Security teams
A prioritised remediation list
Findings arrive ranked by real-world severity using CVSS, so work starts with the change that removes the most risk rather than the first item alphabetically.
External cyber risk assessment
An external cyber risk assessment examines the security weaknesses an organisation exposes to the public internet, using only information that is already publicly available.
See.Tech runs that assessment from a domain name. It identifies internet-facing vulnerabilities, leaked credentials, email authentication weaknesses, DNS and SSL/TLS problems, poor domain reputation and impersonating domains, then scores and ranks what it finds.
From a domain name
This is the full assessment scope. Everything below is derived from publicly reachable information, with no access to the organisation being assessed.
| Assessment area | What See.Tech looks at |
|---|---|
| Domain security | DNS records and configuration, open resolvers, zone transfers, and domain reputation against threat intelligence sources. |
| Email security | SPF, DKIM and DMARC records, and the MX configuration behind them. |
| Web security | SSL/TLS protocols and cipher strength, certificate validity and expiry, security headers, exposed directories, and outdated frameworks. |
| Internet-facing technology | Publicly reachable hosts and services, with vulnerabilities identified and scored using CVSS. |
| Identity exposure | Credentials belonging to the domain that appear in breach corpora and dark web sources. |
| Brand and domain risk | Lookalike, typosquatted and impersonating domains registered against the brand. |
| Asset discovery | Subdomains enumerated from passive DNS and certificate transparency logs, plus orphaned DNS records and unmanaged hosts. |
| Risk prioritisation | A consolidated external risk score, with findings ranked by real-world severity. |
How it differs
These four are routinely confused, and they answer different questions. Most security programmes need more than one.
| Approach | Question it answers | Access required |
|---|---|---|
| External cyber risk assessment | What can an attacker see and target from outside, before they have any access? | A domain name |
| Internal cyber audit | Do our policies, controls and processes meet a standard or framework? | Documentation, interviews, internal systems |
| Vulnerability scanning | Which known vulnerabilities exist on the hosts we manage? | Agents or credentials, plus an asset inventory |
| Penetration testing | Can these weaknesses actually be exploited, and how far does that go? | Scope agreement and rules of engagement |
See.Tech identifies and scores weaknesses; it does not exploit them. It complements the other three rather than replacing them.
Who uses it
Security teams
Findings arrive ranked by real-world severity using CVSS, so work starts with the change that removes the most risk rather than the first item alphabetically.
Executives and boards
An exportable executive report and AI-generated executive briefing translate technical findings into a risk position a non-technical audience can act on.
Procurement and vendor risk
Because nothing is installed, a supplier or acquisition target can be assessed as easily as your own domain, before a contract is signed and for as long as they hold your data.
MSPs and MSSPs
Run assessments across client domains and deliver branded reports through the white-label capability. See the white-label cybersecurity assessment platform for MSPs.
Questions
An external cyber risk assessment identifies the security weaknesses an organisation exposes to the public internet, using only publicly available information. It covers internet-facing vulnerabilities, email authentication, DNS and TLS configuration, exposed credentials, domain reputation and brand impersonation, and prioritises what it finds by severity.
A great deal. From a domain alone, See.Tech enumerates subdomains and internet-facing hosts, examines SPF, DKIM and DMARC, checks SSL/TLS and security headers, identifies vulnerable internet-facing software, checks domain reputation, searches breach and dark web sources for exposed credentials, and identifies lookalike or typosquatted domains.
First findings typically return within hours rather than the weeks a traditional audit requires. There is no deployment phase, because there is nothing to deploy.
No. The assessment is agentless and entirely external. There is no software to install, no appliance, no VPN, no API keys into your tenancy and no domain credentials. That constraint is what makes an assessment possible in hours, and what makes third-party assessment practical.
No. See.Tech identifies and scores weaknesses using CVSS but never attempts to exploit them, and assessments are non-invasive. A penetration test proves exploitability. The findings from an external assessment are a well-evidenced starting point for scoping one.
Yes. Rescans can be scheduled weekly or monthly, and change detection flags material changes between scans with a timestamp and severity. That is how the score is shown to move once remediation work has been done.
Yes. See.Tech supports white-label delivery for MSPs and MSSPs, with per-client branding, custom domain and branded reporting.
Start here
A See.Tech assessment starts from a domain name. Nothing is installed, no credentials change hands, and the first findings come back in hours.
Let's talk about protecting your brand, your customers, and your reputation. Our team is ready to show you exactly how See.Tech can help, starting today.