Continuous threat exposure management for MSPs and MSSPs

Know first.Prove the fix.

Your scanner checks what you give it. Outerwall starts from what an attacker can already see: your clients' exposed systems, the suppliers nobody listed and the threats moving against them. Then it proves every fix.

In pilot with design partners. First partner release early 2027.

  1. Research: Outerwall reads certificate logs, DNS, internet scans, registers, breach and known-exploited feeds, job adverts and vendor case studies for every company, before anyone asks.
  2. Discover: a partner types one domain. Within the hour Outerwall shows the client's hosts, the suppliers nobody listed ranked by blast radius, lookalike domains, and threats already moving, without touching anything.
  3. Assess: after proof of control, a signed scope and 24 hours' notice, only approved assets are checked. A likely flaw on the VPN gateway is confirmed.
  4. Value: one register ranked by blast radius, a ticket in the partner's service desk, and a fix that counts only when two checks that reached the asset agree. The partner sees that 14 of its 40 clients share a breached payroll provider.

The research engine reads the public internet, all the time. Certificate logs, DNS, internet scans, registers, breach notices, job adverts and vendor case studies. Every company is observed once, so the picture exists before anyone asks.

Type one domain. Within the hour: the estate, the suppliers nobody listed, the lookalike domains and the threats already moving. Ranked as likely, and nothing touched.

Checks start only after approval. Proof of control, a signed scope and 24 hours' notice come first. Then only approved assets are checked, and each likely finding is confirmed or dropped.

One ranked register, in your service desk. Coverage gaps come first, tickets open in your PSA, and a fix counts only when two checks that reached the asset agree.

Why now

Attackers come in through three doors. Small firms watch none of them well.

Verizon's 2026 Data Breach Investigations Report, a study of thousands of real breaches, describes all three. The firms MSPs look after have the same doors and, usually, no security team.

Door 1 · Unpatched systems

31%

of breaches began with an exploited vulnerability. For the first time in the report's 19 years, that is the most common way in.

Known-exploited flaws fully fixed26%
Median time to fix43 days

Door 2 · Suppliers

48%

of breaches involved a third party, up 60% in a year.

Door 3 · Stolen credentials

73%

of ransomware victims had an infostealer infection or a credential leak in the year before the attack. Half of them within 95 days.

Source: Verizon, 2026 Data Breach Investigations Report. Credentials appeared in 39% of breaches, and ransomware in 48%.

The category

Continuous threat exposure management, in five stages.

Gartner defines CTEM as a programme an organisation runs on a loop. The aim is to put effort where an attacker could actually get in, instead of working through a list that never ends. Many tools cover one or two stages. Outerwall is built to run all five, for every client, through you.

What it means

Decide which parts of the business matter, and what losing them would cost.

What Outerwall does

Starts from one domain. Research maps the estate, the suppliers and the rules the client answers to. The client confirms what is theirs.

FTC Safeguards · Regulation S-P · NYDFS 500

What it means

Find the assets and their exposures, including the ones nobody listed.

What Outerwall does

Five public surfaces, read passively: infrastructure, records, events, workforce and vendor references. Forgotten hosts, unlisted suppliers and lookalike domains appear before any scan.

Within the hour of adding a client

What it means

Rank exposures by how likely they are to be used and what they would hit.

What Outerwall does

Ranked by blast radius and live threat: known-exploited flaws, breach notices, ransomware mentions. Every rule is tested code, so the same data always gives the same answer.

No AI model decides a finding

What it means

Confirm an attacker could really use the exposure.

What Outerwall does

Non-destructive checks on approved assets turn a likely finding into a confirmed one, or drop it. A version number alone is never enough. Our testers go further when a client needs proof.

Approved assets only

What it means

Get the fix done by the people who own it.

What Outerwall does

Tickets open in ConnectWise, Autotask or HaloPSA, ranked first to last. A fix counts only when two checks that reached the asset agree, and the evidence goes into the client’s compliance pack.

Confirmed, not assumed

Why it matters to a business

01

Attackers already work this way.

They look for the easiest way in: an unpatched gateway, a supplier, a lookalike domain that can receive mail. CTEM looks from the same side, continuously, so the easy ways in close first.

02

The rules now ask for it.

The FTC Safeguards Rule asks for continuous monitoring, or an annual penetration test and vulnerability assessments every six months. SEC Regulation S-P and NYDFS Part 500 add oversight of service providers. Small regulated firms have to show evidence.

03

The market is moving to MSPs.

