Home / Continuous / Perimeter

Perimeter

What an attacker can reach without credentials, tested continuously. Perimeter answers what is exposed on the assets Surface found.

This module is part of the base package

Perimeter is paired with Surface in the base package. Together they cover your external footprint: what exists, and what is reachable on it. This is also where continuous delivery earns its keep, because the long unauthenticated jobs run to completion instead of being cut short by the end of a testing week.

What it covers

  • Reachable services and their versions, checked as they change
  • Exposed web content: admin panels, staging environments, directory listings, backup files
  • Remote access endpoints: VPN, exposed management interfaces, remote desktop and shell access
  • Transport security and certificate configuration across services, not only web
  • Mail and DNS configuration, including SPF, DKIM and DMARC
  • Known-vulnerable versions, verified as reachable rather than merely present
  • Long-running work a one-week test cannot finish: content and directory discovery, and password spraying at a safe rate where you have authorised it

How the work is carried out

A consultant directs this module and does the work that needs judgement, with automation carrying the continuous load between their passes. Your intervals are set during onboarding and recorded in the service agreement, because a schedule that suits one application would be wrong for a large, sprawling estate. What is fixed is the shape: a scheduled layer that runs the same checks on fixed intervals so change is visible, and an exploratory layer that a consultant directs based on what turns up. Reporting is monthly.

What the tooling handles

  • Keeps service and version identification current across in-scope ranges
  • Runs the long unauthenticated jobs to completion rather than to a deadline
  • Flags newly exposed services and ports between consultant passes

What our consultants do

  • Probe the reachable services directly, beyond what automated checks cover
  • Assess which exposed paths actually matter for your environment
  • Perform exploitation requiring judgement, where authorised
  • Confirm every finding, and rate it with business context

Every finding in this module is reproduced or confirmed by a consultant before it reaches you.

What you receive

  • Validated findings, each reproduced or confirmed by a consultant
  • A monthly written report, including what changed since the last one
  • Critical and high findings notified within one business day of validation
  • A current view of what is exposed across your estate
  • Verification of fixes once you have applied them

What is out of scope

  • Anything requiring credentials, which is the Network module for services and the Access module for applications
  • Internal lateral movement from inside your network, which is a separate engagement
  • Operational technology and industrial control systems, which we do not test
  • Denial-of-service testing, which is blocked by default
  • Shared hosting ranges, unless the provider has consented in writing

Prerequisites

Nothing runs until these are in place. We pause rather than proceed against an unconfirmed register.

  • Signed authorisation to test
  • IP ranges confirmed as yours, or written provider consent where they are shared
  • A confirmed asset register from the Surface module
  • Written agreement before any password spraying is attempted

Next module: Network