We assess, once, what your company exposes on the internet — domains, subdomains, IP addresses, publicly reachable services, legacy systems and shadow IT. From the outside and non-invasively: no exploitation of vulnerabilities, no credentials, no access to your internal network. You receive a report with concrete mitigation measures that management, the security team and an auditor can all work from.
A comprehensive document that describes the company's security posture in detail — for IT, for management and for auditors alike.
A clear picture of external exposure and of the few decisions that actually matter — without jargon.
Findings prioritised by real exploitability: not every high severity is a high risk. With a concrete next step per finding. Ready for your ticket system from day one.
Documented scope, method and exclusions — including parked, third-party and unreachable assets — that an auditor can follow.
A penetration test proves whether selected systems can be exploited. The assessment first establishes what you expose at all — so that a subsequent pentest targets the right systems.
Not part of the assessment: Exploitation of vulnerabilities · authenticated testing with credentials · changes to target systems · scans inside your internal network
The report is a professional basis for your ISMS, internal risk analyses and contractual security requirements from your customers — and it supports these requirements:
| Standard | Relevant requirement | How the report supports it |
|---|---|---|
| ISO/IEC 27001:2022 | Annex A 5.9 Inventory of information and other associated assets · A 8.8 Management of technical vulnerabilities | Externally reachable assets inventoried and attributed; vulnerabilities identified, prioritised and documented with next steps. |
| NIST CSF 2.0 | ID.AM Asset Management · ID.RA-01 Vulnerabilities identified, validated and recorded | An outside-in view of the systems and services you expose; validated vulnerabilities recorded per asset. |
| NIS2 Directive (EU) | Art. 21(2)(a) risk analysis · (d) supply chain · (e) vulnerability handling | A dated, documented snapshot as a basis for risk analysis — extended to critical suppliers on request. |
| TISAX | Assessment preparation | Evidenced asset and vulnerability management for externally reachable infrastructure. |
The report replaces neither an audit nor a certification.
Every migration, every new service and every supplier creates new attack surface. We are happy to keep your external attack surface in view all year round as a managed service: the cycle repeats continuously and we report what is new — on request, for the attack surface of critical suppliers as well.
Domains, IP ranges and your group structure for the kick-off, plus a contact person who confirms the discovered assets with us. Nothing is installed.
It is non-invasive and not designed to affect production systems. Alongside passive techniques we run targeted active ones within the agreed scope — no exploits, no authenticated testing, no scans inside your internal network.
Yes. An outside-in analysis is not tied to a location. We define entities and their domains in the kick-off.
No. The assessment is a one-off service with a defined scope. Whether you move on to continuous monitoring with GrayScope is a separate decision.
Tell us your domains, IP ranges and legal entities — whether one or forty. From those we determine the externally reachable assets and agree the scope with you.
Tell us briefly what it’s about – we’ll get back to you within 1–2 business days.