Get a quote

Technology & Threats — Pillar 3

You cannot protect what you cannot see. Asset intelligence and threat visibility start here.

786 Cyber maps your digital footprint, prioritises vulnerabilities by real-world exploitability, scans your cloud and web applications, and monitors external threats targeting your organisation — giving you the intelligence to act before attackers do.

Applies to: All businesses with a digital footprint · Cloud-hosted organisations · MSPs managing client infrastructure

Most organisations are attacked through assets they didn't know they had, vulnerabilities they didn't know were exposed, or exposure they never checked for.

The average CVE is exploited in under five days of disclosure. Credentials from old breaches circulate on the dark web long after anyone remembers the account exists. Typosquatted domains impersonate your brand while you're not looking. Technology & Threats is where 786 Cyber closes that visibility gap — across your assets, your cloud accounts, your web applications, your network, and the open internet. Nine capabilities, one posture score, no blind spots you haven't at least been told about.

What organisations can't see hurts them
Unknown assets: Cloud instances spun up for a project and never decommissioned, subdomains pointing at unconfigured infrastructure, SaaS tools used without IT’s knowledge — each one an unmonitored entry point.
Unpatched vulnerabilities: The average time to exploit a newly published CVE is now under five days. Without systematic scanning and prioritisation, you patch after exploitation, not before.
Dark web exposure: Credentials from past breaches circulate and are used in credential-stuffing attacks long after anyone remembers the account exists.
Brand impersonation: Typosquatted domains and phishing sites impersonating your brand are usually discovered by customers — after the damage.
What complete visibility delivers
Reduced attack surface: A complete, current inventory lets you decommission forgotten infrastructure and close the unknown entry points most breaches exploit.
Prioritised remediation: Findings ranked by real-world exploitability and business impact — so the team fixes what matters, not what scores highest on CVSS.
Early warning intelligence: Credential-breach and dark web monitoring give advance warning before an exposure becomes an incident.
Framework compliance: Asset management and vulnerability scanning are explicit requirements in Cyber Essentials, ISO 27001, PCI-DSS, NIS2 and NIST CSF — mapped automatically.

"The organisations that recover fastest from security incidents are never the ones that were most surprised. They're the ones that had the most visibility — of their assets, their vulnerabilities, and the threats targeting them."

1

Asset Intelligence & Attack Surface Mapping

Live

See everything that’s yours before an attacker finds it first.

Why we built it

Security programmes fail at the first step more often than any other — you can’t defend an asset you don’t know exists. Shadow IT, forgotten cloud instances and unmanaged subdomains are the single most common way organisations get attacked through something they didn’t know was theirs.

What it does

A single, always-current inventory across every asset type your business runs — hardware, endpoints, network devices, on-prem and cloud software, domains and cloud infrastructure. Import from CSV, sync software inventories, or add manually; every asset gets a criticality rating and a computed risk score, and the whole estate renders as a visual, grouped map you can filter by type, criticality, source or department.

Asset Directory — 120 assets grouped by type, with live counts and the visual estate map.
Asset Directory — 120 assets grouped by type, with live counts and the visual estate map.

The technology, named

This is attack surface mapping — continuously discovering and inventorying every system, service and domain you expose, rather than a point-in-time audit that’s stale the day after it’s run.

What it maps to

  • Cyber Essentials (asset scope)
  • ISO 27001 (A.5.9)
  • PCI-DSS (CDE scoping)
  • NIS2
2

Vulnerability Prioritisation

Live · recently enhanced

Stop triaging by CVSS score alone — know which vulnerabilities attackers are actually using right now.

Why we built it

A CVSS 9.8 that has never been exploited in the wild is less urgent than a CVSS 7.5 sitting on the CISA Known Exploited Vulnerabilities list. Most tools stop at severity, leaving teams triaging hundreds of "critical" findings with no way to tell which five matter this week.

What it does

Every finding is scored across four posture lanes — External Domain & IP, Application & Web, Internal Asset and Cloud — into one Technology Posture Score, then ranked by a blended priority combining base severity, real-world exploitability and the criticality of the affected asset. Each finding opens into a plain-English explanation of what it means and what to do, not just a CVE number.

The dashboard — Technology Posture Score with all four posture lanes. (Finding detail with the CISA KEV badge: 05-finding-detail-cisa-kev.jpg, available for a second slot.)
The dashboard — Technology Posture Score with all four posture lanes. (Finding detail with the CISA KEV badge: 05-finding-detail-cisa-kev.jpg, available for a second slot.)

