Graydaxe · Cybersecurity services & tool vendor · Berlin

What is actually visible from outside?

Our own SaaS platform for Continuous Threat Exposure Management assesses your external attack surface non-invasively. We also give you a vendor-neutral view of the current state and effectiveness of your security tools — SIEM, XDR and vulnerability scanners — and show you the target state. Architecture consulting completes the portfolio.

Graydaxe Cybersecurity GmbH, Berlin · Data processed in the EU · 15+ years of security practice
EXTERNAL ATTACK SURFACE — CONTINUOUS DISCOVERY
412assets discovered
37not in the inventory
5critical
legacy-vpn.example.comSubdomain · unused since migration
Critical
staging.example.comTest environment · publicly reachable
High
api.example.comAPI gateway · attributed & confirmed
Reviewed
*.example.comCertificate · attributed & confirmed
Reviewed
Illustrative example · fictitious values · no customer data

Services

See, assess, improve

Four questions that build on each other — and four services that answer them.

The circle closes: what consulting changes, you see in the next run of the assessment.

No SIEM yet, or unsure which tools you actually need? We often join companies one step earlier — at the question of which solutions make sense and are cost-effective in the first place.


Compliance

ISO 27001, NIST CSF 2.0, NIS2

Results that are structured and traceable — usable for audits and evidence obligations.

StandardWhat our assessments deliver
ISO/IEC 27001A 5.9 · A 8.8 · A 8.15/8.16An inventory of externally reachable assets, technical vulnerabilities, logging and monitoring.
NIST CSF 2.0ID.AM · ID.RA-01 · DE.CMDiscovered assets, prioritised findings per asset, detection coverage.
NIS2 Directive (EU)Art. 21(2) a · d · eA dated snapshot for risk analysis, supply chain and vulnerability handling.

FAQ

Frequently asked questions

What does Graydaxe do?

We assess and improve company security from three perspectives: from outside (your attack surface — as a one-off report or continuously as a managed service), in the defence (the effectiveness of your SIEM and security tools with GrayCheck) and in the foundation (architecture & consulting).

Where is the best place to start?

With the one-off assessment of your external attack surface: a defined scope, predictable cost and a result report — with no ongoing contract. You then decide whether we take over monitoring.

What is the difference between the one-off assessment and monitoring?

The one-off assessment is a snapshot with a full result report — usable as evidence in an audit. Monitoring runs continuously and reports changes and new risks as they appear.

Do I need a security team of my own?

No. You can use every service yourself, with partial support, or fully operated by us — whether you have your own SOC, a small team, or none at all.

Do you work with companies outside Germany?

Yes. The attack surface assessment is performed from outside and is not tied to a location; subsidiaries in other countries can be included.


What would you like to know first?

What is reachable from outside? Whether your tools work? Or what the target architecture should look like?

Tell us where you stand — we will suggest the right starting point.


Newsletter

Stay up to date

Updates on our cybersecurity products and selected security insights — by email, with double opt-in, and you can unsubscribe at any time.

Subscribe to the newsletter →