner tests hosts you already know about and usually needs credentials or network access. External attack surface management starts by discovering assets you did not know were exposed (forgotten staging hosts, acquired-company domains, shadow cloud accounts) and then assesses them. It needs no access to your environment at all.

How much do organisations typically find that they did not know about?

Thirty to fifty per cent more internet-facing assets than the internal inventory lists, and it is always in that direction. The gap is usually staging environments, campaign subdomains, acquired infrastructure and cloud resources without a named owner.

Why rate ourselves if we already run internal scanning?

Two reasons. Discovery finds what the scanner's scope is missing. And the score is what a prospective enterprise customer sees when they rate you before signing, which is now a live commercial risk, and one you will never be told about directly.

Do you need access to our systems?

No. Assessment observes only what is published to the public internet. The single optional exception is cloud posture, which uses read-only scoped access to an account you choose to connect.

How often does discovery run?

Continuously. A one-off discovery report is stale within a month, because assets appear constantly, campaign subdomains, test resources, certificates issued by teams you did not know were issuing them.

What do we do with assets nobody owns?

Attribute them. An unattributed internet-facing asset is itself the finding: it will not get patched, it will not appear in scanning scope, and there is nobody to escalate to when it breaks.

Related

Where this connects

Attack surface management →

How assets are discovered, attributed and continuously monitored.

Board reporting →

Turning posture trend into something a board can act on.

How scoring works →

The deterministic model, and how to refute a finding.

Put your vendors on the board

Start with ten vendors. Expand when the first alert pays for the year.