See.Tech

External cyber risk assessment

Assess Your Company's External Cyber Risk from Its Digital Footprint

An external cyber risk assessment examines the security weaknesses an organisation exposes to the public internet, using only information that is already publicly available.

See.Tech runs that assessment from a domain name. It identifies internet-facing vulnerabilities, leaked credentials, email authentication weaknesses, DNS and SSL/TLS problems, poor domain reputation and impersonating domains, then scores and ranks what it finds.

From a domain name

What can See.Tech assess from a domain?

This is the full assessment scope. Everything below is derived from publicly reachable information, with no access to the organisation being assessed.

Assessment areaWhat See.Tech looks at
Domain securityDNS records and configuration, open resolvers, zone transfers, and domain reputation against threat intelligence sources.
Email securitySPF, DKIM and DMARC records, and the MX configuration behind them.
Web securitySSL/TLS protocols and cipher strength, certificate validity and expiry, security headers, exposed directories, and outdated frameworks.
Internet-facing technologyPublicly reachable hosts and services, with vulnerabilities identified and scored using CVSS.
Identity exposureCredentials belonging to the domain that appear in breach corpora and dark web sources.
Brand and domain riskLookalike, typosquatted and impersonating domains registered against the brand.
Asset discoverySubdomains enumerated from passive DNS and certificate transparency logs, plus orphaned DNS records and unmanaged hosts.
Risk prioritisationA consolidated external risk score, with findings ranked by real-world severity.

How it differs

External assessment, internal audit, vulnerability scanning and penetration testing.

These four are routinely confused, and they answer different questions. Most security programmes need more than one.

ApproachQuestion it answersAccess required
External cyber risk assessmentWhat can an attacker see and target from outside, before they have any access?A domain name
Internal cyber auditDo our policies, controls and processes meet a standard or framework?Documentation, interviews, internal systems
Vulnerability scanningWhich known vulnerabilities exist on the hosts we manage?Agents or credentials, plus an asset inventory
Penetration testingCan these weaknesses actually be exploited, and how far does that go?Scope agreement and rules of engagement

See.Tech identifies and scores weaknesses; it does not exploit them. It complements the other three rather than replacing them.

Who uses it

What the assessment is used for.

Security teams

A prioritised remediation list

Findings arrive ranked by real-world severity using CVSS, so work starts with the change that removes the most risk rather than the first item alphabetically.

Executives and boards

One number, tracked over time

An exportable executive report and AI-generated executive briefing translate technical findings into a risk position a non-technical audience can act on.

Procurement and vendor risk

Supplier assessment without access

Because nothing is installed, a supplier or acquisition target can be assessed as easily as your own domain, before a contract is signed and for as long as they hold your data.

MSPs and MSSPs

Client assessments under your brand

Run assessments across client domains and deliver branded reports through the white-label capability. See the white-label cybersecurity assessment platform for MSPs.

White-label assessments for MSPs

Questions

External cyber risk assessment, answered.

What is an external cyber risk assessment?

An external cyber risk assessment identifies the security weaknesses an organisation exposes to the public internet, using only publicly available information. It covers internet-facing vulnerabilities, email authentication, DNS and TLS configuration, exposed credentials, domain reputation and brand impersonation, and prioritises what it finds by severity.

What can be discovered from a domain name?

A great deal. From a domain alone, See.Tech enumerates subdomains and internet-facing hosts, examines SPF, DKIM and DMARC, checks SSL/TLS and security headers, identifies vulnerable internet-facing software, checks domain reputation, searches breach and dark web sources for exposed credentials, and identifies lookalike or typosquatted domains.

How long does an assessment take?

First findings typically return within hours rather than the weeks a traditional audit requires. There is no deployment phase, because there is nothing to deploy.

Do we need to give See.Tech access to our systems?

No. The assessment is agentless and entirely external. There is no software to install, no appliance, no VPN, no API keys into your tenancy and no domain credentials. That constraint is what makes an assessment possible in hours, and what makes third-party assessment practical.

Is this the same as a penetration test?

No. See.Tech identifies and scores weaknesses using CVSS but never attempts to exploit them, and assessments are non-invasive. A penetration test proves exploitability. The findings from an external assessment are a well-evidenced starting point for scoping one.

Can we reassess after fixing the findings?

Yes. Rescans can be scheduled weekly or monthly, and change detection flags material changes between scans with a timestamp and severity. That is how the score is shown to move once remediation work has been done.

Can an MSP run this for its clients?

Yes. See.Tech supports white-label delivery for MSPs and MSSPs, with per-client branding, custom domain and branded reporting.

Start here

Assess your domain.

A See.Tech assessment starts from a domain name. Nothing is installed, no credentials change hands, and the first findings come back in hours.

Ready to see the threats before they strike?

Let's talk about protecting your brand, your customers, and your reputation. Our team is ready to show you exactly how See.Tech can help, starting today.