External Exposure Review
What the review examines
Each area is assessed from the public internet with no internal access. Findings are prioritised by business impact, not technical severity score. The question for each finding is: what does this expose, and what decision does it require?
£2,750
Fixed price · + VAT
Delivered in 4 working days
What is assessed
- DNS posture and delegation risk Authoritative records, delegation chain integrity, dangling DNS pointers, and whether internal infrastructure is inadvertently visible through DNS responses. Delegation misconfigurations are a frequent source of subdomain takeover risk.
- TLS and certificate hygiene Certificate inventory across all discovered subdomains, expiry exposure, weak cipher configuration, and protocol version inconsistencies. An expiring certificate on a low-traffic subdomain can take down a critical service without warning.
- Email authentication and impersonation surface SPF record accuracy and alignment, DKIM configuration and key strength, DMARC policy and enforcement level. Where gaps exist, the practical impersonation surface is named plainly: who could send email appearing to come from your domain, and what would it take.
- Subdomain and asset discovery Discovery of subdomains, forgotten assets, and services attached to your primary domain that may not appear in any internal inventory. Abandoned assets with live DNS records remain your attack surface regardless of whether anyone remembers they exist.
- Unintentionally exposed services Services accessible from the public internet that should not be, or that expose more than intended. Administrative interfaces, staging environments, internal tooling, and API endpoints with insufficient access controls.
You receive
- Prioritised findings report Each finding ranked by business impact. Not by CVSS score or framework severity. By the practical consequence of leaving it unaddressed and the effort required to resolve it.
- Concrete remediation guidance What to address first, what becomes possible once each item is resolved, and which findings can be deprioritised without material risk. Written for the person who will action it, not for a CISO who needs to present it.
- Walkthrough session (60 minutes) A working call to go through findings, answer questions, and align on next steps. Both technical and non-technical attendees can attend. The session is a working conversation, not a presentation.
- Standalone written report The deliverable belongs to you. It can be shared with an IT provider, board, or legal team without any dependency on Dettogni.