Skip to main content
Self-assessment · Worksheet · PDF

An external exposure maturity model that tells you where to stop.

Six levels, from no inventory anybody trusts through to remediation that actually terminates, scored across the seven areas an external exposure programme has to cover. For each level: what it looks like in practice, the question it cannot answer, and what moving up one level actually takes.

Written for the person building the business case — a CISO, a head of security, or whoever has been told to justify the renewal. It is a self-assessment, not a rating: you score it, nobody sees the result unless you show them, and the model says plainly which kinds of estate should stop well below the top level rather than implying everyone belongs there.

What is inside

Forty-two cells you can check, not forty-two aspirations

The six levels are published in full further down this page — the shape of the model is not the part worth an email address. What is gated is the part that has to be worked rather than read:

  • The six levels written out for each of the seven areas — attack surface, data and credential exposure, identity exposure, brand and domain, validation, third-party exposure, and the operating layer underneath all of them. Every cell describes a behaviour somebody outside your team could verify.
  • A self-scoring worksheet that produces a level per area and one overall profile, with the floor rule built into the arithmetic so the score cannot be averaged upwards.
  • For every cell, the three moves that most reliably advance it, ordered by what has to be true before the next one helps rather than by what they cost. Several of them are decisions rather than purchases.
  • What the top of the model costs, itemised into the part a platform can carry and the part that is people. The second is the larger of the two, and it is the half that decides whether the first was worth buying.
  • A target-profile sheet that asks for a target per area rather than one overall ambition, because raising every area at once is the plan that gets abandoned first.
  • A one-page version for a board or budget conversation: current profile, target profile, and what sits between them in plain language.
  • A re-score sheet with a date field, so the next reading has something to be compared against.

It carries no benchmark figures. We do not publish what proportion of organisations sit at each level because we have not measured it, and the only comparison the worksheet endorses is against your own previous score.

External Exposure Maturity Model

Six levels across seven areas, the scoring worksheet, the moves that advance each cell, and a one-page version for the board. We’ll email you a confirmation link — click it and the download starts.

By downloading, you agree to receive relevant communications. We respect your privacy.

The six level definitions are on this page, ungated, whether or not you fill this in. If you only wanted the shape of the model, scroll down — you already have it.

The six levels

Each level is defined by the question the one below it cannot answer

The third column is the one to read first. A maturity level is only meaningful if it names something the level below it structurally could not do — otherwise the model is a ladder of adjectives, and everybody scores themselves in the middle. The levels are also a dependency order rather than a difficulty order: each one is written to be unreachable while the one beneath it is not held.

