Door 1 · Unpatched systems
31%
of breaches began with an exploited vulnerability. For the first time in the report's 19 years, that is the most common way in.
Continuous threat exposure management for MSPs and MSSPs
Your scanner checks what you give it. Outerwall starts from what an attacker can already see: your clients' exposed systems, the suppliers nobody listed and the threats moving against them. Then it proves every fix.
In pilot with design partners. First partner release early 2027.
The research engine reads the public internet, all the time. Certificate logs, DNS, internet scans, registers, breach notices, job adverts and vendor case studies. Every company is observed once, so the picture exists before anyone asks.
Type one domain. Within the hour: the estate, the suppliers nobody listed, the lookalike domains and the threats already moving. Ranked as likely, and nothing touched.
Checks start only after approval. Proof of control, a signed scope and 24 hours' notice come first. Then only approved assets are checked, and each likely finding is confirmed or dropped.
One ranked register, in your service desk. Coverage gaps come first, tickets open in your PSA, and a fix counts only when two checks that reached the asset agree.
Why now
Verizon's 2026 Data Breach Investigations Report, a study of thousands of real breaches, describes all three. The firms MSPs look after have the same doors and, usually, no security team.
Door 1 · Unpatched systems
31%
of breaches began with an exploited vulnerability. For the first time in the report's 19 years, that is the most common way in.
Door 2 · Suppliers
48%
of breaches involved a third party, up 60% in a year.
Door 3 · Stolen credentials
73%
of ransomware victims had an infostealer infection or a credential leak in the year before the attack. Half of them within 95 days.
Source: Verizon, 2026 Data Breach Investigations Report. Credentials appeared in 39% of breaches, and ransomware in 48%.
The category
Gartner defines CTEM as a programme an organisation runs on a loop. The aim is to put effort where an attacker could actually get in, instead of working through a list that never ends. Many tools cover one or two stages. Outerwall is built to run all five, for every client, through you.
What it means
Decide which parts of the business matter, and what losing them would cost.
What Outerwall does
Starts from one domain. Research maps the estate, the suppliers and the rules the client answers to. The client confirms what is theirs.
FTC Safeguards · Regulation S-P · NYDFS 500
What it means
Find the assets and their exposures, including the ones nobody listed.
What Outerwall does
Five public surfaces, read passively: infrastructure, records, events, workforce and vendor references. Forgotten hosts, unlisted suppliers and lookalike domains appear before any scan.
Within the hour of adding a client
What it means
Rank exposures by how likely they are to be used and what they would hit.
What Outerwall does
Ranked by blast radius and live threat: known-exploited flaws, breach notices, ransomware mentions. Every rule is tested code, so the same data always gives the same answer.
No AI model decides a finding
What it means
Confirm an attacker could really use the exposure.
What Outerwall does
Non-destructive checks on approved assets turn a likely finding into a confirmed one, or drop it. A version number alone is never enough. Our testers go further when a client needs proof.
Approved assets only
What it means
Get the fix done by the people who own it.
What Outerwall does
Tickets open in ConnectWise, Autotask or HaloPSA, ranked first to last. A fix counts only when two checks that reached the asset agree, and the evidence goes into the client’s compliance pack.
Confirmed, not assumed
01
They look for the easiest way in: an unpatched gateway, a supplier, a lookalike domain that can receive mail. CTEM looks from the same side, continuously, so the easy ways in close first.
02
The FTC Safeguards Rule asks for continuous monitoring, or an annual penetration test and vulnerability assessments every six months. SEC Regulation S-P and NYDFS Part 500 add oversight of service providers. Small regulated firms have to show evidence.
03
Gartner predicts that by 2029, 60% of organisations will have a structured validation practice within CTEM, with managed service providers among the primary enablers.
CTEM market, worldwide
$2.7B in 2025 to $7.0B by 2033
North America held 37% of 2025 revenue, the largest region. Small and mid-sized organisations are the fastest-growing segment.
Sources: Gartner, Market Guide for Adversarial Exposure Validation, 2026; Grand View Research, CTEM market report, 2025. Intermediate years in the chart are illustrative, drawn at the report's 12.7% annual growth.
Know before we touch
The research engine observes every company once and keeps it current. When you add a client, most of what matters is already known, with where and when each fact was found. Anything we can't confirm is labelled or thrown out.
1Where we look
2What we already hold · harbourlending.example
3What it becomes
3 domains, 38 host names, one forgotten.
FTC Safeguards: evidence the client will need.
Proposed for the client to confirm, ranked by blast radius.
Likely until checked. A version match is never firm.
What we cannot see comes first in the register.
FirmSeen directly in a source we trust, with its date.
LikelyInferred, and shown as likely until a check or the client confirms it.
Thrown outToo old, or contradicted by a newer source.
Can't seeKnown to exist, not measured. Listed, never hidden.
Supplier exposure
Supplier monitoring is usually a separate product, priced per vendor the customer remembers to add. The identity provider and the agent on every laptop are the ones they forget. Outerwall finds them from the outside and ranks them by blast radius.
