DHDatara Hub

Practice 03

See what you expose before someone else does

External exposure discovery, scoped web application penetration testing by a certified tester, and a risk governance plan your leadership can actually run — with owners, deadlines and a monitoring baseline that keeps working after the report is delivered.

Standard engagement record

Entry point
Technical assessment
Duration
2 weeks
You receive
Findings + roadmap
Commitment after
None
Working languages
EN / ES

Scope agreed in writing before work begins.

The problem

Your attack surface grew while nobody was counting

Every subdomain a marketing agency spun up, every test server someone forgot to shut down, every certificate about to expire, every admin panel reachable from the open internet — it is all public, and an attacker enumerates it in minutes with free tooling.

Most companies without a security team have never seen that list. The first deliverable here is not a fix — it is simply knowing what exists, because you cannot govern a risk you cannot name, and you cannot test an application you forgot you were running.

Scope

What this includes, and what it does not.

Stated before you ask, so the first call is about your problem rather than about what we do or do not cover.

Included

  • Discovery of domains, subdomains, DNS records, IPs, services and certificates
  • Scoped web application penetration testing, under written authorisation and agreed rules of engagement
  • Vulnerability analysis, severity triage and a mitigation plan with named owners
  • Risk register, governance cadence, monitoring and executive reporting

Not included

  • Full-scope red-team, social engineering and physical intrusion exercises
  • Certified regulatory audits (ISO 27001, SOC 2 attestation)
  • 24/7 staffed incident response

How it runs

Four steps, in this order.

01

Authorisation and rules of engagement

Nothing is scanned or tested before the asset owner authorises it in writing. For a penetration test we also agree the rules of engagement first: which targets, which techniques, which hours, and who to call if something breaks.

02

Map the external surface

Domains, subdomains, DNS, certificates, exposed services. The inventory almost always contains something nobody in the room knew was online.

03

Triage by real impact

Not a raw scanner dump. Each finding gets a severity, a business consequence and an owner, so leadership can decide what is worth money now and what can wait.

04

Install the cadence

A risk register your team keeps, monitoring that alerts on change, and a reporting rhythm — so the second month is better than the first instead of identical to it.

Track record

The experience behind this practice

Track record

Certified web penetration tester, currently practising

Certified Web Penetration Tester (American Council for Cybersecurity) — not a course badge but the credential the testing runs under. Two live engagements in parallel during 2026: vulnerability assessments for one of Mexico's largest public universities, and risk management for a legal and real-estate consultancy.

Track record

Real threats, neutralised

Designed a full risk management plan — threat identification, prioritisation and mitigation — and neutralised active phishing and impersonation campaigns aimed at a firm and its clients. Not a tabletop exercise: live attacks, shut down.

Track record

Assessment work made repeatable

Built automation so recurring security assessments run the same way every time, plus a monitoring dashboard covering DNS visibility, service discovery, change alerting and operational reporting.

Questions

Answered before you have to ask.

Do you perform penetration testing?

Yes — scoped web application penetration testing, run by a certified Web Penetration Tester under written authorisation and agreed rules of engagement. What is not included is full-scope red-team work, social engineering and physical intrusion: those need a different team, a different contract and a different conversation with your legal counsel. The scope is written down and signed before anything is tested.

Do we need to authorise the testing?

Yes, in writing, from whoever owns the assets — before anything begins. If the target runs on a third-party platform, that provider usually has to authorise it too. Testing infrastructure without documented authorisation is a legal problem for both sides, so it is a hard prerequisite rather than a formality.

We are a small company. Is this overkill?

The opposite: companies without a security team are the ones with the largest blind spot, and the discovery step is cheap. Knowing what you expose costs far less than finding out through an incident.

What do we get at the end?

An inventory of your external footprint, a test report with reproduction steps for each finding, severity and business impact, a mitigation plan with owners and dates, a risk register, and a monitoring baseline that keeps running. Retesting after remediation is agreed up front rather than sold back to you later.

Start here

Tell us what is broken, slow or expensive.

Describe the problem in a few lines. You get a written reply with a first read on it, whether or not there is an engagement in it. The message is sent from this page — no email client, no third-party form service, no trackers.

We use your message to reply to you. Nothing else — no list, no third parties.