One-off report

Which assets are exposed? External Attack Surface Assessment

We assess, once, what your company exposes on the internet — domains, subdomains, IP addresses, publicly reachable services, legacy systems and shadow IT. From the outside and non-invasively: no exploitation of vulnerabilities, no credentials, no access to your internal network. You receive a report with concrete mitigation measures that management, the security team and an auditor can all work from.

Typically two weeks from kick-off · scope agreed before we begin · Graydaxe Cybersecurity GmbH, Berlin · data processed in the EU
RESULT REPORT — MANAGEMENT SUMMARY
Externally reachable assets attributed to you412
Not in your inventory (shadow IT, legacy systems)37
Findings of critical or high priority5
Excluded from scope — documented58
Highest priority
legacy-vpn.example.com — VPN gateway without vendor support
Known exploited vulnerability · next step: decommission or patch
References: ISO/IEC 27001 · NIST CSF 2.0 · NIS2
Illustrative example · fictitious values · no customer data

Why it matters

Your asset inventory ends — your attack surface does not.

Forgotten, but onlineOld subdomains, test environments and cloud resources that nobody maintains any more — and everybody can reach.
Growth outruns the inventoryAcquisitions, subsidiaries, agencies and cloud projects create attack surface faster than a CMDB records it.
Auditors want evidenceISO 27001, NIST CSF and NIS2 require documented asset and vulnerability management — not estimates.

What you get

A report that holds up — in the boardroom and in the audit.

A comprehensive document that describes the company's security posture in detail — for IT, for management and for auditors alike.

RESULT REPORT — CONTENTS
01Management summaryBoard
02Scope, method & exclusionsAudit
03Attributed asset inventoryIT
04Findings by exploitabilitySecurity
05Shadow IT & legacy systemsIT
06References to standardsAudit
07Next steps & walkthroughAll
Illustrative example · structure, not a real report
Management

Where do we stand?

A clear picture of external exposure and of the few decisions that actually matter — without jargon.

Security & IT

What do we fix first?

Findings prioritised by real exploitability: not every high severity is a high risk. With a concrete next step per finding. Ready for your ticket system from day one.

Audit & compliance

Can we evidence it?

Documented scope, method and exclusions — including parked, third-party and unreachable assets — that an auditor can follow.


How it works

Four steps, two weeks.

1Kick-off & scopeYou name domains, IP ranges and legal entities — in any country. We define the scope together before the work begins.
2Confirm assetsWe identify your externally reachable assets and attribute them to you. You confirm what belongs to you — only then does the assessment start.
3AssessmentPassive and targeted active, non-invasive techniques. Prioritisation by real exploitability — EPSS, CVSS, known exploited vulnerabilities (KEV) and exploit data; our security experts validate selected results together with you — without exploits.
4Report & walkthroughYou receive the result report, and we go through it with your team — including the next steps.
CTEMThe four steps match one full cycle of Continuous Threat Exposure Management — scoping → discovery → prioritisation → validation → mobilisation. The assessment runs through it once and gives you a documented baseline.
Scope and price
  • You tell us the domains to be assessed. From those we determine the externally reachable assets and confirm the scope together with you — before the assessment
  • Only confirmed assets attributed to your company are charged
  • The price depends on the number of confirmed assets and follows fixed price tiers. We provide the pricing and billing model on request
  • No automatic expansion: if the scope turns out larger than expected, we agree the price tier with you beforehand

A clear boundary

Not a penetration test — the step before it.

A penetration test proves whether selected systems can be exploited. The assessment first establishes what you expose at all — so that a subsequent pentest targets the right systems.

Attack surface assessment

  • Comprehensive: all externally reachable assets
  • Largely automated, manually validated
  • Non-invasive, very low operational risk
  • Finds unknown assets — and defines the scope for a pentest

Penetration test

  • Selective: defined systems or applications
  • Heavily manual, exploit-based
  • Potentially invasive, operational risk depending on depth
  • Proves exploitability

Not part of the assessment: Exploitation of vulnerabilities · authenticated testing with credentials · changes to target systems · scans inside your internal network


Compliance

ISO 27001, NIST CSF 2.0, NIS2, TISAX

The report is a professional basis for your ISMS, internal risk analyses and contractual security requirements from your customers — and it supports these requirements:

StandardRelevant requirementHow the report supports it
ISO/IEC 27001:2022Annex A 5.9 Inventory of information and other associated assets · A 8.8 Management of technical vulnerabilitiesExternally reachable assets inventoried and attributed; vulnerabilities identified, prioritised and documented with next steps.
NIST CSF 2.0ID.AM Asset Management · ID.RA-01 Vulnerabilities identified, validated and recordedAn outside-in view of the systems and services you expose; validated vulnerabilities recorded per asset.
NIS2 Directive (EU)Art. 21(2)(a) risk analysis · (d) supply chain · (e) vulnerability handlingA dated, documented snapshot as a basis for risk analysis — extended to critical suppliers on request.
TISAXAssessment preparationEvidenced asset and vulnerability management for externally reachable infrastructure.

The report replaces neither an audit nor a certification.


And afterwards?

Your attack surface keeps changing.

Every migration, every new service and every supplier creates new attack surface. We are happy to keep your external attack surface in view all year round as a managed service: the cycle repeats continuously and we report what is new — on request, for the attack surface of critical suppliers as well.

To attack surface monitoring →

FAQ

Frequently asked questions

What do we need to prepare?

Domains, IP ranges and your group structure for the kick-off, plus a contact person who confirms the discovered assets with us. Nothing is installed.

Does the assessment touch our systems?

It is non-invasive and not designed to affect production systems. Alongside passive techniques we run targeted active ones within the agreed scope — no exploits, no authenticated testing, no scans inside your internal network.

Can subsidiaries abroad be included?

Yes. An outside-in analysis is not tied to a location. We define entities and their domains in the kick-off.

Am I committed to anything afterwards?

No. The assessment is a one-off service with a defined scope. Whether you move on to continuous monitoring with GrayScope is a separate decision.


The first step is the scope.

Tell us your domains, IP ranges and legal entities — whether one or forty. From those we determine the externally reachable assets and agree the scope with you.