Teams jump into pentests or tool waves without knowing which assets are even in the outside-in picture. That creates scope creep, surprises, and reports nobody can prioritise with confidence.
Outside-in assessment — clarity before expensive active testing.
An outside-in assessment at SHELL-AFFECT is CASP: a passive view of the externally visible attack surface, only after domain authorisation, with analyst accountability and a signed report. Orientation for leaders and IT before budget flows into active testing or unclear tool waves.
- Kickoff with scope
- DNS-TXT gate
- Passive outside-in
Example kickoff (anonymised)
Scope: 1 primary domain + 2 subdomains, goal “board-ready outside-in clarity in 12 days”. DNS-TXT on day 0, 45-minute kickoff, CASP Lite, report review with IT and leadership. Deliverable: prioritised list of what should be fixed before a planned app pentest in Q3. Pentest remains a separate offer. Figures and names are anonymised; the flow matches typical engagements. Decision criteria stay explicit.
Outside-in assessment here is CASP: authorised, passive, reported. It prepares active tests or deliberately replaces them when the goal is exposure clarity only — never as a silent pentest.
This page’s job: Owns engagement and kickoff (how outside-in CASP runs). Surface picture lives on attack-surface; comparisons on vs-pentest/vs-scan.
Outside-in assessment — practical flow
What you can roughly expect (Lite-oriented):
- 01
Day 0
DNS-TXT, final scope, contacts.
- 02
Profiling
Passive outside-in work in scope.
- 03
Prioritisation
Business context + visibility + actionability.
- 04
Report
Signed deliverable, not raw-dump-only handoff.
- 05
Review
Walkthrough and next steps.
- 06
Optional after
Internal hardening, audit, or pentest — new scopes.
Active without outside-in is expensive blind flight
Before the first or next pentest, after M&A domain chaos, or when scanner output overwhelms the organisation.
Not for you if…
- You want red-team simulation without approval
- You only need a certification stamp without exposure work
- You refuse DNS-TXT or written scope
Outside-in assessment: how we differ — and what to watch.
Outside-in should create orientation before expensive active tests. Many offers are relabelled scans. We deliver authorised CASP with a report and clearly state it does not automatically replace a pentest.
How we differ on outside-in assessment
Prep, not a substitute for active tests
Outside-in sharpens scope — it does not automatically replace RoE and active validation.
DNS-TXT gate
No start without authorisation — not even “informally”.
Leadership-ready output
A map and priority, not only raw technical dumps.
Staged investment
Lite/Full and optional follow-ons — no forced maximum package.
What to watch in outside-in offers
- Outside-in without authorisation proof
- Same pitch as a “full pentest” without method separation
- No clarity on duration, domains, and deliverable
- Price without Lite/Full or scope logic
- Blanket promises that no active test will ever be needed after
- OSINT spam / personal doxxing without engagement ethics
Included vs. deliberately not (outside-in)
Typical boundaries:
- We do / include
Authorised outside-in assessment (CASP) with signed report
- We do / include
Advice on whether a later pentest makes sense
- We do / include
Clear domain and goal definition before start
- We do not / exclude
Active attacks in the outside-in scope
- We do not / exclude
Unauthorised OSINT against third parties
- We do not / exclude
Blanket “you are secure after this” claims
If you want orientation before a large test budget: scope meeting. If you want a mixed do-everything scan without limits, we are not the fit.
What you decide, what is authorised, what is out of scope.
Method boundaries first — no mixed CASP/pentest theatre.
What you can decide
Shared outside-in map before active investment.
What is authorised
DNS-TXT, passive method, report, clear limits.
How fast you get clarity
Weeks, not quarters of tool rollout.
What comes from you
Approval and review sessions.
Practical outcomes for you.
Sharpen scope
Better targets for later active tests.
Stakeholders aligned
One language for tech and leadership.
Optional follow-on
Audit/pentest only when useful.
Core offer and clear options.
CASP outside-in assessment
Lite or Full depending on domain breadth.
DNS-TXT gate
Authorisation before work.
Signed report
Handoff with priority.
Pentest prep
Link to active path when needed.
What you get
- Outside-in assessment report
- Prioritised actions
- Scope recommendation for follow-ons
- Clarity CASP vs active testing
Outside-in flow
- 01
Goal & domains
What decision should this enable?
- 02
DNS-TXT
Prove authorisation.
- 03
Assessment
Passive profiling.
- 04
Report
Priority and next steps.
Objections, answered honestly.
Is outside-in the same as OSINT spam?
No. Structured authorised profiling with a report — not arbitrary doxxing.
Do I always need a pentest after?
No. Often prioritisation and hardening are enough; active testing is optional.
What does it cost?
CASP Lite € 7,500, Full € 19,900 as public orientation.
How do I start?
Contact with goal and domains.
Is outside-in assessment the same as CASP?
At SHELL-AFFECT yes: CASP is our outside-in assessment product. Others often mean only a scan.
Lite or Full?
Lite for focused primary-domain baseline; Full for more domains/depth. Price orientation: Lite € 7,500, Full € 19,900.
Request an outside-in assessment
Share goal and domains briefly — we reply with a scope proposal.