Know what attackers can see

External Attack Surface Management

Expose · See and Prioritise Your External Exposure

Your internet-facing estate changes every day. Expose continuously discovers exposed assets, leaked credentials and relevant threat activity—then turns that signal into a clear, prioritised view of what needs action.

Your outside-in view

Identify internet exposure constantly. Not annually.

Most organisations expose more than their asset register shows. Forgotten domains, temporary cloud services, open ports and leaked credentials can remain visible to attackers while ownership and patching fall behind. Expose combines automated discovery, threat and dark-web intelligence with human security judgement. You see what is exposed, why it matters, who owns it and whether the risk has actually been closed.

  • 01Find unknown internet-facing assets before an attacker does
  • 02Detect exposed services, certificate issues and leaked credentials
  • 03Prioritise changes using threat relevance and business context
  • 04Track remediation and evidence a reduction in external exposure

One Expose view

Three ways to see where your organisation is exposed.

Expose connects what your organisation exposes with the external evidence that changes its urgency. The three layers work together rather than creating separate queues.

01

See what is exposed

Attack-surface discovery continuously identifies domains, subdomains, IPs, cloud services, APIs, technologies, certificates and open ports—including assets your inventory has missed.

02

See what is being targeted

Threat intelligence adds relevant actor, campaign and infrastructure context so your team can distinguish a credible threat to your sector and technology from a generic headline.

03

See what is already leaked

Dark-web intelligence monitors authorised brand, domain, email and executive identifiers for leaked credentials, data exposure, access-broker listings and credible criminal chatter.

How Pentesys works

From unknown exposure to verified closure.

01

Discover

Continuously map your public-facing footprint.

02

Enrich

Add ownership, technology and threat context.

03

Prioritise

Separate urgent exposure from background noise.

04

Close

Assign, remediate and verify the fix in one view.

Continuous loopClose · rescan · rediscoverRescan after closure

What you receive

A working record of what is exposed, what matters and whether the agreed action has been completed.

Ready to get started

From alerts to owned exposure

How much visibility do you need?

A vulnerability scanner, an EASM platform and a managed exposure programme provide different levels of context and ownership. The right choice depends on whether your team needs more alerts—or a clearer route to closure.

CapabilityPentesys managed ExposeBasic vulnerability scannerUnmanaged EASM platform
Unknown asset discoveryContinuous, with ownership supportLimited to supplied targetsCore capability
Exposure monitoringContinuous discovery and change trackingScheduled scansContinuous or frequent
Vulnerability signalsPrioritised with exposure contextCore capabilityCommonly included
Threat intelligenceRelevant actors, campaigns and infrastructureNormally absentDepends on the platform
Dark-web intelligenceConnected to authorised identifiersNormally absentMay be a separate module
Human validationConsultant reviewed before escalationCustomer-ledUsually customer-led
Business-risk prioritisationContext, reachability and consequencePrimarily technical severityPrimarily platform risk scoring
Remediation workflowFinding, owner, action and evidence connectedOften exported separatelyPlatform dependent
Closure and rescanTracked through verified closure and rediscoveryRescan confirms scanner resultPlatform dependent
Best suited toTeams needing an owned route from discovery to closureKnown systems requiring routine checksTeams with internal capacity to operate the platform

Need visibility without another raw feed?Tell us what you currently monitor and where ownership breaks down. We’ll recommend the most proportionate starting scope.

Discuss the right Expose model

A proportionate starting point

Start with visibility. Add testing when it becomes useful.

All plans use a 12-month agreement. Pay monthly at the standard rate or pay annually and save 5%. Prices exclude VAT and use the published starting scopes below.

CONTINUOUS VISIBILITY

Expose

£295/month

For organisations establishing a reliable, continuously updated view of their external attack surface.

