Threat Surface
Every assessment begins by understanding what is exposed. This includes systems, identities, cloud services, applications, external services and the broader technology environment. The objective is not simply to identify assets, but to understand where potential exposure exists and how that exposure influences organisational risk.