HackRisk and the NCSC EASM buyer’s guide
The NCSC publishes a guide for organisations buying external attack surface management. It sets out what these products should do and what to ask a supplier. Here is where HackRisk lands against it, including where it doesn’t.
Most vendor comparisons are written by the vendor and scored by the vendor. This one uses someone else’s criteria. Every row marked covered was checked against what the platform actually does, not against what we would like to say it does, and the gaps are listed with the same prominence as the rest.
Read the guide on ncsc.gov.ukVisibility and insight
What the guide expects a product to show you about your own estate.
| What the guide asks for | HackRisk | Detail |
|---|---|---|
| Asset discovery | Covered | Subdomains, IP addresses and live endpoints, found from the domains you register with us and rediscovered on every scan. |
| Technology identification | Covered | The software and frameworks each host is running, listed per asset. Versions are not identified. |
| DNS configuration visibility | Covered | Registrar, nameservers, DNS records, DNSSEC status, related domains and domain expiry. |
| Web presence analysis | Covered | HTTP status, page titles, web server, a screenshot of every live host, and discovered directories. |
| Certificate visibility and monitoring | Covered | Chain analysis, weak keys and signature algorithms, hostname mismatches, certificate transparency logs, and expiry warnings well before anything breaks. |
| Supplier identification | On the roadmap | Not derived from your attack surface today. Our supplier assurance programme is invitation-based. |
Security analysis
What the guide expects a product to find wrong.
| What the guide asks for | HackRisk | Detail |
|---|---|---|
| Vulnerability assessment | Covered | Active validation rather than version inference: findings are confirmed by request and response, and carry CVE, CWE and CVSS. |
| Exposed admin and web surface | Covered | Login pages, admin panels, exposed configuration files and version control, found the way an attacker would look for them. |
| Threat intelligence | Partial | Breach and leaked-credential monitoring, including exposed secrets and session tokens. No KEV or EPSS feed. |
| Email security (SPF, DKIM, DMARC, MTA-STS) | On the roadmap | Not covered today. |
| Subdomain takeover detection | On the roadmap | Not covered today. |
| Unsupported or end-of-life software | On the roadmap | Not covered today. Technologies are identified by name, not by version. |
| HTTP security headers and TLS configuration | On the roadmap | Not covered today. Certificate hygiene is, and is listed above. |
Supporting functions
What the guide expects around the findings themselves.
| What the guide asks for | HackRisk | Detail |
|---|---|---|
| Dashboards and multiple views | Covered | A risk dashboard per module, and six views of the attack surface including an asset graph and a geographic map. |
| History and trend tracking | Covered | Assets added and removed between scans, and risk score history so you can show a direction of travel, not just a number. |
| Summarised reporting | Covered | A per-scan PDF with selectable sections, plus a monthly report across every module you subscribe to. |
| Hierarchical access control | Covered | Eight roles across staff, partners and resellers, with tenant isolation enforced on every request. |
| Workflow features | Covered | Findings carry a status: acknowledge one and it drops out of your reports and your score, with a record of who did it and when. |
| Raw data export | Covered | CSV export of subdomains, endpoints and dark web findings. |
| Configurable prioritisation | Covered | A severity-weighted score out of 1000, recalculated every six hours, with certificate trust folded into the same number. |
| Integrations out | Partial | Slack, Microsoft Teams and email. No SIEM or ticketing integration. |
| Integrations in | On the roadmap | No cloud provider or asset database import today. Domains are registered with us directly. |
The questions the guide tells you to ask
Answered here so you don’t have to get us on a call to find out.
How is the attack surface discovered?
From the domains you register with us, expanded using public DNS and certificate transparency data. We do not go looking for domains you have not told us about.
How current is the data?
Reconnaissance runs weekly per domain. Certificates are analysed continuously. Breach intelligence arrives as it is found. You can also trigger a scan yourself, once a day.
How are risks prioritised?
By severity and by how many instances exist, combined into a score out of 1000 and recalculated every six hours. Certificate trust feeds the same score.
How is scope controlled?
At the domain level: a domain is either monitored or it is not. Excluding an individual asset from a scan is not available.
Is there confidence scoring on findings?
No. Findings carry severity and CVSS. You can acknowledge one to take it out of your reports and score, but you cannot mark it a false positive yourself.
See it against your own attack surface
A free report shows you what the covered rows above actually find on your domain. No card details, and no sales call unless you ask for one.