Outside-in assessment — clarity before expensive active testing.

An outside-in assessment at SHELL-AFFECT is CASP: a passive view of the externally visible attack surface, only after domain authorisation, with analyst accountability and a signed report. Orientation for leaders and IT before budget flows into active testing or unclear tool waves.

  • Kickoff with scope
  • DNS-TXT gate
  • Passive outside-in
Concrete example

Example kickoff (anonymised)

Scope: 1 primary domain + 2 subdomains, goal “board-ready outside-in clarity in 12 days”. DNS-TXT on day 0, 45-minute kickoff, CASP Lite, report review with IT and leadership. Deliverable: prioritised list of what should be fixed before a planned app pentest in Q3. Pentest remains a separate offer. Figures and names are anonymised; the flow matches typical engagements. Decision criteria stay explicit.

Outside-in assessment here is CASP: authorised, passive, reported. It prepares active tests or deliberately replaces them when the goal is exposure clarity only — never as a silent pentest.

This page’s job: Owns engagement and kickoff (how outside-in CASP runs). Surface picture lives on attack-surface; comparisons on vs-pentest/vs-scan.

Checklist

Outside-in assessment — practical flow

What you can roughly expect (Lite-oriented):

  1. 01

    Day 0

    DNS-TXT, final scope, contacts.

  2. 02

    Profiling

    Passive outside-in work in scope.

  3. 03

    Prioritisation

    Business context + visibility + actionability.

  4. 04

    Report

    Signed deliverable, not raw-dump-only handoff.

  5. 05

    Review

    Walkthrough and next steps.

  6. 06

    Optional after

    Internal hardening, audit, or pentest — new scopes.

Problem & fit

Active without outside-in is expensive blind flight

Cost of the status quo

Teams jump into pentests or tool waves without knowing which assets are even in the outside-in picture. That creates scope creep, surprises, and reports nobody can prioritise with confidence.

What “done” looks likeAn authorised outside-in assessment that gives leaders and IT the same map — before the next large test budget.
Ideal before large security investments

Before the first or next pentest, after M&A domain chaos, or when scanner output overwhelms the organisation.

Not for you if…

  • You want red-team simulation without approval
  • You only need a certification stamp without exposure work
  • You refuse DNS-TXT or written scope
Differentiation & buying guide

Outside-in assessment: how we differ — and what to watch.

Outside-in should create orientation before expensive active tests. Many offers are relabelled scans. We deliver authorised CASP with a report and clearly state it does not automatically replace a pentest.

How we differ on outside-in assessment

Prep, not a substitute for active tests

Outside-in sharpens scope — it does not automatically replace RoE and active validation.

DNS-TXT gate

No start without authorisation — not even “informally”.

Leadership-ready output

A map and priority, not only raw technical dumps.

Staged investment

Lite/Full and optional follow-ons — no forced maximum package.

What to watch in outside-in offers

  • Outside-in without authorisation proof
  • Same pitch as a “full pentest” without method separation
  • No clarity on duration, domains, and deliverable
  • Price without Lite/Full or scope logic
  • Blanket promises that no active test will ever be needed after
  • OSINT spam / personal doxxing without engagement ethics

Included vs. deliberately not (outside-in)

Typical boundaries:

  • We do / include

    Authorised outside-in assessment (CASP) with signed report

  • We do / include

    Advice on whether a later pentest makes sense

  • We do / include

    Clear domain and goal definition before start

  • We do not / exclude

    Active attacks in the outside-in scope

  • We do not / exclude

    Unauthorised OSINT against third parties

  • We do not / exclude

    Blanket “you are secure after this” claims

If you want orientation before a large test budget: scope meeting. If you want a mixed do-everything scan without limits, we are not the fit.

How delivery works

What you decide, what is authorised, what is out of scope.

Method boundaries first — no mixed CASP/pentest theatre.

/ 01

What you can decide

Shared outside-in map before active investment.

/ 02

What is authorised

DNS-TXT, passive method, report, clear limits.

/ 03

How fast you get clarity

Weeks, not quarters of tool rollout.

/ 04

What comes from you

Approval and review sessions.

What changes

Practical outcomes for you.

01

Sharpen scope

Better targets for later active tests.

02

Stakeholders aligned

One language for tech and leadership.

03

Optional follow-on

Audit/pentest only when useful.

In the package

Core offer and clear options.

01
Core

CASP outside-in assessment

Lite or Full depending on domain breadth.

02
Bonus

DNS-TXT gate

Authorisation before work.

03
Bonus

Signed report

Handoff with priority.

04
Optional

Pentest prep

Link to active path when needed.

What you get

  • Outside-in assessment report
  • Prioritised actions
  • Scope recommendation for follow-ons
  • Clarity CASP vs active testing
Steps

Outside-in flow

  1. 01

    Goal & domains

    What decision should this enable?

  2. 02

    DNS-TXT

    Prove authorisation.

  3. 03

    Assessment

    Passive profiling.

  4. 04

    Report

    Priority and next steps.

FAQ

Objections, answered honestly.

Is outside-in the same as OSINT spam?

No. Structured authorised profiling with a report — not arbitrary doxxing.

Do I always need a pentest after?

No. Often prioritisation and hardening are enough; active testing is optional.

What does it cost?

CASP Lite € 7,500, Full € 19,900 as public orientation.

How do I start?

Contact with goal and domains.

Is outside-in assessment the same as CASP?

At SHELL-AFFECT yes: CASP is our outside-in assessment product. Others often mean only a scan.

Lite or Full?

Lite for focused primary-domain baseline; Full for more domains/depth. Price orientation: Lite € 7,500, Full € 19,900.

Next step

Request an outside-in assessment

Share goal and domains briefly — we reply with a scope proposal.

Scope before active workNext step
Request a scope meeting