AI & Automation · Public university
The assessment that used to take days now runs in hours
A public university with a large, sprawling estate needed its external infrastructure assessed — and then reassessed, repeatedly. Doing that by hand does not scale. Automating it changed the unit of work from the whole estate to a single subdomain.
At a glance
- Client
- Public university (unnamed)
- Practice
- Cybersecurity
- Scope
- Full external infrastructure
- Before
- 12 h continuous manual analysis
- After
- ~8 min per subdomain
Python · DNS · Subdomain enumeration · Automated triage · Reporting
The situation
A security assessment you can only afford to run once is not a security programme
The first full assessment of the university's external infrastructure took twelve hours of continuous manual analysis. It produced a real picture — and it was obsolete the moment a department spun up a new subdomain, which in a university happens constantly.
That is the trap most organisations fall into: the assessment becomes an annual event because nobody can justify twelve hours a month. The fix is not working faster by hand. It is making the assessment repeatable enough that running it stops being a decision.
What we did
Four steps, in this order.
Ran the manual baseline first
Twelve hours of continuous analysis across the full external estate, to establish what the assessment should find before automating the search for it.
Encoded the analysis, not just the scanning
The automation reproduces the reasoning steps of the manual pass, so the output is a triaged finding rather than a raw scanner dump somebody still has to read.
Made the subdomain the unit of work
Each subdomain is assessed independently in around eight minutes, which means new ones get covered as they appear instead of waiting for the next full sweep.
Handed over the tooling
The automation belongs to the client and runs without us, which is the difference between a report and a capability.
Results
The numbers, as measured.
The takeaway
What this case actually shows
The headline number is the eight minutes, but the result that matters is the change in frequency. An assessment that costs twelve hours gets run once a year and argued about; one that costs eight minutes per subdomain gets run whenever something changes. Security posture is not decided by how good a single assessment is — it is decided by how often you can afford to look.
Start here
Have a version of this problem?
Describe the problem in a few lines. You get a written reply with a first read on it, whether or not there is an engagement in it. The message is sent from this page — no email client, no third-party form service, no trackers.