Outside-In Security Assessment
A real assessment, shown in full. We removed the company name and its hostnames. Nothing else. That is the discretion you would get too.
One critical exposure, an actively-exploited software vulnerability running on your public edge, is open to anyone scanning today and needs a verified fix this week. Beneath it, five exploitable security gaps (open DNS records, unencrypted mail ports, and exposed source maps) sit on a two-week clock, and one customer-visible service error (broken certificates) is on a same-week patch. All visible to any underwriter, enterprise buyer, or investor who looks.
40 distinct findings · 574 checks across 24 internet-facing assets · 1 critical + 1 customer-visible item on a this-week fix
Most outside-in scanners inherit the inflation of CVSS scoring, a finding with a high CVSS gets flagged Critical regardless of whether anyone has a working exploit. We require a verified working exploit path (CISA KEV listing, public exploit, or high EPSS) AND a severe outcome class for any Critical or High. Six of the seven raw "criticals" were unweaponized CVEs or non-compromise-class findings and dropped to their honest tier, one survived, with a verified exploit path AND a severe outcome, and stays Critical. Every raw finding is still in the report below, rated honestly. Less noise, more signal.
Four questions every outside reviewer asks about you. Each category reflects its single worst finding, never an average.
24 assets checked. Each shows its single worst active finding; the 16 with one are listed here.
| Asset | Owner | Status | Worst finding |
|---|---|---|---|
| api.northwind.com | Network Ops | Critical | Runs software with a publicly known, exploited flaw (CISA KEV) |
| app.northwind.com | Network Ops | Critical | Runs software with a publicly known, exploited flaw (CISA KEV) |
| connect.northwind.com | Network Ops | Critical | Runs software with a publicly known, exploited flaw (CISA KEV) |
| portal.northwind.com | Network Ops | Critical | Runs software with a publicly known, exploited flaw (CISA KEV) |
| gateway.northwind.com | Network Ops | Critical | Runs software with a publicly known, exploited flaw (CISA KEV) |
| www.northwind.com | Engineering | High | Source maps expose front-end code and internal addresses |
| northwind.com | DNS Admin | High | Anyone can download a full map of your systems |
| email.northwind.com | DNS Admin | High | Exposed on the public DNS map |
| isend.northwind.com | Network Ops | High | Unencrypted mail port open to the internet |
| mail.northwind.com | Network Ops | High | Unencrypted mail port open to the internet |
| archive.northwind.com | DNS Admin | Attention | DNS answers are not cryptographically signed |
| blog.northwind.com | DNS Admin | Attention | DNS answers are not cryptographically signed |
| careers.northwind.com | DevOps | Attention | Customer-visible TLS warning, fix this week |
| docs.northwind.com | DevOps | Attention | Missing browser-protection headers |
| object-store · cloud | Cloud Admin | Healthy | Storage bucket verified private ✓ |
| northwind · code repo | Engineering | Healthy | Source repositories verified private ✓ |
The items to act on first: one critical exposure (Critical · this week), the exploitable security gaps (High · 2 weeks: open DNS, unencrypted mail, exposed source maps), and one customer-visible service error (Attention severity but on a fix-this-week override).
Grouped by when to act. Severity drives the deadline (Critical = this week, High = 2 weeks, Attention = 1 month). Customer-visible service breakage gets a one-week override even at Attention severity.
For your CTO or technical reviewer. Every finding above traces directly to scanner evidence below.
| Asset | Check | Signal / Evidence | Confidence |
|---|---|---|---|
| www.northwind.com | SOURCEMAP_EXPOSED | Public source maps reveal front-end code and internal addresses | V1 |
| www.northwind.com | CVE_KEV_EXPLOITED | Server version matches a CISA KEV-listed CVE with a public exploit | V1 |
| northwind.com | DNS_ZONE_TRANSFER | Unauthenticated AXFR returned the full zone | V1 |
| www, support, blog | OPEN_MAIL_PORT | Ports 110 and 143 accepted public TCP connections | V1 |
| blog.northwind.com | BROKEN_TLS | Certificate SAN omits subdomain; name-mismatch on handshake | V1 |
| email.northwind.com | BROKEN_TLS | TLS handshake failed before completion | V1 |
| Asset | Check | Signal / Evidence | Confidence |
|---|---|---|---|
| docs.northwind.com | BROKEN_TLS | Non-compliant TLS negotiation response | V1 |
| email, jobs subdomains | DNS_ZONE_TRANSFER | Same misconfiguration on two further zones | V1 |
| www.northwind.com | MISSING_CSP | No Content-Security-Policy header observed | V1 |
| docs.northwind.com | BANNER_LEAK | Server response returns version string in cleartext | V1 |
| support.northwind.com | OUTDATED_JQUERY | Script files reference jQuery 3.5.1 | V1 |
| northwind.com | SPF_SOFTFAIL | SPF uses ~all; DMARC separately enforced | V1 |
| northwind.com | DNSSEC_DISABLED | No DNSSEC signature records on the zone | V1 |
| object-store · cloud | SECURE_STORAGE | Unauthenticated access returns HTTP 403, verified locked | V1 |
| Apache host | SOFTWARE_VULN_CVE | Version banner matched to moderate CVEs; none CISA KEV-listed | V2 |
| Edge / all domains | WAF_SIGNAL_ABSENT | Probe completed with no WAF block, absence of signal, not proof of absence | V3 |
This report covers everything visible from the public internet. But the risks that tend to cause the most damage are inside, in your cloud configuration, your access controls, your employees' habits. Those require authorized access. Here's what we couldn't see:
Dark-web credential exposure, leaked passwords, active breach data, requires dedicated threat-intelligence feeds. Not visible from the outside.
Access-control reviews need internal access. Overprivileged accounts and former employees with still-active credentials are invisible from outside.
We confirmed your storage bucket is locked from the outside. What we cannot see: misconfigured IAM roles, over-permissive security groups, missing logging, all require an authorized cloud-configuration review.
Authenticated scanning surfaces logic flaws, injection vulnerabilities, and broken access controls that are invisible to anyone without a login.
An authorized inside-out assessment typically surfaces 2–3× more findings than the outside view alone. But the outside-in view is what your underwriter, customer, or acquirer sees first. That's where to start.
Get your report →Yours in 24 hours. A full outside-in assessment of your own company, prioritized and exactly this thorough.
Get your Security Mirror · $495 →Delivered in 24 hours · No internal access required · No surprises.