Identity · Cloud · Email · Brand · AI
You don’t have a tools problem.
You have an exposure problem.
Almost every organisation that gets breached already owned the tools that should have stopped it. CyberDNA measures what those tools were never built to see — then reduces your breach likelihood by 90% in 90 days, guaranteed.†
90 seconds8 questionsNo signup to start
Pick the surface you’re least sure about
Trusted by enterprises and critical-infrastructure operators across ANZ
The gap nobody budgets for
Your tools report events. Attackers walk paths.
A misconfiguration created in 2019 generates no logs until the day it is abused — and then every step looks like legitimate admin activity. That is not a detection failure. It is an exposure that was never measured.
// after the audit
“We only find misconfigurations when someone else points them out.”
Audits, insurers and incidents keep discovering things your team should have seen first. Then everything stops while you fix what an attacker could have used in minutes.
// alert fatigue
“Everything alerts. Nothing tells us what actually matters.”
Ten thousand events a week, and not one of them says this specific delegation is your most likely breach path. Severity lists send teams to fix hundreds of mediums while the handful of real paths stay open.
// the board question
“Can you prove our risk is going down?”
Leadership, auditors and cyber insurers all want the same thing: a defensible number that moves in the right direction. “We’re working on it” is not one.
Why five surfaces, one score
Attackers don’t respect your org chart. Neither should your risk number.
A leaked credential is an identity problem. It arrives by email, is validated against a cloud tenant, and is used to spin up a lookalike domain that invoices your customers. Four teams, four tools, four dashboards — one attack.
CyberDNA measures all five surfaces on the same scale, so exposure is comparable, trendable and reportable to a board in one figure — then reduced under a single accountable programme.
- Comparable — the same 0–100 scale across identity, cloud, email, brand and AI
- Trendable — re-scored monthly, so improvement is evidence rather than assertion
- Accountable — one partner owns the number, not five vendors owning five dashboards
One attack, four surfaces
A reused password surfaces in an unrelated breach
Identity exposure. No malware, no exploit — a valid credential in a dump you never see.
It arrives as a convincing internal email
Email exposure. Sent from an already-compromised mailbox, so your gateway never inspects it.
It unlocks an over-permissioned cloud role
Cloud exposure. One workload, one role, and access far beyond anything that role has ever used.
Your customers get invoiced from a lookalike domain
Brand exposure. On someone else’s infrastructure, targeting people your tools cannot protect.
Each step scores as “medium” in isolation. Together they are a critical path — which is why finding counts matter far less than combinations.
Measure → Prioritise → Close → Prove
One continuous loop, delivered as a managed outcome. Not a dashboard you have to run.
Establish the baseline
Read-only, API-based collection across the surfaces in scope. No MX changes, no agents. Findings become a single 0–100 exposure score with the evidence behind every point.
48h from access granted
Rank by attack path, not CVSS
Every finding is ranked by what an attacker would actually use first, and by how much closing it moves your score. You get three things to fix, not three hundred.
paths, not findings lists
Remediation-led, not alert-led
We do the closing work with your team — guided or fully managed, change-controlled, and reversible. This is the part most services hand back to you as a PDF.
90-day programme
Re-score and report
The same measurement runs again. Your score moves, the delta is attributable to specific closures, and the report is written for a board, an auditor or an insurer.
monthly · quarterly board pack
Baseline score
Read-only collection and your first exposure score, with attack paths mapped.
Critical paths closed
The exposures an attacker would reach first, remediated and verified.
Systemic fixes
The conditions that recreate exposure — process, privilege model, monitoring gaps.
Re-score & prove
Independent re-measurement, board-ready report, and the guarantee tested against it.
The services
Five managed programmes. One exposure score.
Start with the surface you are least sure about. Every programme runs the same loop and reports into the same number.
Managed Identity Resilience
Active Directory & Entra ID
Stale privilege, shadow admins, Kerberos weakness, delegation and leaked credentials — mapped as attack paths and closed continuously.
Explore MIR →
Managed Cloud Resilience
AWS, Azure & M365
Asset discovery, misconfiguration, entitlement sprawl and toxic combinations across a fragmented cloud estate.
