Optional external assurance product

Continuously watch approved public-facing assets for exposure that was not there yesterday.

Guardian External Vulnerability Monitoring tracks approved public IPs, domains, hosts and services for supported vulnerability and exposure changes beyond the Core website allowance.

Australian data residency

Guardian for Australian customers is built, operated and hosted in Australia. All Guardian customer and platform data, including backups and recovery copies, is maintained and stored within Australia.

Authorised external asset scopeContinuous exposure monitoringFinding-to-action workflowRemediation verification
Buyer decision summary

Know what Guardian External Vulnerability Monitoring does, what the customer sees and what Damocles is responsible for before activation.

Guardian retains target, monitoring status, observation dates, finding identity, severity, evidence, action, exception and later review state. Credentials and raw execution payloads remain restricted.

The proposal identifies target unit, approved assets, profile, cadence, retention, reporting, support, provider relationship and any included validation or managed remediation coordination.

Targets, ownership, policy, cadence, exclusions and safe-testing methods must be approved. Third-party or unsupported targets are excluded unless separately authorised.

01

What the product does

The commercial unit can be an approved target, host, public IP, domain, service or another agreed asset model.

02

What the customer sees

The interface avoids raw scanner payloads while retaining enough context for remediation and traceability.

03

What Damocles manages

Formal penetration testing remains separate where human-led exploitation or attack-path validation is required.

The operational problem

Internet exposure changes between formal assessments as services, cloud resources, certificates and remote-access paths are added or changed.

A penetration test provides deep validation at a point in time. External monitoring provides ongoing awareness when a new host appears, a service changes, a certificate expires, a vulnerability persists or a previously resolved issue returns.

Guardian keeps target authority, customer ownership, findings, actions and later observation state together. The selected compatible assessment component performs the safe checks; Guardian provides the customer and provider workflow.

01

Maintain an authorised external inventory

Know which public IPs, domains, hosts and services are approved and owned by the customer.

02

Identify material change

Surface new, persistent, returned or changed exposure using the agreed monitoring policy.

03

Verify the response over time

Track ownership, evidence and later monitoring state rather than closing a finding from a task update alone.

Product capability

Continuous external posture for the approved customer attack surface.

The commercial unit can be an approved target, host, public IP, domain, service or another agreed asset model.

AI

External asset inventory

Record customer-owned public IPs, domains, hosts, services, environment and business context.

EM

Exposure monitoring

Run supported non-destructive external checks at the agreed cadence and profile.

CH

Change awareness

Identify new, returned, materially changed and no-longer-observed exposure where supported.

CF

Customer-readable findings

Present affected target, issue, severity, status, dates, evidence and remediation context.

RA

Risk and actions

Create owner-ready work for patching, removal, segmentation, hardening, upgrade or investigation.

RV

Resolution review

Use later monitoring state or approved validation to review whether exposure was removed.

What the customer sees

Customers see the approved attack surface, what changed and which exposure remains open.

The interface avoids raw scanner payloads while retaining enough context for remediation and traceability.

AS

Asset and service view

Approved target, ownership, service context, latest check and current finding state.

NV

New exposure

New host, port, service, certificate or supported vulnerability condition requiring review.

PF

Persistent findings

Material issues that remain observed across checks and require remediation escalation.

RR

Returned findings

Previously resolved or absent exposure that has been observed again.

OA

Owner actions

Remediation, evidence, due date, exception and review state for each material issue.

PV

Provider portfolio

Authorised customer target inventories, monitoring state and remediation through provider-scoped access.

What Damocles manages

Damocles manages target governance, monitoring health and finding follow-up according to the product schedule.

Formal penetration testing remains separate where human-led exploitation or attack-path validation is required.

TA

Target authorisation

Confirm customer ownership, asset scope, contacts, exclusions and safe-testing policy.

BL

Baseline inventory

Establish the approved external assets and supported current exposure state.

MO

Monitoring operation

Run the agreed checks, track job health and investigate failed or unavailable monitoring.

QR

Quality review

Validate customer scope, duplicate targets, finding continuity and customer-readable evidence.

RF

Remediation follow-up

Track owners, due dates, exceptions, evidence and required deeper assessment.

SR

Assurance reporting

Report approved assets, monitoring health, new and persistent exposure, overdue actions and resolution.

Operating lifecycle

From authorised asset scope to continuous monitoring and reviewed remediation.

The monitoring profile remains non-destructive and limited to explicit customer authority.

01

Authorise

Confirm target ownership, asset model, safe-testing policy, contacts and exclusions.

02

Baseline

Establish the approved external inventory and current supported exposure state.

03

Monitor

Run the agreed checks at the contracted cadence and record execution health.

