External monitoring
External monitoring is your outside‑in view — what an attacker can see and probe from the internet, checked automatically so you don’t have to remember to look.
What gets checked
Section titled “What gets checked”786 Cyber runs a stack of intelligence sources across your domains and internet‑facing assets:
| Check | What it finds |
|---|---|
| Exposed services & ports (Shodan) | Open ports, services and known CVEs on your public IPs |
| Look‑alike domains (DNSTwist) | Domains impersonating yours, used for phishing and fraud |
| Domain reputation (VirusTotal) | Whether your domains are flagged as malicious |
| Certificate & headers (SSL Labs, Mozilla Observatory) | TLS certificate and security‑header scoring |
| Subdomain discovery (crt.sh) | Subdomains you may have forgotten about |
| Credential breaches (Have I Been Pwned) | Your people’s details appearing in known breaches |
Sources return a clear available / unavailable / error status, so a source that can’t be reached is never shown as a false “all clear”.
When it runs
Section titled “When it runs”- At onboarding — an initial sweep as soon as your assets and domains are in.
- Weekly — an automatic re‑sweep (Monday mornings, UK time) to catch changes.
Findings flow into the External lane of your Posture dashboard and the Beware of this feed on your Overview.
Reviewing results
Section titled “Reviewing results”- Open Scan reports to see per‑asset detail for services, certificates and domain checks.
- New look‑alike domains, freshly exposed services and new breaches surface newest‑first so you can act on what’s changed.
Note on on‑demand scans: external sweeps are on the automatic schedule above. The Run scan button on the vulnerability dashboard re‑scores your existing findings rather than launching a brand‑new external scan.
Why it matters
Section titled “Why it matters”For everyday security: most incidents start with something exposed or impersonated on the internet. Continuous outside‑in checks mean you find out early — often before an attacker acts on it.
For compliance: external vulnerability scanning and monitoring of your internet‑facing footprint support Cyber Essentials Plus, NCA ECC and SAMA CSF requirements, and the weekly cadence evidences continuous monitoring rather than a once‑a‑year snapshot.
Next: Testing & Validation →