  • 1 root domain and up to 25 internet-facing assets
  • Continuous discovery and weekly exposure scan
  • Live portal, prioritised findings and change alerts
  • Monthly exposure summary
VISIBILITY + REPEATABLE TESTING

Expose + Validate*

£2,195/month

For growing organisations that need continuous monitoring plus scheduled testing of the systems that matter.

  • 3 root domains and up to 100 internet-facing assets
  • Daily change detection and weekly vulnerability scan
  • 4 AI-led cycles and 1 human-verification cycle a year
  • Retesting, monthly summaries and quarterly review
ADVANCED ASSURANCE

Expose + Validate + Adversary*

Tailored scope

Add human-led penetration testing and realistic red-team exercises to continuous exposure monitoring. Prove which weaknesses are exploitable and how well your organisation detects and responds.

  • Continuous external visibility and prioritisation
  • Human-led penetration testing and retesting
  • Threat-led adversary and red-team exercises
  • Connected evidence, remediation and executive reporting

* The guided trial provides access to the Expose workflow in the Pentesys Portal only. A Pentesys expert will discuss your Validate penetration test or Adversary red-team or purple-team requirements with you. These can be configured in the Pentesys Portal and made ready for activation once customer onboarding is complete.

Anonymous customer outcome

From scattered visibility to a measurable reduction in critical exposure.

An enterprise technology organisation needed one owned view of a large, changing internet-facing estate. Continuous discovery consolidated more than 200 domains, while consultant validation filtered noise and focused remediation on credible, high-priority exposure.

“The combination of continuous visibility and human validation gave our teams a clearer route from discovery to an evidenced fix.”
Discuss a similar outcome
78%fewer critical exposures
96%validation accuracy
faster remediation
200+domains continuously monitored

What Expose monitors

The exposure signals your team needs—without another raw feed.

Automated coverage provides breadth. Consultant review adds ownership, relevance and a practical next action before material findings reach your team.

01

Assets and shadow IT

Domains, subdomains, IP ranges, cloud resources, APIs and public services discovered from multiple external sources.

02

Technology and vulnerabilities

Technology and version fingerprinting, unsupported components and correlation with known vulnerabilities.

03

Ports, services and certificates

Risk-scored open ports, exposed administrative services, SSL/TLS health and certificate-expiry monitoring.

04

Credentials and data leaks

Corporate credentials, stealer logs, breach records and credible data exposure tied to authorised identifiers.

05

Threat actors and campaigns

Relevant tactics, infrastructure and active campaigns filtered for your sector, geography and technology.

06

Change and risk trend

New-asset alerts, material exposure changes and a historical view showing whether external risk is reducing.

One portal across every product

The Pentesys Portal is the shared working view. Every Pentesys service feeds the same route from evidence to action.

The Pentesys Portal is not limited to attack-surface monitoring. It supports Foundation readiness, Expose discovery, Validate testing and Adversary exercises—keeping scope, evidence, findings, owners and progress connected.

01 · EXPOSEContinuous view
PentesysILLUSTRATIVE CONTINUOUS VIEWEXPOSE
YOUR SECURITY, ONE CLEAR VIEW

Good morning, Mathew.

EXPOSE7

assets need review

VALIDATE4

open findings

REMEDIATION68%

findings closed

Exposure trendLAST 90 DAYS
Next priorityHUMAN VERIFIED
Review unknown cloud asset

Owner unassigned · seen 2h ago

Illustrative finding
02 · FOUNDATIONReadiness view
FOUNDATIONCyber Essentials readiness
Cyber Essentials74%ready to submit
18controls complete4actions remaining9evidence items

Next action: confirm secure configuration evidence

03 · VALIDATEResults view
VALIDATEPenetration test results
1Critical3High7Medium8Closed
H
Broken access controlHuman verified · remediation assigned
M
Security header weaknessRetest scheduled
04 · ADVERSARYBuilder view
ADVERSARYDefine an engagement
PRIMARY OBJECTIVETest access to sensitive data
Phishing simulationExternal intrusionPhysical accessCloud compromiseSocial engineeringPersistence testing
3 actions selectedReview scope →
Explore the Pentesys Portal

FAQ

Expose monitoring, without the noise.

