Articles

Practical external security, explained.

Comparisons, how-tos and plain-language explainers on attack surface monitoring, TLS, DNS and the other things the outside world can see about your infrastructure.

The Gap in Your Compliance Stack Is the Part the Internet Can See

Compliance tooling monitors the assets you enrolled: laptops in MDM, cloud accounts in CSPM, repos in CI. Breaches keep coming from assets nobody enrolled. Why every control in the stack is inside-out, and where an external scanner fits.

Read article →

Bastion vs. OpenVAS: Vulnerability Scanner or External Monitor?

OpenVAS is a free, self-hosted vulnerability scanner with tens of thousands of CVE checks; Bastion is a hosted external monitor that watches your domains for drift. What each actually does, the operational cost of self-hosting, and when to run both.

Read article →

Hand Your Security Findings to a Coding Agent: Claude Code, Codex and opencode

Most external scan findings are config changes living in a repo — exactly what coding agents are good at. How to hand a scan report to Claude Code, OpenAI Codex or opencode so the findings actually get fixed, and what to keep a human on.

Read article →

Turning External Monitoring Into SOC 2 and ISO 27001 Evidence

SOC 2 CC7.1 and ISO 27001 Annex A 8.8 both expect continuous monitoring you can prove. How to use external attack surface monitoring as audit evidence — what maps to which control, what auditors sample, and what it does not cover.

Read article →

The Best External Attack Surface Monitoring Tools in 2026, Compared

A practical comparison of external attack surface monitoring options in 2026 — Bastion, Detectify, Intruder, Shodan Monitor, Censys, Microsoft Defender EASM and free tooling — organized by team size and budget.

Read article →

Bastion vs. Detectify: Which External Security Monitor Fits Your Team?

An honest comparison of Bastion and Detectify for external attack surface monitoring: what each checks, how they price, and which team each one actually fits.

Read article →

Bastion vs. Intruder: Vulnerability Scanning or Attack Surface Monitoring?

Intruder is a polished vulnerability scanner with attack surface features; Bastion is a passive external monitor with change detection. Here is how to decide which one your team needs.

Read article →

Bastion vs. Shodan and Censys: Search Engines Aren't Monitoring

Shodan and Censys index the whole internet; Bastion continuously monitors the domains you own. What each is for, where they overlap, and why teams often need the monitoring layer, not the search engine.

Read article →

Which HTTP Security Headers Actually Matter in 2026 (and How to Set Them)

A practical guide to HTTP security headers: HSTS, Content-Security-Policy, X-Content-Type-Options, Referrer-Policy, Permissions-Policy and frame protection — what each prevents, copy-paste starting values, and what to skip.

Read article →

SSL Labs vs. SecurityHeaders.com vs. Mozilla Observatory: Free Scanners Compared

The best free website security checkers — Qualys SSL Labs, securityheaders.com, Mozilla HTTP Observatory, MXToolbox and Hardenize — compared: what each grades, what each misses, and how to combine them.

Read article →

Subdomain Takeover: How a Dangling CNAME Becomes Someone Else's Website

Subdomain takeover happens when a DNS record points at a deprovisioned service that anyone can claim. How the attack works, how to find dangling CNAMEs, and how to prevent takeovers.

Read article →

How to Monitor SSL/TLS Certificate Expiry (Before Your Users Do)

TLS certificates now expire in under 200 days and are heading to 47. How certificate expiry outages happen, how to monitor expiry for free, and what a monitoring setup should actually alert on.

Read article →

SPF, DKIM and DMARC Explained: Stop Other People Sending Email as You

Plain-English guide to email authentication: what SPF, DKIM and DMARC each do, how the three fit together, common record mistakes, and how to move to a DMARC reject policy safely.

Read article →

What Is External Attack Surface Management (EASM)? A Plain-English Guide

External attack surface management (EASM) is the continuous discovery and monitoring of everything your organization exposes to the internet. Here is what it covers, why it matters, and how it differs from vulnerability scanning and pentesting.

Read article →