01
Mail exchange and sender records, verification tokens, CNAMEs and the sign-in realm reveal who runs a client’s mail, identity, hosting and software. All of it public, none of it asked for.
02
“Experience with our payroll platform required.” A vendor’s case study that names the client as a customer. Each one is proposed for the client to confirm, with where it was found.
03
How much damage a failure there would do. Catastrophic: the identity provider, and an endpoint agent that updates itself on every laptop. Severe: processors of regulated data. High: hosting. Moderate: peripheral software.
04
Northgate IT looks after 40 clients. 14 of them use the same payroll provider, and 31 the same identity provider. No client-by-client spreadsheet shows that.
05
The payroll provider files a breach notice. All 14 clients are flagged in one view, with the evidence, within the 6-hour target. Northgate raises it with all of them in one morning.
We never test a supplier without that supplier’s own signed consent. Suppliers are observed from public sources only.
Safe by design
Research is passive. Active checks run only on assets the client has approved, after it has proven control, signed the scope and had 24 hours' notice. A blocked check is shown as blocked, never worked around.
The path to the first active check
All five gates passed. Checks run on approved assets only, inside the agreed window, and the client’s contact already has our scan addresses.Stopped at control. The organisation sees its passive footprint and counts of issues by type. No active check runs, and no exposure detail is shown.
Suppliers are observed from public sources. Testing one needs that supplier’s own signed consent.
Until an organisation proves it controls a domain, it sees its footprint and counts of issues by type. Never the exposure detail.
What we learn about an organisation is never used to sell to it.
Any secret we detect becomes a keyed fingerprint and a count the moment it is collected. The value is never stored.
Separation is enforced by the database itself, for every partner and every client.
Every decision is tested code. The same data always gives the same answer.
Prove the fix
Most scanners close a finding when the next scan doesn't see it, even when a firewall blocked that scan. Outerwall records what every check actually reached. A finding closes only after two consecutive checks reached the asset and found it gone.
Finding lifecycle · harbourlending.example · VPN gateway
A new flaw on CISA’s known-exploited list that matches software a client runs. A new certificate or open port. Staff credentials in a breach or infostealer log. A lookalike domain. A ransomware group naming a client. A supplier’s breach, outage or insolvency.
New subdomains and addresses, DNS and email records. A change triggers a recheck of the one asset that changed, not a new scan of the whole estate.
Detection targets for clients and suppliers alike. The measure we hold ourselves to: the share of high and critical findings fixed, and confirmed fixed, within the agreed time.
Built for MSPs and MSSPs
Outerwall is sold only through managed service providers. You see every client in one portfolio, work the fixes in the service desk you already use, and hand clients reports with your name on them.
MSPs
One view of every client, ranked. Fixes flow into the service desk your technicians already use.
MSSPs
Deterministic rules, evidence with every finding and coverage that shows its own gaps.
Their clients
Mortgage brokers, tax preparers, investment advisers and medical practices, typically 20 to 200 staff.
Every client ranked in one place, with the suppliers they share across your book.
ConnectWise, Autotask and HaloPSA. Ranked by blast radius, closed only when the fix is confirmed.
Sold only through partners. Reports and the client portal carry your name.
Mapped to the FTC Safeguards Rule, SEC Regulation S-P and NYDFS Part 500.
A new client sees its passive picture within an hour or two, before any scan touches its systems.
Annual penetration tests start from the estate Outerwall has already mapped.
Outerwall's output supports a client's compliance evidence. It does not, by itself, make a client compliant.
FTC Safeguards Rule16 CFR 314
Non-bank financial firms
Continuous monitoring, or an annual penetration test and vulnerability assessments every six months. Oversight of service providers.
SEC Regulation S-P2024 amendments
Broker-dealers, advisers, funds
Oversight of service providers, through due diligence and monitoring. Smaller firms from June 2026.
NYDFS Part 500New York
Financial services firms
Automated scans, an annual penetration test, risk-based remediation and a complete asset inventory.
PCI DSS v4.0.1Requirement 11.3.2
Anyone handling card data
Quarterly external scans by an Approved Scanning Vendor. Outerwall adds to those scans; it does not replace them.
HIPAA Security RuleProposed update
Healthcare and business associates
Proposed: scans every six months, a yearly penetration test and an asset inventory. Not yet final.
The name
It is everything the internet can see: the hosts, the names, the suppliers that connect through it. Attackers study it before they try a door. Outerwall studies it first, and keeps watching.
The mark is that wall: eight segments around what it protects. One segment is lit. It is the one that was found, fixed, and proven fixed.
Design partners
We are working with a small group of US MSPs and MSSPs ahead of the first partner release in early 2027. Design partners get early access and a direct line to the people building it.
Start with your own estate
Every design partner starts by running Outerwall on its own domain, after proving control of it. You see exactly what your clients would see, and nobody else's data is involved.