Six levels of an external exposure programme, with the question each level cannot answer and what advancing from it takes
LevelWhat it looks like in practiceWhat it cannot answerWhat moving up one level takes
1 · Ad hoc The list of internet-facing systems lives in a spreadsheet, or in three spreadsheets that disagree with one another. Discovery happens when something breaks, when an auditor asks, or when a subsidiary is acquired and somebody wonders what came with it. Nobody in the room would defend the list as current. “What do we actually have?” — and therefore every question after it. A finding cannot be prioritised against an inventory nobody trusts, so severity arguments quietly become arguments about whether the asset is even ours. One list with an owner, built from the outside in — derived from the apex domains the organisation trades under rather than assembled from what the estate is believed to contain. The distance between those two things is the entire reason this level exists.
What puts an otherwise well-run security team here is rarely negligence. Acquisitions, regional subsidiaries and a decade of marketing microsites each add estate nobody was ever asked to hold, and past a certain size the list stops fitting in anybody’s head.
2 · Inventoried A maintained list and a scan against it on a cycle — quarterly, or annually in the weeks before an audit. The scope is defined by a person, the report carries a date, and between one report and the next the record is silent. What appeared, opened or changed between the scans, and what the list never carried in the first place. A scan is evidence about a scope. It is not evidence about an estate, and the difference only shows up after an incident. Discovery that derives the scope instead of accepting it: starting at the apex domain and resolving outwards, so a host nobody remembered to add is still found. Attribution matters more than discovery at this step — a host tied to the wrong company is a finding somebody can disprove in a meeting.
There is a real reason to stop here: a dated report against a defined scope is the artefact an audit asks to see. Producing that artefact and knowing what you own are different achievements, and only one of them is examined on a cycle — nothing on this page decides whether any particular obligation is met.
3 · Monitored Outside-in discovery running continuously, with nobody scheduling it. Every asset carries the date it entered scope and, where it has gone, the date it left. A change arrives as a dated finding with an owner rather than as a movement in a score. Which of these matters this week. Everything is dated and nothing is ranked, so the queue grows faster than anyone works it. It is also silent on exposure that does not present as a host — a credential in a stealer log, a look-alike domain, a file in a bucket nobody listed. Joining what is observed on one surface to what is observed on the others, so that separate observations about the same asset stop arriving as separate pieces of work in separate queues.
This is the level at which “when did you know” becomes answerable, and the first level a review cycle structurally cannot reach: between two annual reviews there is nothing to date.
4 · Correlated Findings resolve into one correlated exposure model. A credential in a stealer log, an administrative interface that stopped presenting a second factor, and a certificate about to expire on the same host arrive as one item with one owner and one priority — not as three tickets raised by three tools in three weeks. Whether what looks reachable actually is. Correlation raises confidence in what matters and orders the queue accordingly, but a prioritised list is still a list of inferences, and the application team knows it. Validation — and, before validation, the authorisation to perform it. This is the step at which the constraint stops being technical and starts being a conversation with whoever owns the system.
Prioritisation is the stage almost every published treatment of exposure management skips, because it is the one that cannot be bought as a feed. It is also the stage at which a security team stops having to argue that a finding is real.
5 · Validated Exposure is tested rather than inferred, where it is safe and authorised: Continuous Automated Red-Teaming against your own estate, bounded to inventory that discovery has already found and attributed to you. Each finding states which kind of evidence it is — validated, or observed and not validated. Whether anything was fixed. A validated finding is a better finding; it is not an outcome. A programme can validate impeccably for a year while the same three issues stay open, and the reporting will look excellent throughout. A recorded disposition on every finding, with a named owner and a date — and the discipline to keep the ones that were not fixed in the record rather than closing them quietly at quarter end.
Validation is bounded on purpose, and a model that implies otherwise is describing something nobody should buy. It runs against your own estate; testing a third party’s systems needs authorisation from the party that owns them, which in a supplier relationship is not yours to give.
6 · Closed Every finding reaches a recorded end state: fixed and re-checked, accepted in writing by a named owner with a review date, or shown to belong to somebody else. The record keeps the surfaces that were examined and returned nothing, and the occasions your own service levels were missed. Nothing further about your exposure — but it will not tell you whether this level was worth reaching in the area you reached it in. That question is the next section, and it is the one a maturity model usually declines to ask. Nothing sits above it. The work at this level is holding it: a level reached in one quarter and dropped in the next was a project, not a programme.
Most maturity models stop at validation, because closure is the level a vendor cannot sell and the only one a board can see. It is also the level that makes the five below it worth the money — a queue nobody terminates is an expensive way to be told the same thing repeatedly.

Six levels of an external exposure programme, with the question each level cannot answer and what advancing from it takes

1 · Ad hoc

What it looks like in practice
The list of internet-facing systems lives in a spreadsheet, or in three spreadsheets that disagree with one another. Discovery happens when something breaks, when an auditor asks, or when a subsidiary is acquired and somebody wonders what came with it. Nobody in the room would defend the list as current.
What it cannot answer
“What do we actually have?” — and therefore every question after it. A finding cannot be prioritised against an inventory nobody trusts, so severity arguments quietly become arguments about whether the asset is even ours.
What moving up one level takes
One list with an owner, built from the outside in — derived from the apex domains the organisation trades under rather than assembled from what the estate is believed to contain. The distance between those two things is the entire reason this level exists.

What puts an otherwise well-run security team here is rarely negligence. Acquisitions, regional subsidiaries and a decade of marketing microsites each add estate nobody was ever asked to hold, and past a certain size the list stops fitting in anybody’s head.

2 · Inventoried

What it looks like in practice
A maintained list and a scan against it on a cycle — quarterly, or annually in the weeks before an audit. The scope is defined by a person, the report carries a date, and between one report and the next the record is silent.
What it cannot answer
What appeared, opened or changed between the scans, and what the list never carried in the first place. A scan is evidence about a scope. It is not evidence about an estate, and the difference only shows up after an incident.
What moving up one level takes
Discovery that derives the scope instead of accepting it: starting at the apex domain and resolving outwards, so a host nobody remembered to add is still found. Attribution matters more than discovery at this step — a host tied to the wrong company is a finding somebody can disprove in a meeting.

