Service
External Infrastructure Assessment
Internet-facing infrastructure review for UK businesses — discover exposure, risky services and weak configurations you can actually fix.
An External Infrastructure Assessment maps what your organisation exposes to the internet: hosts, services, certificates, remote access paths and assets that should not be public. It answers “what can someone reach?” before you sink time into the wrong deep dive.
BoundaryProof delivers this as a focused, founder-led engagement — not a black-box agency package. It sits alongside Web, OSINT and Firewall reviews. Choose Infra when exposure discovery is the priority; choose Web when a specific application is the priority; combine later if needed.
What it is
External asset discovery and review from the internet’s point of view. That includes identifying hosts and services associated with your authorised domains and ranges, checking ports and services that appear reachable, and highlighting TLS and remote access weaknesses that commonly turn into incident stories.
The aim is clarity. Unknown internet-facing services are one of the most common SME problems: old VPNs, forgotten admin interfaces, development systems that escaped, monitoring endpoints, or vendor appliances left with broad exposure. You cannot prioritise what you have not named.
Who it is for
Startups and SMEs without a full-time security team. Agencies and SaaS operators who need a clean external picture before customer reviews. UK businesses that have grown through cloud migrations and acquisitions and suspect the public footprint drifted.
If your only concern is application logic on a single portal, start with Web. If your only concern is rule-base hygiene on a firewall you already manage tightly, start with Firewall. If your concern is public documents and phishing fuel, start with OSINT. Infra is for reachability and external service exposure.
What we need
Authorisation covering the domains, IP ranges or cloud accounts in scope. A starting list of known assets helps but is not required to begin discovery within agreed bounds. Contacts who understand DNS and hosting. Clarity on what must not be touched. Timing constraints around peak traffic or releases.
We refuse third-party infrastructure you cannot authorise. “Please check this competitor” is not a valid statement of work. Shared environments need explicit permission from the owning party.
What you get
A prioritised view of external exposure with evidence and business context. Practical remediation guidance: close this, restrict that, patch or retire this service, fix this TLS posture, rethink this remote access path. A debrief call. Optional retest after remediation.
Reports are written for people who must implement changes — internal IT, MSPs, or founders wearing the ops hat — not for shelfware.
What we will not do
We will not pretend External Infrastructure work replaces a full internal build-out exercise. We will not expand into unauthorised networks. We will not sell unrelated product bundles. We will not equate a single pass with eternal safety; major changes deserve revisits.
No CE+ offering. No “any company” scanning. Authorised scope only.
Related next steps
Findings often lead naturally to Web assessment for exposed applications, Firewall review for permit paths, or OSINT for public clues that explain how attackers choose targets. We will recommend sequencing rather than dumping everything into one uncontrolled bag of work.
Example starting scenarios
You inherited cloud accounts and nobody is sure what is public. You run multiple domains after a rebrand. You suspect a forgotten VPN. You need a sober external picture before an enterprise security questionnaire. External Infrastructure is built for those moments: name the exposure, prioritise it, fix it, retest what mattered.
Bring DNS ownership details if you can. If you cannot, bring who knows. The scope call will turn that into an authorised asset boundary you can defend.
Fit with the rest of the site
External Infrastructure often sits first in a sequence because it answers what is reachable. From there, Web may examine a specific application that showed up as exposed, Firewall may address how traffic is permitted, and OSINT may explain public clues that make targeting easy. You do not have to buy all four. You should understand how they relate.
Founder-led delivery means the person mapping exposure is the person explaining it. That matters when findings touch MSP-managed hosts or legacy systems nobody wants to claim. Clear ownership conversations are part of making remediation real.
Book the free intro call if you want a sober external picture. Bring domains and any known ranges you are authorised to include. We will not scan arbitrary companies, and we will not pretend a single pass is forever.
What “good enough” looks like after Infra
You should be able to name your main internet-facing services, know which ones are intentional, and have owners for the surprises. High-risk remote access paths should be closed or justified. Weak TLS and obviously misplaced admin endpoints should be on a dated fix list. That is a solid SME outcome from a focused External Infrastructure assessment.
You should also know what you are still choosing not to do yet — for example a deep Web assessment on a portal that appeared during discovery. Naming the deferral keeps the programme honest and prevents the feeling that one review was supposed to end all uncertainty forever.
Authorised scope and inbound buying
External Infrastructure work is limited to named ranges, hosts and domains you authorise. We refuse “scan them” requests about unrelated organisations. Inbound only — no cold outreach from this library. Free intro ≠ free scan.
Ready to talk it through?
Book a free intro call to confirm fit, authorisation and scope. Prefer the form? Use the contact section on the main site.