Gartner predicts that by 2029, 60% of organisations will have a structured validation practice within CTEM, with managed service providers among the primary enablers.

CTEM market, worldwide

$2.7B in 2025 to $7.0B by 2033

North America held 37% of 2025 revenue, the largest region. Small and mid-sized organisations are the fastest-growing segment.

Sources: Gartner, Market Guide for Adversarial Exposure Validation, 2026; Grand View Research, CTEM market report, 2025. Intermediate years in the chart are illustrative, drawn at the report's 12.7% annual growth.

Know before we touch

The picture exists before your client signs.

The research engine observes every company once and keeps it current. When you add a client, most of what matters is already known, with where and when each fact was found. Anything we can't confirm is labelled or thrown out.

1Where we look

InfrastructureCertificate logs, DNS, internet scan dataRecordsRegisters, certificationsEventsBreach notices, known-exploited flawsWorkforceJob adverts, staff emails in breachesVendor referencesCase studies, procurement notices

2What we already hold · harbourlending.example

12 Aug 2026staging.harbourlending.example, a staging site nobody rememberedCertificate logFirm
LiveA VPN gateway whose banner shows its make and versionInternet scan dataFirm
LiveLicensed mortgage broker, so the FTC Safeguards Rule appliesState licence registerFirm
3 Sep 2026A payroll provider and an endpoint agent, named in a job advertJob advertLikely
2025A loan platform that names Harbour as a customerVendor case studyLikely
9 days agoA flaw in that VPN make added to CISA’s known-exploited listCISA KEVLikely
2019An FTP serverOld DNS record, no longer resolvesThrown out
Looked forThe internal payroll systemKnown to exist, not measurable from outsideCan't see

3What it becomes

Assets

3 domains, 38 host names, one forgotten.

Rules

FTC Safeguards: evidence the client will need.

Suppliers

Proposed for the client to confirm, ranked by blast radius.

Exposures

Likely until checked. A version match is never firm.

Coverage

What we cannot see comes first in the register.

FirmSeen directly in a source we trust, with its date.

LikelyInferred, and shown as likely until a check or the client confirms it.

Thrown outToo old, or contradicted by a newer source.

Can't seeKnown to exist, not measured. Listed, never hidden.

Supplier exposure

The suppliers nobody listed carry the widest damage.

Supplier monitoring is usually a separate product, priced per vendor the customer remembers to add. The identity provider and the agent on every laptop are the ones they forget. Outerwall finds them from the outside and ranks them by blast radius.

01

DNS names the obvious ones.

Mail exchange and sender records, verification tokens, CNAMEs and the sign-in realm reveal who runs a client’s mail, identity, hosting and software. All of it public, none of it asked for.

02

Job adverts and case studies name the rest.

“Experience with our payroll platform required.” A vendor’s case study that names the client as a customer. Each one is proposed for the client to confirm, with where it was found.

03

Ranked by blast radius.

How much damage a failure there would do. Catastrophic: the identity provider, and an endpoint agent that updates itself on every laptop. Severe: processors of regulated data. High: hosting. Moderate: peripheral software.

04

Seen across your whole book.

Northgate IT looks after 40 clients. 14 of them use the same payroll provider, and 31 the same identity provider. No client-by-client spreadsheet shows that.

05

When a supplier is breached, everyone affected knows within hours.

The payroll provider files a breach notice. All 14 clients are flagged in one view, with the evidence, within the 6-hour target. Northgate raises it with all of them in one morning.

We never test a supplier without that supplier’s own signed consent. Suppliers are observed from public sources only.

Safe by design

Nothing is touched until it's approved.

Research is passive. Active checks run only on assets the client has approved, after it has proven control, signed the scope and had 24 hours' notice. A blocked check is shown as blocked, never worked around.

The path to the first active check

  1. Domain addedPassive research only
  2. Assets confirmedThe client says what is its own
  3. Control provenA DNS record or a file
  4. Scope signedPer asset, inside a testing window
  5. 24 hours’ noticeOur scan addresses, before the first run
  6. Active checksApproved assets only

All five gates passed. Checks run on approved assets only, inside the agreed window, and the client’s contact already has our scan addresses.Stopped at control. The organisation sees its passive footprint and counts of issues by type. No active check runs, and no exposure detail is shown.

What we never do

  • Test a supplier

    Suppliers are observed from public sources. Testing one needs that supplier’s own signed consent.

  • Show detail before proof of control

    Until an organisation proves it controls a domain, it sees its footprint and counts of issues by type. Never the exposure detail.