The technology, named

Prioritisation is driven by EPSS (Exploit Prediction Scoring System — the probability a vulnerability will be exploited in the next 30 days) and CISA KEV (the US government’s catalogue of vulnerabilities confirmed as exploited in the wild). Adding EPSS and KEV on top of base severity is what "enhanced" means in the recent What’s New entry.

What it maps to

  • Cyber Essentials
  • ISO 27001 (A.8.8)
  • PCI-DSS (Req. 11)
  • NIS2
3

Cloud Security Posture Management (CSPM)

Live · new

Catch cloud misconfigurations before they become the breach headline, not after.

Why we built it

The majority of cloud breaches trace back to misconfiguration, not a novel exploit — an open storage bucket, an over-permissioned IAM role, a security group left wide open. These are invisible to traditional vulnerability scanning because there’s no CVE for "someone left the door unlocked."

What it does

Connect an AWS, Azure or GCP account read-only — a small CloudFormation stack creates a SecurityAudit/ViewOnlyAccess role, gated by an ExternalId and revocable in one click — and 786 Cyber runs misconfiguration scanning against CIS Benchmarks, routing findings into the same prioritised queue as every other posture lane.

Connecting a cloud account — read-only, ExternalId-gated and revocable in one click.
Connecting a cloud account — read-only, ExternalId-gated and revocable in one click.

The technology, named

This is CSPM (Cloud Security Posture Management) — automated, continuous checking of cloud configuration against a benchmark, run here via Prowler against CIS and ISO benchmarks. Findings surface as misconfigurations and indicators of exposure, scored and prioritised.

What it covers

  • Misconfigurations & indicators of exposure
  • CIS Benchmarks
  • AWS · Azure · GCP
4

Web Application Scanning

Live · new

Find the security headers and web-layer weaknesses attackers probe for automatically — before they do.

Why we built it

Public-facing web applications are the most exposed thing most businesses run, and the most commonly targeted. Missing security headers, weak content policies and clickjacking exposure are all things automated scanners find in minutes — which means attackers find them in minutes too, if you don’t first.

What it does

Baseline web application scans run against every domain you register, checking for missing protective headers, content security policy gaps, clickjacking protection and other OWASP-catalogued web risks — each finding scored, mapped to compliance controls and explained in plain English with a remediation link.

Application & Web Posture findings — header and clickjacking issues, scored and mapped.
Application & Web Posture findings — header and clickjacking issues, scored and mapped.

The technology, named

Scanning runs on OWASP ZAP (Zed Attack Proxy) — the open-source web application security scanner maintained under the OWASP Foundation, run here in baseline/passive mode.

What it maps to

  • PCI-DSS (Req. 6)
  • ISO 27001 (A.8.26)
  • Cyber Essentials Plus
5

Network & Asset Graph, Four Ways

Live · new

See how your estate actually connects — not a spreadsheet, a picture you can navigate.

Why we built it

Asset lists tell you what you have. They don’t tell you what talks to what, who has access to which system, or which single point of failure would take down the most connected part of your network. That’s a graph problem, not a list problem.

What it does

The same estate data renders four ways — by Assets (grouped by type), by People (who’s linked to what), by Network (typed connections, with the relationship labelled) and by Map (department-grouped) — with export to PNG. The Network view adds criticality-weighted risk rings, so the most critical, most connected assets are visually obvious rather than numerically ranked in a table.

The Network topology view — 120 assets, subnet groupings, typed connection labels.
The Network topology view — 120 assets, subnet groupings, typed connection labels.

The technology, named

This is a relationship graph (sometimes called an asset/dependency graph) — nodes are assets or people, edges are typed relationships, and the layout is force-directed so structurally important nodes surface visually rather than requiring a manual audit.

What it maps to

  • ISO 27001 (A.5.9)
  • NIS2 (network mapping)
  • Incident-response readiness
6

External Threat & Exposure Monitoring

Live

Know what the open internet already knows about you.

Why we built it

Attackers reconnoitre using public data before they ever touch your network — exposed ports, weak TLS configuration, breached credentials for sale, domains registered to impersonate your brand. All of it is visible to anyone who looks. Most businesses never look.

What it does

Continuous monitoring across your domains and IP ranges pulls from SSL Labs (certificate and protocol strength), Mozilla Observatory (header hygiene), Shodan (exposed services and ports), VirusTotal (reputation), DNSTwist (typosquat and look-alike domains) and crt.sh (certificate transparency) — plus dark web monitoring for credential exposure tied to your domains.

