E

Advisory / External Exposure Review

What can the outside
world see about
your organisation today?

Before an attacker
looks, you should
know what they
will find.

The external surface of an organisation accumulates quietly. Subdomains from old projects. DNS records pointing at decommissioned infrastructure. TLS certificates about to expire or already weak. Email authentication policies configured once and never reviewed. Services accessible from the public internet that nobody remembers were exposed.

An attacker spending an hour on your domain will find all of it. This engagement produces the same view, before they do, with every finding explained in terms of the decision it requires.

The External Exposure Review is conducted entirely from the public internet. No credentials, no internal access, no agents. The same vantage point a third party would have when they start looking at your organisation. What they see is what this review maps.

Five areas.
One outside-in view.

The review covers the full external surface of your primary domain and any confirmed subsidiary domains. Scope is agreed at the start of the engagement. Nothing outside that boundary is assessed.

What this engagement
deliberately does not include.

The External Exposure Review is outside-in only. It does not include:

  • Internal network scanning or internal infrastructure assessment
  • Identity or access control review (Entra ID, Active Directory, permissions)
  • Cloud configuration assessment (Azure, Microsoft 365 tenant posture)
  • Penetration testing or active exploitation attempts
  • Vulnerability scanning of internal systems
  • Compliance audit or certification work

If the review surfaces findings that point toward internal identity or cloud risk as the more significant concern, the recommended next step will reflect that. The boundary is intentional and stated in the report.

What buyers
ask before engaging.

  • Q

    Do you need access to our systems or network?

    No. The entire review is conducted from the public internet using passive and active reconnaissance techniques available to any external party. You provide your primary domain and any known subsidiary domains. Nothing else is required before the engagement begins.

  • Q

    We already have a WAF and Cloudflare in place. Does that change what the review covers?

    No. Edge protection changes what is exploitable, not what is visible. DNS records, subdomains, certificate inventories, and email authentication are all assessable regardless of edge protection. The review maps visibility and exposure, not exploitability.

  • Q

    How does this differ from the Security Posture Baseline?

    The External Exposure Review goes deep on one surface: what is visible from outside your perimeter. The Security Posture Baseline covers four domains at a shallower level, including external exposure, identity, operational readiness, and M365 fundamentals. Choose the External Exposure Review if you already know external exposure is the question. Choose the Baseline if you are not yet sure where your risk is concentrated.

  • Q

    Automated attack surface scanners are cheap or free. Why does this cost £2,750?

    Scanners are cheap because they stop at detection. They produce findings without context: no prioritisation by business impact, no read on which exposures matter in your specific environment, and no accountability for what they miss. The review exists for the judgment layer: what each exposure means, what decision it requires, and what can safely be ignored. The output is a short list you can act on, not a hundred-item export that becomes someone's backlog.

  • Q

    Will anything be changed on our infrastructure during the review?

    No. The review is entirely passive and read-only from the public internet. No changes are made. No credentials are used. Nothing touches your systems.

  • Q

    What if the findings point toward identity or cloud risk rather than external exposure?

    That is a valid outcome. If the external surface is relatively clean but the review surfaces indicators of more significant risk elsewhere, the deliverable will say so plainly and name the appropriate next engagement. The engagement ends with an honest read, not a confirmation of the expected finding.

Begin here

Four working days.
No internal access.
£2,750 + VAT.

The first step is a short Discovery Call. Twenty minutes. Used to confirm scope, agree on the domain list, and set the start date.

The review is carried out personally by Alex Ulfeldt, the security engineer who operates Dettogni. No handoffs, no junior analysts.

If the External Exposure Review is not the right engagement for your situation, that will be the outcome of the call rather than a sale.

Book a Discovery Call See all advisory engagements

Dettogni advisory is fixed in scope, fixed in price, and designed to end.
United Kingdom · Remote engagements