FAQ
Continuous Monitoring

What is an externally observable security signal?

An externally observable security signal is a piece of evidence about an organisation’s digital environment that can be detected from outside its internal network. Examples include DNS records, certificates, open services, software fingerprints, security headers, exposed APIs, email protections, scripts and cloud endpoints. A signal is not automatically a vulnerability; its meaning depends on accuracy, ownership and context. ThingsRecon correlates multiple signals to discover assets and suppliers, validate relationships and monitor changes that could alter external exposure. In practice, teams should record the supporting evidence, confirm ownership and business criticality, and connect the finding to an accountable workflow. This prevents a useful observation from becoming another isolated score or dashboard alert. The strongest implementation combines external intelligence with internal knowledge, supplier engagement and documented risk decisions, creating a view that remains useful as the digital ecosystem changes.