Live findings — DNSTwist look-alike domain registrations and Shodan-detected exposed services.
Live findings — DNSTwist look-alike domain registrations and Shodan-detected exposed services.

The technology, named

This is external attack surface monitoring combined with dark web / credential-exposure monitoring — the outside-in view of your organisation, built from open-source intelligence (OSINT) feeds rather than anything installed inside your network.

What it maps to

  • Cyber Essentials
  • NIS2
  • Brand protection & fraud prevention
7

Software Inventory & SBOM

Live · new

Know exactly which CVEs affect which app, on which asset — with an export your customers or auditors can actually use.

Why we built it

"We have a vulnerability management programme" isn’t a satisfying answer to "prove it" — customers, auditors and regulators increasingly want a software bill of materials, not a summary. Per-app CVE matching also turns "patch everything" into "patch this specific outdated package on this specific server."

What it does

Every asset’s installed software inventory is matched against CVE databases (CPE-to-NVD matching) automatically, surfaced per-asset alongside recent scan history, and exportable as a CycloneDX-format SBOM for the whole estate or a single system.

Asset detail — Recent Scans (CPE match) and Installed Software, including the package behind a Log4Shell finding.
Asset detail — Recent Scans (CPE match) and Installed Software, including the package behind a Log4Shell finding.

The technology, named

An SBOM (Software Bill of Materials) is a machine-readable inventory of every software component running on a system — increasingly required in procurement and by regulations like the EU Cyber Resilience Act. Export format here is CycloneDX, one of the two dominant open SBOM standards (alongside SPDX).

What it maps to

  • PCI-DSS
  • ISO 27001 (A.8.8)
  • Procurement / vendor onboarding
8

Capability Gap Analysis

Live

Compliance as capabilities you either have evidence for or don’t — not a thousand-item checklist.

Why we built it

Every framework ultimately depends on a much smaller set of underlying capabilities — MFA, cloud posture, web scanning, patching discipline. Answering the same question thirty different ways for thirty different frameworks is the single biggest source of compliance fatigue. Map the capability once, and every framework that depends on it inherits the answer.

What it does

Capabilities are marked Evidenced (detected from platform activity or a connected third-party tool), Unknown (not yet evidenced either way — flagged honestly rather than assumed) or Declared (documentation- or process-based). Gaps route automatically to the right fix — in-platform tooling, a documentation task, or a third-party partner — and the reverse view surfaces frameworks you’re already most of the way to satisfying.

The Security Capabilities page — Evidenced / Unknown / Declared breakdown and reverse opportunities.
The Security Capabilities page — Evidenced / Unknown / Declared breakdown and reverse opportunities.

The technology, named

This maps frameworks → controls → canonical controls (a normalised control taxonomy shared across frameworks) → underlying capabilities, which is what makes cross-framework credit possible — one capability, evidenced once, can satisfy the equivalent control in every framework that requires it.

What it maps to

  • Every framework 786 Cyber supports — by design
9

PDF Scan Reports

Live · new

Hand a client, auditor or your own leadership a branded report in one click — not a screenshot.

Why we built it

Findings that live only inside a dashboard don’t get shared. MSPs need something branded to hand a client. In-house teams need something to attach to a board update or an insurer questionnaire. A PDF export turns a live scan into a document that travels.

What it does

Every web and cloud scan exports as a branded PDF — organisation name, scan target and date, severity breakdown table, and full per-finding detail with remediation guidance and reference links, ready to share as-is or attach to a compliance submission.

Scan Reports — exportable, branded reports with severity breakdown and per-finding remediation detail.
Scan Reports — exportable, branded reports with severity breakdown and per-finding remediation detail.

The technology, named

No single named standard here — this is plainly exportable, audit-ready PDF reporting; the value is the export/share workflow rather than an underlying protocol.

What it maps to

  • PCI-DSS (Req. 11.3 — scan report retention)
  • MSP client reporting
  • Insurer & procurement questionnaires

Every capability above is tagged and mapped automatically

Findings and controls from every capability on this page are tagged and mapped automatically to Cyber Essentials, Cyber Essentials Plus, ISO 27001, PCI-DSS 4.0.1, NIS2, NIST CSF 2.0 and DORA — plus the GCC frameworks covered under the Security Universe.

See your attack surface clearly.

Start free for 14 days — no card. Connect a domain and a cloud account and see real findings on day one.

Where to go next

See it priced

Every capability on this page is included from Essentials up; CSPM and web scanning allowances scale by tier.

Pricing →

Talk to us

Book a walkthrough with someone who knows the platform.

Book a walkthrough →