Explore MCR →
Managed Email Resilience
Microsoft 365 & Google
Phishing, BEC and account takeover stopped at the mailbox — plus the quarantine and phishing-report triage your team is drowning in.
Explore MER →
Managed Brand Resilience
Domains, executives & customers
Lookalike domains, executive and brand impersonation, credential leaks, and managed takedowns with tracked SLAs.
Explore MBR →
Managed AI Resilience
Shadow AI & agent identity
AI tool discovery, non-human identity governance, data reachability and prompt-layer testing.
Explore MAR →
What the numbers look like
Outcome-driven, measured, and reported.
Target reduction in measured exposure score within 90 days, under the CyberDNA guarantee.
From access granted to baseline exposure report — read-only, API-based, no agents.
Attack surfaces measured on one comparable scale: identity, cloud, email, brand, AI.
Prioritised fixes per cycle — ranked by attack path, not by finding count.
The 20 checks we run first, so you can run them yourself.
The Hidden Identity Exposure Checklist is the same starting list our engineers work from — twenty checks against your own directory, and what a bad answer actually means. Six pages, no pitch.
PDF6 pagesInstant download
A 90% reduction in your measured exposure score within 90 days.
A guarantee with no stated measurement is marketing. Here is exactly what ours means, so you can hold us to it.
What is measured
- The CyberDNA Exposure Score for the surfaces in scope, established at day 0 by read-only assessment.
- The same methodology, re-run at day 90. No change of scale, no re-weighting mid-programme.
- The baseline and the method are documented in your engagement schedule before work starts.
What happens if we miss
- We continue remediation work at no additional service cost until the reduction is achieved.
- You get the full re-score data either way — including where we fell short and why.
- Exclusions are stated up front: remediation we recommend and you decline, and changes outside the agreed scope.
† Guarantee applies to the surfaces contracted under a CyberDNA managed programme and is measured using the CyberDNA Exposure Score methodology documented in your engagement schedule. Full terms: the 90-day guarantee.
“Why not just…?”
Fair question. Here is the honest answer for each thing you already own.
Entra ID P2 and Defender are strong at what they are built for: broad identity management and detecting known attack behaviours. Neither continuously maps misconfiguration, stale privilege and attack paths across a hybrid AD and Entra estate — and neither closes what it finds.
Microsoft tells you about the fire. It does not remove the fuel. CyberDNA complements the Microsoft stack rather than replacing it: we find and close the exposures those tools assume are already handled.
A SIEM correlates what happens. Exposure is not an event. A delegation created in 2019 produces zero logs until the day it is abused — and at that point every action in the chain uses legitimate permissions, so it reads as normal administration.
Detection and exposure management answer different questions. You need both; most organisations have only the first.
Most MSSP contracts are monitoring contracts: they are measured on alerts triaged and tickets raised, not on your risk going down. Ask yours a simple question — what is our exposure score, and what has it done over the last two quarters?
If the answer is a volume metric rather than a risk trend, you are buying vigilance rather than resilience. CyberDNA is measured on the second.
A pen test is a point-in-time sample by a skilled human, and it is genuinely useful. But it expires: your directory, cloud estate and mail flow change weekly, and the report does not.
Exposure management is the continuous version — measured monthly, trended, and tied to closure rather than to a findings list.
PAM controls the privilege you have onboarded into it. The exposures we find are the privilege nobody onboarded: nested group memberships, delegations set years ago, service accounts with static passwords, and non-human identities created by an integration.
PAM is a control. Exposure management is how you find out what the control does not cover.
The 90-second version is self-reported: eight weighted questions, a score, and your top three exposure factors. It is an indicator, and we say so on the result. It is genuinely useful for deciding where to look first, and it costs you nothing but the answers.
The full assessment is the real measurement — read-only API collection against your actual environment, 48 hours to a report, and no obligation to buy anything afterwards.
Delivered with enterprise technology partners
See your exposure before an attacker measures it for you.
The free assessment takes 90 seconds and gives you a score plus your top three exposure factors. If you want the real number, the full assessment reads your actual environment — read-only, no agents.
90 secondsNo signup to startNo agents, read-onlyNo obligation