  • Market to anyone with their exposure

    What we learn about an organisation is never used to sell to it.

  • Keep a leaked password or secret

    Any secret we detect becomes a keyed fingerprint and a count the moment it is collected. The value is never stored.

  • Let one client’s data reach another

    Separation is enforced by the database itself, for every partner and every client.

  • Let an AI model decide a finding

    Every decision is tested code. The same data always gives the same answer.

Prove the fix

A fix counts when two checks agree.

Most scanners close a finding when the next scan doesn't see it, even when a firewall blocked that scan. Outerwall records what every check actually reached. A finding closes only after two consecutive checks reached the asset and found it gone.

Finding lifecycle · harbourlending.example · VPN gateway

  1. FoundVPN flaw, confirmed
  2. TicketOpened in your PSA
  3. PatchedMarked fixed by your team
  4. Check 1Reached the asset · gone
  5. Check 2Reached the asset · goneBlocked by a firewall
  6. Confirmed fixedCounted, and in the evidence packAwaiting proof

Fast-moving changes

A new flaw on CISA’s known-exploited list that matches software a client runs. A new certificate or open port. Staff credentials in a breach or infostealer log. A lookalike domain. A ransomware group naming a client. A supplier’s breach, outage or insolvency.

Daily changes

New subdomains and addresses, DNS and email records. A change triggers a recheck of the one asset that changed, not a new scan of the whole estate.

Detection targets for clients and suppliers alike. The measure we hold ourselves to: the share of high and critical findings fixed, and confirmed fixed, within the agreed time.

Built for MSPs and MSSPs

Sold through you. Run from one view. Under your brand.

Outerwall is sold only through managed service providers. You see every client in one portfolio, work the fixes in the service desk you already use, and hand clients reports with your name on them.

MSPs

Recurring exposure management across your whole book.

One view of every client, ranked. Fixes flow into the service desk your technicians already use.

MSSPs

Confirmed findings and supplier alerts, without new noise.

Deterministic rules, evidence with every finding and coverage that shows its own gaps.

Their clients

Small regulated firms with no security team.

Mortgage brokers, tax preparers, investment advisers and medical practices, typically 20 to 200 staff.

  • Portfolio view

    Every client ranked in one place, with the suppliers they share across your book.

  • Tickets in your PSA

    ConnectWise, Autotask and HaloPSA. Ranked by blast radius, closed only when the fix is confirmed.

  • Under your brand

    Sold only through partners. Reports and the client portal carry your name.

  • Evidence packs

    Mapped to the FTC Safeguards Rule, SEC Regulation S-P and NYDFS Part 500.

  • One domain to start

    A new client sees its passive picture within an hour or two, before any scan touches its systems.

  • Testers for depth

    Annual penetration tests start from the estate Outerwall has already mapped.

The rules your clients answer to

Outerwall's output supports a client's compliance evidence. It does not, by itself, make a client compliant.

FTC Safeguards Rule16 CFR 314

Non-bank financial firms

Continuous monitoring, or an annual penetration test and vulnerability assessments every six months. Oversight of service providers.

SEC Regulation S-P2024 amendments

Broker-dealers, advisers, funds

Oversight of service providers, through due diligence and monitoring. Smaller firms from June 2026.

NYDFS Part 500New York

Financial services firms

Automated scans, an annual penetration test, risk-based remediation and a complete asset inventory.

PCI DSS v4.0.1Requirement 11.3.2

Anyone handling card data

Quarterly external scans by an Approved Scanning Vendor. Outerwall adds to those scans; it does not replace them.

HIPAA Security RuleProposed update

Healthcare and business associates

Proposed: scans every six months, a yearly penetration test and an asset inventory. Not yet final.

The name

Every organisation has an outer wall.

It is everything the internet can see: the hosts, the names, the suppliers that connect through it. Attackers study it before they try a door. Outerwall studies it first, and keeps watching.

The mark is that wall: eight segments around what it protects. One segment is lit. It is the one that was found, fixed, and proven fixed.

Design partners

Shape Outerwall with us.

We are working with a small group of US MSPs and MSSPs ahead of the first partner release in early 2027. Design partners get early access and a direct line to the people building it.

Start with your own estate

Every design partner starts by running Outerwall on its own domain, after proving control of it. You see exactly what your clients would see, and nobody else's data is involved.

  1. NowPilot with design partners
  2. Early 2027First partner release, tickets in your PSA
  3. 2027Supplier alerts within hours, automated confirmation of known-exploited flaws, Microsoft 365 and RMM connectors

We use these details only to reply to you.