There is a real reason to stop here: a dated report against a defined scope is the artefact an audit asks to see. Producing that artefact and knowing what you own are different achievements, and only one of them is examined on a cycle — nothing on this page decides whether any particular obligation is met.

3 · Monitored

What it looks like in practice
Outside-in discovery running continuously, with nobody scheduling it. Every asset carries the date it entered scope and, where it has gone, the date it left. A change arrives as a dated finding with an owner rather than as a movement in a score.
What it cannot answer
Which of these matters this week. Everything is dated and nothing is ranked, so the queue grows faster than anyone works it. It is also silent on exposure that does not present as a host — a credential in a stealer log, a look-alike domain, a file in a bucket nobody listed.
What moving up one level takes
Joining what is observed on one surface to what is observed on the others, so that separate observations about the same asset stop arriving as separate pieces of work in separate queues.

This is the level at which “when did you know” becomes answerable, and the first level a review cycle structurally cannot reach: between two annual reviews there is nothing to date.

4 · Correlated

What it looks like in practice
Findings resolve into one correlated exposure model. A credential in a stealer log, an administrative interface that stopped presenting a second factor, and a certificate about to expire on the same host arrive as one item with one owner and one priority — not as three tickets raised by three tools in three weeks.
What it cannot answer
Whether what looks reachable actually is. Correlation raises confidence in what matters and orders the queue accordingly, but a prioritised list is still a list of inferences, and the application team knows it.
What moving up one level takes
Validation — and, before validation, the authorisation to perform it. This is the step at which the constraint stops being technical and starts being a conversation with whoever owns the system.

Prioritisation is the stage almost every published treatment of exposure management skips, because it is the one that cannot be bought as a feed. It is also the stage at which a security team stops having to argue that a finding is real.

5 · Validated

What it looks like in practice
Exposure is tested rather than inferred, where it is safe and authorised: Continuous Automated Red-Teaming against your own estate, bounded to inventory that discovery has already found and attributed to you. Each finding states which kind of evidence it is — validated, or observed and not validated.
What it cannot answer
Whether anything was fixed. A validated finding is a better finding; it is not an outcome. A programme can validate impeccably for a year while the same three issues stay open, and the reporting will look excellent throughout.
What moving up one level takes
A recorded disposition on every finding, with a named owner and a date — and the discipline to keep the ones that were not fixed in the record rather than closing them quietly at quarter end.

Validation is bounded on purpose, and a model that implies otherwise is describing something nobody should buy. It runs against your own estate; testing a third party’s systems needs authorisation from the party that owns them, which in a supplier relationship is not yours to give.

6 · Closed

What it looks like in practice
Every finding reaches a recorded end state: fixed and re-checked, accepted in writing by a named owner with a review date, or shown to belong to somebody else. The record keeps the surfaces that were examined and returned nothing, and the occasions your own service levels were missed.
What it cannot answer
Nothing further about your exposure — but it will not tell you whether this level was worth reaching in the area you reached it in. That question is the next section, and it is the one a maturity model usually declines to ask.
What moving up one level takes
Nothing sits above it. The work at this level is holding it: a level reached in one quarter and dropped in the next was a project, not a programme.

Most maturity models stop at validation, because closure is the level a vendor cannot sell and the only one a board can see. It is also the level that makes the five below it worth the money — a queue nobody terminates is an expensive way to be told the same thing repeatedly.

The levels described above are worked separately for each of the seven areas in the worksheet, because the seven move independently and a single overall level hides that. Level 5 validation laid over a Level 2 inventory is exactly the mismatch this exercise exists to surface, and it is usually the most useful thing it produces.

How to run it

Five steps, and the order is not decorative

Scoring produces seven readings; the floor rule turns them into one; that decides which area is worth a move; and only then does a re-score have anything to measure. Run them out of order and the exercise produces a number that feels fair and changes nothing.

Where the ceiling sits

Most organisations should not be at the top of this model

Not in every area, and for some estates not in any of them. A maturity model that implies the top row is everybody’s destination has stopped being a diagnostic and become a proposal, and the reader it is written for has seen enough of those to price them accordingly. Below is where the ceiling sensibly sits for five shapes of estate — the recommendation is stated in words on each row, so nothing here rests on the colour of a chip.

