TL;DR
- We’ve started sending some prospects an unsolicited “Attack Surface Snapshot”, built entirely from public information, as a conversation starter rather than a data sheet.
- A handful of CISOs have told us it feels like using AI to embarrass people into a sales call. Others have called it the most useful two minutes of any vendor email they’ve had all year. We’d genuinely like to know which camp you’re in.
- Two anonymised examples, one food manufacturer, one higher education institution, are set out below so you can judge the actual content, not just the idea of it.
Why we’re asking instead of telling
We’re going to be upfront about something we’re testing rather than something we’ve perfected. As part of our Proactive Cyber Security Monitoring Service, we’ve started building what we call an Attack Surface Snapshot for some of the prospects we’d like to talk to, and sending it over cold, before any call has happened.
The reaction has been split. Some CISOs have told us directly that it isn’t helpful, that running an AI-generated report on someone’s organisation in the name of a sales pitch feels like it’s implying they’re not good at their job. Others have replied within the hour asking how quickly we could run the full picture. We think both reactions deserve a proper answer, not a defensive one, which is why we’re writing this instead of quietly shelving the idea or quietly doubling down on it.
What actually goes into one of these
Every snapshot is built entirely from publicly available information: DNS and certificate records, indexed web content, dark web marketplaces and breach data feeds. We do not scan, probe or connect into any live system at any point. Everything in the report is exactly what a patient outsider, or a less patient attacker, could already piece together without ever touching your network.
That distinction matters more than it sounds. This isn’t a penetration test dressed up as a favour. It’s closer to standing across the street and noting which windows are open, nothing more.
The message that lands in someone’s inbox
Here’s the actual template, lightly anonymised, so you can judge the tone for yourselves rather than take our word for it:
“We ran an outside-in security snapshot of [Organisation]’s public footprint using only public information, as part of our Proactive Cyber Security Monitoring Service. See attached infographic for more details. Your top three issues today are: [three headline findings]. Would it be helpful if we shared the full snapshot to see how we could help close these gaps?”
No jargon, no scoreboard, no “act now or else”. Just what we found and a genuine question at the end, not a demand.
The pushback, in their words
A few CISOs have pushed back hard, and we think their point is worth repeating properly rather than paraphrasing away. The argument is that using AI and third-party intelligence feeds to compile a vulnerability report on an organisation that never asked for one, then using it as a sales lever, is a form of pressure dressed up as a public service. It implies the recipient has been asleep at the wheel, and it uses their own exposure as the hook.
That’s a fair challenge and we’re not going to wave it away. Anyone doing outside-in monitoring at scale needs to sit with that discomfort rather than dismiss it.
Why we think there’s a real difference, but we could be wrong
Here’s our honest reasoning. Every one of these findings is already sitting in public view. It’s on GitHub, in breach dumps already circulating, in DNS records anyone can query. We haven’t gone looking for anything hidden. We’ve just organised what’s already visible into something a busy security team might not have had time to pull together themselves, and we think there’s a meaningful difference between pointing that out and mocking someone for not spotting it first.
A locksmith mentioning your back gate is swinging open isn’t the same as a locksmith laughing at you for not noticing. Intent matters, but so does how it lands, and that’s exactly the bit we can’t judge from the inside. That’s what we’re asking you to help us with.
What we’re seeing in practice
Two recent, anonymised examples show how differently this plays out by sector.
- A UK food manufacturer: 99 open findings overall, with 64 corporate email addresses and passwords found in third-party breach data spanning the parent company and its group brands, alongside 7 critical-severity flaws in outdated WordPress, Apache and PHP components, and one orphaned DNS record leaving a subdomain open to takeover.

- A UK higher education institution: 50 open findings, and unusually, every single one rated Very High severity, an unusually concentrated risk profile compared with most organisations we assess. That included 21 critical software flaws across outdated Apache, OpenSSL, WordPress and Python components, several likely under active exploitation, 19 staff and student devices currently infected with credential-harvesting malware, and 8 public GitHub repositories referencing internal authentication systems and secret names.

Neither organisation had any idea these were sitting in their public footprint until we got in touch. That’s the entire case for doing this. Whether it’s the right way to open a conversation is the bit we’re less sure of, and the bit we want your view on.
UK & New Zealand perspective
Tone lands differently depending on where you sit. UK buyers tend to react badly to anything that feels like a gotcha, direct, evidence-led outreach tends to work better here than anything with a whiff of scare tactics. New Zealand’s security community is small and closely connected, so a report that feels like a stunt travels fast, and not in a good way. Both markets reward the same thing: show your working, make the value obvious, and don’t dress up a sales email as a safety announcement.
What we predict
Looking 12 to 36 months out, we expect this style of evidence-led outreach to become far more common, not less. The tooling to build these snapshots is getting cheaper and faster for every vendor to use, not just us, so the report itself will stop being the differentiator.
What will separate the useful from the unwelcome is restraint: whether a vendor uses the findings to genuinely open a conversation, or leans on them to manufacture urgency. We think that distinction is about to matter a lot more than it does today.
Where ITogether stands, for now
We think there’s a real difference between an ambulance chaser and a neighbour pointing out your gate’s swinging open, and we’ve tried hard to build this as the latter. But we’re aware that intent doesn’t always survive contact with someone’s inbox, and perception matters just as much as what we meant by it.
So we’re asking properly, not rhetorically: if this landed in your inbox, would it read as useful or as a cheap shot? We’d rather hear the honest answer now than keep guessing.
👉 Tell us what you think in the comments, and if you’d like to see your own organisation’s snapshot, one-off or as an ongoing monthly service, get in touch.
📞 UK +44 (0) 113 341 0123
📞 NZ +64 (0)9 802 2444
📧 hello@itogether.com
FAQs
What information goes into an Attack Surface Snapshot?
Entirely public sources: DNS and certificate records, indexed web content, dark web marketplaces and breach data feeds. Nothing is gathered by scanning, probing or connecting into any live system.
Do you access or touch our live systems to produce one?
No, at no point. Everything in the report reflects what’s already publicly visible.
Can we get this as an ongoing service rather than a one-off report?
Yes. We offer it as a managed monthly service with a live dashboard, designed to be a cost-effective addition alongside your existing security team, not a replacement for it.
Can we opt out of receiving one of these unsolicited?
Yes, just let us know and we won’t send an unsolicited snapshot to your organisation.

0 Comments