What is External Attack Surface Management?

External Attack Surface Management, or EASM, is the continuous discovery, inventory and monitoring of internet-facing assets such as domains, subdomains, IP addresses, cloud services, APIs and exposed applications. It helps organisations find changes and unknown assets before attackers can exploit them.

How is Expose different from a vulnerability scanner?

A vulnerability scanner checks known systems for technical weaknesses. Expose first discovers what is actually exposed, then adds ownership, technology, threat and business context. Pentesys consultants review material findings so teams receive prioritised exposure rather than an unfiltered scanner feed.

Does Expose include threat intelligence?

Yes. Relevant information about active campaigns, threat actors, tactics and infrastructure is used to help explain which exposures deserve attention. The aim is focused intelligence for your organisation, not a generic stream of indicators.

What does dark-web monitoring cover?

Expose can monitor breach data, stealer logs, criminal forums, leak sites, paste sites and selected chat channels for authorised identifiers such as company domains, email patterns, brands and executive names. Potential matches are reviewed before they are escalated.

Will Expose find every asset or leaked record?

No monitoring service can guarantee complete coverage of the internet or closed criminal communities. Expose uses multiple discovery and intelligence sources, repeats monitoring over time and clearly distinguishes verified findings from incomplete or uncertain evidence.

What happens when Expose finds something important?

The finding is reviewed, risk-rated and published with evidence, ownership context and recommended action. Your team can then track remediation and retain a record of closure, with Validate available where deeper technical proof is required.

Trusted experience

Supporting recognised organisations.

Royal Ballet and Opera logo
Royal Ballet and Opera
Rightmove logo
Rightmove
Fortis logo
Fortis
Orange logo
Orange
Small Luxury Hotels of the World logo
Small Luxury Hotels of the World
AI Incumbency logo
AI Incumbency
Pentesys has continuously performed admirably during our collaboration, giving us faith in their knowledge. They delivered work that above our expectations by approaching each project with a deep understanding of our specifications. Their team demonstrated a remarkable degree of proficiency by effectively pinpointing weaknesses and offering practical suggestions to reduce possible hazards.
MDFortis Cyber Security Limited
Unlike previous pentests that produced generic outputs, this engagement gave us clear, prioritised actions with real-world attack scenarios. The platform visibility into assets, vulnerabilities and remediation progress has helped us mature our security posture significantly. The team were professional, responsive, and genuinely cared about improving our security rather than just ticking a box.
Head of ITHealthcare Technology Company
The red team and external attack surface management work highlighted blind spots we didn't know existed. What stood out was the strategic guidance alongside the technical delivery – helping us shape a longer-term security roadmap rather than a one-off engagement. This felt like a partnership, not just a transactional assessment.
CISOSaaS Provider
Pentesys has continuously produced excellent work. Their group demonstrated extraordinary technical proficiency by spotting crucial flaws and offering clever fixes that greatly strengthened our security stance. Their meticulous approach and attention to detail ensured that every facet of the project was covered in full.
IT Security SpecialistRightmove PLC
We engaged Pentesys and the team for a complex penetration test and adversary simulation. The quality of the technical findings, realism of the attack paths, and clarity of reporting were outstanding. The recommendations were practical and mapped clearly to business risk, which made board-level conversations much easier. We've since built Pentesys into our ongoing security assurance programme.
CTOUK Financial Services Provider

Assurance that joins up

Recognised expertise, built around your environment.

Pentesys combines independent assurance, qualified testers and practical integration with the systems your teams already use.

Ready to apply this to your environment?

Make your external exposure visible and actionable.

Tell us what you need to understand, test or prove. We'll recommend the smallest useful next step and prepare the right specialist for the conversation.

Request an exposure review