5,000+ external assets surfaced in 3 months; exposed API keys, S3 credentials, and dev/staging systems remediated first — reported to the board in FAIR terms.
Minor flaws chained into admin privilege escalation, remote control of a connected system, and a large-scale customer-PII exposure path — proven and closed before an incident.
Shadow assets identified through EASM, linkage to a nation-state-backed actor investigated, and exploitable exposures delivered with PoC-verified evidence.
In their words.
They went beyond listing assets — they singled out the vulnerabilities most likely to be exploited, with concrete guidance and re-verification after the fix.
Each finding on its own looked minor — the kind our annual scans had always waved through. Seeing them chained into a working intrusion path, then re-tested until it was closed, changed how we run security.