Our own SaaS platform for Continuous Threat Exposure Management assesses your external attack surface non-invasively. We also give you a vendor-neutral view of the current state and effectiveness of your security tools — SIEM, XDR and vulnerability scanners — and show you the target state. Architecture consulting completes the portfolio.
Four questions that build on each other — and four services that answer them.
A non-invasive snapshot of your externally reachable assets — attributed, assessed and prioritised by real exploitability.
Your resultA report with a defined as-of date, your asset inventory and concrete mitigation measures — usable for ISO 27001 and NIS2.To the attack surface assessment →What is changing?Your attack surface shifts with every migration and every new service. We keep it in view all year round — operated by us.
Your resultA continuously current asset inventory, alerts on new risks and leaked credentials, regular reports.To attack surface monitoring →Does your defence see what happens?A vendor-neutral assessment of your SIEM, XDR and vulnerability scanners — through a questionnaire, workshops with your team and read access to the running system.
Your resultA maturity rating across ten domains, your largest gaps and a clear picture of the target state.To GrayCheck →Does the foundation hold?Experienced security consultants for project work — from target architecture through to operations, built on what assessment and monitoring actually show.
Your resultA target architecture, a risk assessment and an action plan — accompanied through implementation if you wish.To consulting →The circle closes: what consulting changes, you see in the next run of the assessment.
No SIEM yet, or unsure which tools you actually need? We often join companies one step earlier — at the question of which solutions make sense and are cost-effective in the first place.
Results that are structured and traceable — usable for audits and evidence obligations.
| Standard | What our assessments deliver |
|---|---|
| ISO/IEC 27001A 5.9 · A 8.8 · A 8.15/8.16 | An inventory of externally reachable assets, technical vulnerabilities, logging and monitoring. |
| NIST CSF 2.0ID.AM · ID.RA-01 · DE.CM | Discovered assets, prioritised findings per asset, detection coverage. |
| NIS2 Directive (EU)Art. 21(2) a · d · e | A dated snapshot for risk analysis, supply chain and vulnerability handling. |
We assess and improve company security from three perspectives: from outside (your attack surface — as a one-off report or continuously as a managed service), in the defence (the effectiveness of your SIEM and security tools with GrayCheck) and in the foundation (architecture & consulting).
With the one-off assessment of your external attack surface: a defined scope, predictable cost and a result report — with no ongoing contract. You then decide whether we take over monitoring.
The one-off assessment is a snapshot with a full result report — usable as evidence in an audit. Monitoring runs continuously and reports changes and new risks as they appear.
No. You can use every service yourself, with partial support, or fully operated by us — whether you have your own SOC, a small team, or none at all.
Yes. The attack surface assessment is performed from outside and is not tied to a location; subsidiaries in other countries can be included.
What is reachable from outside? Whether your tools work? Or what the target architecture should look like?
Tell us where you stand — we will suggest the right starting point.
Updates on our cybersecurity products and selected security insights — by email, with double opt-in, and you can unsubscribe at any time.
Subscribe to the newsletter →Tell us briefly what it’s about – we’ll get back to you within 1–2 business days.