04

Review

Normalise material findings, identify change and confirm customer ownership.

05

Remediate

Assign the required patch, configuration, removal, segmentation, certificate or engineering action.

06

Verify and report

Use later monitoring state or approved validation to review closure and report residual exposure.

Common use cases

Common external-monitoring use cases.

The product expands beyond the website-only allowance included in Guardian Core.

SM

Small external estate

Monitor a defined set of public IPs, domains and remote-access services for a small business.

CL

Cloud exposure

Track approved public cloud hosts and services that can change faster than annual review cycles.

RA

Remote access monitoring

Watch approved VPN, gateway and remote-management services for material exposure changes.

MS

MSP customer portfolios

Manage exact customer-owned target inventories and monitoring without fuzzy attribution.

PT

Between penetration tests

Maintain exposure awareness and remediation follow-up after a formal assessment.

CA

Certificate and service change

Identify supported certificate, protocol or exposed-service conditions requiring operational attention.

Operating model

How Guardian External Vulnerability Monitoring is onboarded, integrated, evidenced and scoped commercially.

These details remain explicit before activation, but are grouped into one operating view so buyers can review the responsibilities without working through four separate page sections.

ON

Onboarding and implementation

Onboarding establishes target ownership before any monitoring is enabled. The customer provides public IPs, domains, hosts, services, ownership evidence, environment, business context, contacts, exclusions and any third-party restrictions. Damocles confirms which targets are suitable for the approved safe-testing profile. The baseline validates reachability, target identity, duplicate ownership, assessment behaviour, finding quality and customer mapping. Assets without confirmed authority are not silently included. Go-live records target quantity, cadence, assessment policy, finding workflow, support, reporting and the boundary to deeper active assessment, penetration testing and engineering.

IN

Connector and integration model

The external-monitoring product can use approved assessment components without exposing them as the customer product. The assessment connector must preserve target authority, job status, timestamps, target identity, finding continuity, evidence and safe failure state. Guardian provides customer scope, action, risk, evidence and reporting. The selected component may change as long as target safety, finding identity, history, customer ownership and supportability remain intact. The commercial schedule identifies the implementation where relevant. New connector requests are reviewed for target controls, assessment policy, execution isolation, data quality, evidence, rate limits, supportability and commercial effort.

EV

Data, evidence and reporting

The monitoring record shows what was checked, what was observed and what happened next. Guardian retains target, monitoring status, observation dates, finding identity, severity, evidence, action, exception and later review state. Credentials and raw execution payloads remain restricted. A failed monitoring job, unreachable target or unsupported check is shown explicitly. Missing assessment data is not represented as a clean external posture. Reports distinguish new, persistent, returned, resolved-pending-review and closed findings where retained records support those states.

CM

Commercial unit and responsibilities

Commercial scope follows the approved external-asset quantity, cadence and managed follow-up. The proposal identifies target unit, approved assets, profile, cadence, retention, reporting, support, provider relationship and any included validation or managed remediation coordination. Additional targets, deeper assessment profiles, authentication, penetration testing, retesting and remediation engineering remain separate unless included. The customer owns target authority and remediation decisions. Damocles owns the monitoring and follow-up activities listed in the product schedule.

Frequently asked questions

Questions buyers ask about Guardian External Vulnerability Monitoring.

The exact answer is confirmed in the proposal and package schedule, but these points should be understood before activation.

Q1

What counts as a target?

The proposal defines whether the commercial unit is a public IP, domain, host, service or another approved asset model.

Q2

Does this discover every internet asset?

No. Coverage follows the authorised inventory and supported discovery or monitoring methods stated in the service.

Q3

Is exploitation performed?

Not as part of baseline external monitoring. Deeper active or manual testing requires separate authority and scope.

Q4

Can an MSP manage customer targets?

Yes through explicit provider relationships and exact customer target ownership.

Q5

How is closure verified?

Later monitoring state, approved evidence or a separate validation activity is used according to the finding.

Q6

What if a target is third-party controlled?

It requires appropriate authority or may be excluded from active monitoring.

Scope and boundaries

External monitoring is authorised assessment, not unrestricted internet scanning.

Targets, ownership, policy, cadence, exclusions and safe-testing methods must be approved. Third-party or unsupported targets are excluded unless separately authorised.

The product does not guarantee complete attack-surface discovery or identification of every vulnerability and does not perform destructive testing or denial-of-service activity.

Manual penetration testing and remediation engineering remain separate where deeper validation or implementation work is required.

Take the next practical step

Map the public-facing assets that change too often for annual assurance alone.

We will define the authorised target model, monitoring policy, cadence, connector, remediation workflow and verification approach.