Skip to content

Cybersecurity

Know what is exposed, who has access and what to fix first.

Cybersecurity is one of the two core disciplines at oxHaus. We assess the systems you run, the identities and access around them and what is visible from outside, then work through the fixes with your team in priority order. Every assessment runs against a scope you have authorised.

A security analyst reviewing activity on several monitors.
  • The glass and concrete façade of an office building.

    External exposure

    Domains, internet-facing services and credentials linked to your business, checked against the sources you authorise. A match is evidence to investigate, not proof that you have been breached.

  • A staff member holding an access card to a door reader.

    Identity and access

    Who can reach which system, through which accounts and roles, and how access is granted, reviewed and removed. Privileged, shared and service accounts are included.

  • An analyst watching screens in a monitoring room.

    Remediation

    Findings ranked by risk and effort, with the fix, the owner and a retest date agreed for each. Fixes can be carried out by us or by your own staff.

What an assessment can cover

  • Internet-facing services, TLS certificates and DNS records
  • Email authentication: SPF, DKIM and DMARC
  • Exposed or reused credentials linked to your domains
  • User, administrator and service accounts, and MFA coverage
  • Joiner, mover and leaver processes for access
  • Cloud and SaaS tenant configuration
  • Application authentication, session handling and input validation
  • Backups, logging and the ability to detect and recover from an incident

The exact scope, systems and testing windows are agreed in writing before any testing starts.

oxHaus Exposure

oxHaus Exposure is our own application for the external part of an assessment. It verifies that you control the domain, shows which business identities and portal accounts appear in exposure sources, and tracks each finding through to a fix.

Describe the systems you want assessed.

Security discovery records the scope, the systems involved and who can authorise testing. Nothing is tested until that is agreed.

Help improve this website

Optional analytics is off.