Technology & Threats — Pillar 3
You cannot protect what you cannot see. Asset intelligence and threat visibility start here.
786 Cyber maps your digital footprint, prioritises vulnerabilities by real-world exploitability, scans your cloud and web applications, and monitors external threats targeting your organisation — giving you the intelligence to act before attackers do.
Why visibility matters
Most organisations are attacked through assets they didn't know they had, vulnerabilities they didn't know were exposed, or exposure they never checked for.
The average CVE is exploited in under five days of disclosure. Credentials from old breaches circulate on the dark web long after anyone remembers the account exists. Typosquatted domains impersonate your brand while you're not looking. Technology & Threats is where 786 Cyber closes that visibility gap — across your assets, your cloud accounts, your web applications, your network, and the open internet. Nine capabilities, one posture score, no blind spots you haven't at least been told about.
"The organisations that recover fastest from security incidents are never the ones that were most surprised. They're the ones that had the most visibility — of their assets, their vulnerabilities, and the threats targeting them."
Asset Intelligence & Attack Surface Mapping
LiveSee everything that’s yours before an attacker finds it first.
Why we built it
Security programmes fail at the first step more often than any other — you can’t defend an asset you don’t know exists. Shadow IT, forgotten cloud instances and unmanaged subdomains are the single most common way organisations get attacked through something they didn’t know was theirs.
What it does
A single, always-current inventory across every asset type your business runs — hardware, endpoints, network devices, on-prem and cloud software, domains and cloud infrastructure. Import from CSV, sync software inventories, or add manually; every asset gets a criticality rating and a computed risk score, and the whole estate renders as a visual, grouped map you can filter by type, criticality, source or department.
The technology, named
This is attack surface mapping — continuously discovering and inventorying every system, service and domain you expose, rather than a point-in-time audit that’s stale the day after it’s run.
What it maps to
- Cyber Essentials (asset scope)
- ISO 27001 (A.5.9)
- PCI-DSS (CDE scoping)
- NIS2
Vulnerability Prioritisation
Live · recently enhancedStop triaging by CVSS score alone — know which vulnerabilities attackers are actually using right now.
Why we built it
A CVSS 9.8 that has never been exploited in the wild is less urgent than a CVSS 7.5 sitting on the CISA Known Exploited Vulnerabilities list. Most tools stop at severity, leaving teams triaging hundreds of "critical" findings with no way to tell which five matter this week.
What it does
Every finding is scored across four posture lanes — External Domain & IP, Application & Web, Internal Asset and Cloud — into one Technology Posture Score, then ranked by a blended priority combining base severity, real-world exploitability and the criticality of the affected asset. Each finding opens into a plain-English explanation of what it means and what to do, not just a CVE number.
The technology, named
Prioritisation is driven by EPSS (Exploit Prediction Scoring System — the probability a vulnerability will be exploited in the next 30 days) and CISA KEV (the US government’s catalogue of vulnerabilities confirmed as exploited in the wild). Adding EPSS and KEV on top of base severity is what "enhanced" means in the recent What’s New entry.
What it maps to
- Cyber Essentials
- ISO 27001 (A.8.8)
- PCI-DSS (Req. 11)
- NIS2
Cloud Security Posture Management (CSPM)
Live · newCatch cloud misconfigurations before they become the breach headline, not after.
Why we built it
The majority of cloud breaches trace back to misconfiguration, not a novel exploit — an open storage bucket, an over-permissioned IAM role, a security group left wide open. These are invisible to traditional vulnerability scanning because there’s no CVE for "someone left the door unlocked."
What it does
Connect an AWS, Azure or GCP account read-only — a small CloudFormation stack creates a SecurityAudit/ViewOnlyAccess role, gated by an ExternalId and revocable in one click — and 786 Cyber runs misconfiguration scanning against CIS Benchmarks, routing findings into the same prioritised queue as every other posture lane.
The technology, named
This is CSPM (Cloud Security Posture Management) — automated, continuous checking of cloud configuration against a benchmark, run here via Prowler against CIS and ISO benchmarks. Findings surface as misconfigurations and indicators of exposure, scored and prioritised.
What it covers
- Misconfigurations & indicators of exposure
- CIS Benchmarks
- AWS · Azure · GCP
Web Application Scanning
Live · newFind the security headers and web-layer weaknesses attackers probe for automatically — before they do.
Why we built it
Public-facing web applications are the most exposed thing most businesses run, and the most commonly targeted. Missing security headers, weak content policies and clickjacking exposure are all things automated scanners find in minutes — which means attackers find them in minutes too, if you don’t first.
What it does
Baseline web application scans run against every domain you register, checking for missing protective headers, content security policy gaps, clickjacking protection and other OWASP-catalogued web risks — each finding scored, mapped to compliance controls and explained in plain English with a remediation link.
The technology, named
Scanning runs on OWASP ZAP (Zed Attack Proxy) — the open-source web application security scanner maintained under the OWASP Foundation, run here in baseline/passive mode.
What it maps to
- PCI-DSS (Req. 6)
- ISO 27001 (A.8.26)
- Cyber Essentials Plus
Network & Asset Graph, Four Ways
Live · newSee how your estate actually connects — not a spreadsheet, a picture you can navigate.
Why we built it
Asset lists tell you what you have. They don’t tell you what talks to what, who has access to which system, or which single point of failure would take down the most connected part of your network. That’s a graph problem, not a list problem.
