- Home
- Guides
Guides
Reference pages for people making a decision rather than reading about a product: scoring rubrics, vendor questions, pricing-model literacy and UK procurement checks. Written to be usable against any vendor, including ours.
Buyer's guide · September 2026
External Attack Surface Management: UK Buyer's Guide
A vendor-neutral reference for UK SMEs and MSPs: what EASM is and is not, a weighted scoring rubric you can apply to any vendor, the questions to ask on a demo call, the four pricing models in this market, and the UK-specific checks (data residency, Cyber Essentials scope, NIS applicability).
Operating manual · September 2026
The MSP Playbook for External Attack Surface Monitoring
How a UK MSP actually runs external monitoring as a managed service: what to include in the service, four commercial models and the margin mechanics behind them, written authorisation to scan, a nine-step onboarding runbook, triage ownership, monthly reporting that shows change rather than counts, and the client objections you will meet. Tool-neutral.
Reference guide · September 2026
Cyber Essentials and CE Plus: What Is Actually Assessed Externally
The neutral reference on the internet-facing half of Cyber Essentials: which of the five technical control themes an outside view can evidence, what the CE Plus test cases add, how external scope is defined and why discovery comes first, the findings that cause trouble at assessment, and a pre-assessment checklist. Sourced to NCSC and IASME throughout.
Reference guide · September 2026
NIS2 and Externally-Facing Controls: What It Means for UK Firms
NIS2 does not apply to the UK -- the UK runs the NIS Regulations 2018, and most vendor content gets this wrong. This guide leads with that distinction, then sets out the two genuine routes by which UK firms are affected, which of the directive's ten risk-management measures are externally observable, the 24-hour and 72-hour reporting timelines, and what to actually do. Sourced to EUR-Lex by article.
Response guide · September 2026
Subdomain Takeover Remediation: A Response Guide
What to do when you find a dangling DNS record pointing at a deprovisioned service: the lifecycle that creates one, how to confirm it read-only without exploiting it and where the legal line sits, triage by class of hosting provider rather than by vendor, the delete-reclaim-repoint decision, verifying the fix including the trust the hostname still holds, and the prevention that closes the class.
Looking for first-party exposure data instead? See Research. For definitions of individual terms, see the glossary.