Skip to main content
SurfaceShield Logo
SurfaceShield
SERVICES/EXTERNAL-SECURITY-ASSESSMENT

External Security Exposure Assessment

A meticulous, evidence-backed inspection of everything your company connects to the public internet. Designed specifically for small businesses to eliminate external blind spots without operational disruption.

Perspective
Public Internet
Zero credentials required.
Disruption Risk
Low-Impact Testing
Polite, throttled probes.
Deliverables
Report + Re-Test
Executive & technical proof.
Accountability
Single Lead
Experienced consultant direct.
Audit Scope Layers6 CORE TECHNICAL DOMAINS
01

Perimeter & Asset Discovery

STANDARDS: RFC 8482, RFC 1035, CA/B Forum Baseline Requirements

Passive DNS resolution, certificate transparency monitoring, apex domain enumeration, autonomous system correlation, and orphaned subdomain discovery.

02

External Network & Service Probing

STANDARDS: RFC 793, RFC 768, Rate-limited TCP SYN / Connect

Polite TCP/UDP port scanning across common administrative, remote management, database, and message broker ports. Service banner extraction and version verification.

03

Web Application Perimeter Analysis

STANDARDS: OWASP Top 10 API & Web Security Verification

Security header verification (CSP, HSTS, X-Content-Type-Options), session cookie hygiene (Secure, HttpOnly, SameSite), open directory indexing, and publicly reachable admin consoles.

04

Email Infrastructure & Anti-Spoofing

STANDARDS: RFC 7208 (SPF), RFC 6376 (DKIM), RFC 7489 (DMARC)

Syntax and alignment audit of SPF (Sender Policy Framework), DKIM public keys, and DMARC enforcement policies (p=none vs p=quarantine/reject). Identification of spoofing vectors.

05

Transport Layer Security (TLS/HTTPS)

STANDARDS: NIST SP 800-52r2, RFC 8446 (TLS 1.3)

Cryptographic cipher suite strength, deprecation check for TLS 1.0 and 1.1, certificate chain validity, revocation mechanism status (OCSP), and forward secrecy configuration.

06

Unintentional Information Disclosure

STANDARDS: CWE-200 Information Exposure Guidelines

Inspection for exposed repository directories (.git), environment secret configuration files (.env), unlinked database backups, Swagger/OpenAPI interactive consoles, and verbose debug logs.

Request Your Scoping Proposal

We review your initial public domains, compile an exact target schedule, and provide a fixed-scope engagement agreement with zero sales pressure.