And what happens when AI starts looking too?
Every business has a digital footprint extending beyond its walls.
Your website is the obvious part. But there may also be customer portals, supplier systems, remote access services, cloud applications, login pages and public-facing IP addresses connecting your organisation to the internet.
They’re there because modern businesses need to be connected. But when did you last look at your business from the outside?
Because anything accessible from the internet has the potential to become part of your external attack surface and understanding what is visible is an important part of understanding your Cyber Security risk. The NCSC describes external attack surface management as looking at internet-accessible assets from an external perspective, effectively giving defenders a view closer to what an attacker could see.
What could someone find?
An external view of your organisation may reveal more than you realise.
There may be public IP addresses associated with internet-facing systems, web applications and portals, login pages, remote access services, cloud-hosted systems or services running on infrastructure exposed to the internet.
None of these things automatically represents a vulnerability. Being visible isn’t the same as being vulnerable.
The important question is whether something exposed, also contains a weakness, perhaps outdated software, a configuration issue, an application vulnerability or another Cyber Security weakness that could potentially be exploited. And that’s where things are changing.
AI can look too.
AI hasn’t suddenly invented an entirely new way of breaking into businesses. What it is doing is making elements of existing cyber activity faster, more efficient and potentially easier to scale.
The UK’s National Cyber Security Centre says threat actors are already using AI to enhance reconnaissance, vulnerability research and exploit development, social engineering and other existing techniques. Its assessment through 2027 is that AI will primarily enhance existing attack methods rather than create entirely new ones. (src https://www.ncsc.gov.uk/report/impact-ai-cyber-threat-now-2027)
In other words, an attacker can potentially use AI as another tool to help gather information, analyse what has been discovered and investigate possible weaknesses.
AI doesn't need to invent the door. It can help someone find it faster.
That’s an important distinction.
AI can’t simply look at a company website and magically gain access to the business behind it. There still needs to be a route in such as a vulnerability, poor configuration, compromised credentials or successful social engineering.
But the NCSC expects AI-assisted vulnerability research and exploit development to become particularly significant, including making it easier to exploit known vulnerabilities in systems that haven’t been updated.
Which raises a much more useful question for businesses:
If someone started looking at your business from the outside, what would they find?
That’s where external penetration testing becomes valuable.
See what they see. Before they do.
Penetration testing is an authorised assessment designed to test the security of an IT system by attempting to breach its defences using techniques an adversary might use.
For an external penetration test, the focus can be the systems your organisation exposes to the internet.
That might include your:
- Public-facing IP addresses and associated services
- Customer, employee or supplier portals
- Web applications and login interfaces
- Remote access systems
- Internet-facing infrastructure and services
- Other agreed external systems within the scope of the test
A properly scoped test goes beyond simply asking what’s visible. It examines whether identified weaknesses could present a genuine security risk and provides findings that can be prioritised and addressed.
Look at your business from the outside.
You don’t need to assume that somebody is trying to break into your organisation every minute of the day. But you should understand what you’ve made available to the internet and have confidence that the systems protecting it are doing their job.
External penetration testing can help provide that assurance by examining agreed public-facing IP addresses, portals, applications and services from an external perspective.
AI may be changing how quickly threats evolve. The fundamentals haven’t changed: understand what you’ve exposed, test it and address weaknesses before somebody else finds them.
What would someone find if they looked at your business today? We help businesses understand and strengthen their Cyber Security, including testing internet-facing systems for potential weaknesses. Talk to our team 0800 038 7222. Email sales@bom.co.uk.
“You can’t secure what you don’t know is exposed.“
“External penetration testing gives businesses the opportunity to see their systems from an attacker’s perspective, understand where the weaknesses are and address them before they become a problem.”