Measured against an independent standard

HackRisk and the NCSC EASM buyer’s guide

The NCSC publishes a guide for organisations buying external attack surface management. It sets out what these products should do and what to ask a supplier. Here is where HackRisk lands against it, including where it doesn’t.

Most vendor comparisons are written by the vendor and scored by the vendor. This one uses someone else’s criteria. Every row marked covered was checked against what the platform actually does, not against what we would like to say it does, and the gaps are listed with the same prominence as the rest.

Read the guide on ncsc.gov.uk

Visibility and insight

What the guide expects a product to show you about your own estate.

Visibility and insight: what the NCSC guide asks for, and what HackRisk does
What the guide asks forHackRiskDetail
Asset discoveryCoveredSubdomains, IP addresses and live endpoints, found from the domains you register with us and rediscovered on every scan.
Technology identificationCoveredThe software and frameworks each host is running, listed per asset. Versions are not identified.
DNS configuration visibilityCoveredRegistrar, nameservers, DNS records, DNSSEC status, related domains and domain expiry.
Web presence analysisCoveredHTTP status, page titles, web server, a screenshot of every live host, and discovered directories.
Certificate visibility and monitoringCoveredChain analysis, weak keys and signature algorithms, hostname mismatches, certificate transparency logs, and expiry warnings well before anything breaks.
Supplier identificationOn the roadmapNot derived from your attack surface today. Our supplier assurance programme is invitation-based.

Security analysis

What the guide expects a product to find wrong.

Security analysis: what the NCSC guide asks for, and what HackRisk does
What the guide asks forHackRiskDetail
Vulnerability assessmentCoveredActive validation rather than version inference: findings are confirmed by request and response, and carry CVE, CWE and CVSS.
Exposed admin and web surfaceCoveredLogin pages, admin panels, exposed configuration files and version control, found the way an attacker would look for them.
Threat intelligencePartialBreach and leaked-credential monitoring, including exposed secrets and session tokens. No KEV or EPSS feed.
Email security (SPF, DKIM, DMARC, MTA-STS)On the roadmapNot covered today.
Subdomain takeover detectionOn the roadmapNot covered today.
Unsupported or end-of-life softwareOn the roadmapNot covered today. Technologies are identified by name, not by version.
HTTP security headers and TLS configurationOn the roadmapNot covered today. Certificate hygiene is, and is listed above.

Supporting functions

What the guide expects around the findings themselves.

Supporting functions: what the NCSC guide asks for, and what HackRisk does
What the guide asks forHackRiskDetail
Dashboards and multiple viewsCoveredA risk dashboard per module, and six views of the attack surface including an asset graph and a geographic map.
History and trend trackingCoveredAssets added and removed between scans, and risk score history so you can show a direction of travel, not just a number.
Summarised reportingCoveredA per-scan PDF with selectable sections, plus a monthly report across every module you subscribe to.
Hierarchical access controlCoveredEight roles across staff, partners and resellers, with tenant isolation enforced on every request.
Workflow featuresCoveredFindings carry a status: acknowledge one and it drops out of your reports and your score, with a record of who did it and when.
Raw data exportCoveredCSV export of subdomains, endpoints and dark web findings.
Configurable prioritisationCoveredA severity-weighted score out of 1000, recalculated every six hours, with certificate trust folded into the same number.
Integrations outPartialSlack, Microsoft Teams and email. No SIEM or ticketing integration.
Integrations inOn the roadmapNo cloud provider or asset database import today. Domains are registered with us directly.

The questions the guide tells you to ask

Answered here so you don’t have to get us on a call to find out.

How is the attack surface discovered?

From the domains you register with us, expanded using public DNS and certificate transparency data. We do not go looking for domains you have not told us about.

How current is the data?

Reconnaissance runs weekly per domain. Certificates are analysed continuously. Breach intelligence arrives as it is found. You can also trigger a scan yourself, once a day.

How are risks prioritised?

By severity and by how many instances exist, combined into a score out of 1000 and recalculated every six hours. Certificate trust feeds the same score.

How is scope controlled?

At the domain level: a domain is either monitored or it is not. Excluding an individual asset from a scan is not available.

Is there confidence scoring on findings?

No. Findings carry severity and CVSS. You can acknowledge one to take it out of your reports and score, but you cannot mark it a false positive yourself.

See it against your own attack surface

A free report shows you what the covered rows above actually find on your domain. No card details, and no sales call unless you ask for one.

Get your free reportAsk us about a gap