What it does
The same estate data renders four ways — by Assets (grouped by type), by People (who’s linked to what), by Network (typed connections, with the relationship labelled) and by Map (department-grouped) — with export to PNG. The Network view adds criticality-weighted risk rings, so the most critical, most connected assets are visually obvious rather than numerically ranked in a table.
The technology, named
This is a relationship graph (sometimes called an asset/dependency graph) — nodes are assets or people, edges are typed relationships, and the layout is force-directed so structurally important nodes surface visually rather than requiring a manual audit.
What it maps to
- ISO 27001 (A.5.9)
- NIS2 (network mapping)
- Incident-response readiness
External Threat & Exposure Monitoring
LiveKnow what the open internet already knows about you.
Why we built it
Attackers reconnoitre using public data before they ever touch your network — exposed ports, weak TLS configuration, breached credentials for sale, domains registered to impersonate your brand. All of it is visible to anyone who looks. Most businesses never look.
What it does
Continuous monitoring across your domains and IP ranges pulls from SSL Labs (certificate and protocol strength), Mozilla Observatory (header hygiene), Shodan (exposed services and ports), VirusTotal (reputation), DNSTwist (typosquat and look-alike domains) and crt.sh (certificate transparency) — plus dark web monitoring for credential exposure tied to your domains.
The technology, named
This is external attack surface monitoring combined with dark web / credential-exposure monitoring — the outside-in view of your organisation, built from open-source intelligence (OSINT) feeds rather than anything installed inside your network.
What it maps to
- Cyber Essentials
- NIS2
- Brand protection & fraud prevention
Software Inventory & SBOM
Live · newKnow exactly which CVEs affect which app, on which asset — with an export your customers or auditors can actually use.
Why we built it
"We have a vulnerability management programme" isn’t a satisfying answer to "prove it" — customers, auditors and regulators increasingly want a software bill of materials, not a summary. Per-app CVE matching also turns "patch everything" into "patch this specific outdated package on this specific server."
What it does
Every asset’s installed software inventory is matched against CVE databases (CPE-to-NVD matching) automatically, surfaced per-asset alongside recent scan history, and exportable as a CycloneDX-format SBOM for the whole estate or a single system.
The technology, named
An SBOM (Software Bill of Materials) is a machine-readable inventory of every software component running on a system — increasingly required in procurement and by regulations like the EU Cyber Resilience Act. Export format here is CycloneDX, one of the two dominant open SBOM standards (alongside SPDX).
What it maps to
- PCI-DSS
- ISO 27001 (A.8.8)
- Procurement / vendor onboarding
Capability Gap Analysis
LiveCompliance as capabilities you either have evidence for or don’t — not a thousand-item checklist.
Why we built it
Every framework ultimately depends on a much smaller set of underlying capabilities — MFA, cloud posture, web scanning, patching discipline. Answering the same question thirty different ways for thirty different frameworks is the single biggest source of compliance fatigue. Map the capability once, and every framework that depends on it inherits the answer.
What it does
Capabilities are marked Evidenced (detected from platform activity or a connected third-party tool), Unknown (not yet evidenced either way — flagged honestly rather than assumed) or Declared (documentation- or process-based). Gaps route automatically to the right fix — in-platform tooling, a documentation task, or a third-party partner — and the reverse view surfaces frameworks you’re already most of the way to satisfying.
The technology, named
This maps frameworks → controls → canonical controls (a normalised control taxonomy shared across frameworks) → underlying capabilities, which is what makes cross-framework credit possible — one capability, evidenced once, can satisfy the equivalent control in every framework that requires it.
What it maps to
- Every framework 786 Cyber supports — by design
PDF Scan Reports
Live · newHand a client, auditor or your own leadership a branded report in one click — not a screenshot.
Why we built it
Findings that live only inside a dashboard don’t get shared. MSPs need something branded to hand a client. In-house teams need something to attach to a board update or an insurer questionnaire. A PDF export turns a live scan into a document that travels.
What it does
Every web and cloud scan exports as a branded PDF — organisation name, scan target and date, severity breakdown table, and full per-finding detail with remediation guidance and reference links, ready to share as-is or attach to a compliance submission.
The technology, named
No single named standard here — this is plainly exportable, audit-ready PDF reporting; the value is the export/share workflow rather than an underlying protocol.
What it maps to
- PCI-DSS (Req. 11.3 — scan report retention)
- MSP client reporting
- Insurer & procurement questionnaires
Framework coverage
Every capability above is tagged and mapped automatically
Findings and controls from every capability on this page are tagged and mapped automatically to Cyber Essentials, Cyber Essentials Plus, ISO 27001, PCI-DSS 4.0.1, NIS2, NIST CSF 2.0 and DORA — plus the GCC frameworks covered under the Security Universe.
Cyber Essentials
Patch management and malware protection both require asset visibility.
ISO 27001
Annex A.5.9 and A.8.8 require documented asset inventory and vulnerability management.
PCI-DSS 4.0.1
Requirements 6, 11 and 12 require scanning, testing and a complete CDE inventory.
NIST CSF 2.0
The Identify and Detect functions depend on asset visibility and threat monitoring.
See your attack surface clearly.
Start free for 14 days — no card. Connect a domain and a cloud account and see real findings on day one.
Where to go next
Related reading
See it priced
Every capability on this page is included from Essentials up; CSPM and web scanning allowances scale by tier.
Pricing →