Recommended ceiling by estate shape. Read it as guidance to argue with, not as a scoring rule.
Estate shapeWhat makes it distinctWhere the ceiling sensibly sits
Regulated financial estate Examined on the record, third-party arrangements in scope, and the question actually asked is when you knew rather than what you found. Level 6 on attack surface, identity exposure and third-party exposure. The evidence trail is the deliverable here; detection is the cheaper half of the work.
Consumer brand, large public surface Impersonation, look-alike domains and fake applications are a customer-harm problem before they are a security problem, and volume rather than ambiguity is the difficulty. Level 5 to 6 on brand and domain, Level 3 to 4 elsewhere. Correlation earns more than validation here, because these findings are rarely in doubt once seen.
B2B software company A concentrated estate that changes several times a week, and customers who ask about it in writing before they buy. Level 5 on attack surface and validation. Level 3 on brand is usually the honest answer, and writing that down in a security questionnaire costs nothing.
Distributed estate after acquisitions Several inherited estates, uneven documentation, and at least one subsidiary whose infrastructure nobody at the centre has ever enumerated. Level 3 everywhere before Level 5 anywhere. Correlation and validation laid over an inventory that is wrong is expensive theatre with a convincing dashboard.
Small team, single product One or two people carrying security alongside other work, and no realistic prospect of a queue being worked every day. Level 3 on attack surface and identity exposure, Level 2 elsewhere, and no apology for it. A level you can hold beats a level you can describe.
Key
  • The top of the model earns its cost here
  • Level 5 is a sensible ceiling
  • Raise the floor before raising the ceiling
  • Level 2 to 3 is a defensible place to rest

If your estate is genuinely two of these at once — a regulated group with a consumer brand attached, or a software company halfway through absorbing three acquisitions — score them as separate estates and keep the profiles apart. Merging them produces an average that describes neither, which is the same failure the floor rule exists to prevent one level down.

The cost of the top

The expensive half of Levels 5 and 6 is not software

This is the part a maturity model owes its reader and usually withholds, because it is the part that makes the top level look less attractive. The worksheet itemises it per area; the shape of it is the same everywhere.

Levels 5 and 6

What it takes to reach the top two levels, split by where the cost actually lands

What a platform carries
Continuous discovery and attribution, joining what is seen on one surface to what is seen on the others, validation of your own estate where it is safe and authorised, and the audit trail underneath all of it — including the surfaces examined that returned nothing. This half is buyable, it is measurable, and it is the cheaper of the two. It is also the half a vendor will spend the whole meeting on.
What people carry
Somebody has to own a disposition. Somebody has to argue with an application team about a fix window, write down an accepted risk with their own name against it, and come back to it on the review date they set. Somebody has to keep the findings that were not fixed in the record at quarter end. No platform performs any of that, and a queue arriving faster than it is worked is a liability rather than a capability — the evidence trail now shows you knew.
What decides whether it was worth it
Ask who outside the security team asks for the record in this area, and how often. Where the answer is a regulator, an examiner, an insurer or an enterprise customer’s procurement function, the evidence trail is the deliverable and Level 6 is what produces it. Where the answer is nobody, Level 3 is a defensible resting place and the money is better spent raising a different area off the floor. Ask it area by area rather than for the programme as a whole: the answer is rarely the same in all seven, and the areas where it is nobody are where a lower ceiling is a decision rather than a concession.

Method

How the model was built, and what it deliberately is not

A self-assessment is only worth running if the reader can see how it was constructed and where it declines to go. The exclusions below sit at the same weight as the method, because on a document headed “maturity model” they are the half most likely to be assumed rather than read.

External Exposure Maturity Model — construction and limits As of August 2026
  • Every cell describes observable behaviour, not intent. Each one is written so it can be checked by somebody who does not work for you — a thing you could show, rather than a thing you could describe.
  • The levels are a dependency order, not a difficulty order. Each is written to be unreachable while the level beneath it is not held, which is why the floor rule and not the average produces the programme score.
  • The seven areas were derived from what organisations are actually asked to evidence — by regulators, auditors, insurers and enterprise customers — rather than from a product catalogue. Two of them, validation and the operating layer, cut across the other five instead of describing a surface.
  • Scoring is per area. The worksheet asks for a target level per area as well, because a single overall target is the form of this exercise that reliably gets abandoned.
  • Nothing on the worksheet requires ShadowMap or any other platform. Where a level describes behaviour our platform is one route to, the worksheet says so rather than pretending the vendor writing it is absent.
  • The model is versioned and dated. If the levels change, the previous version stays available, because a score taken against a definition that has since moved is not comparable and should not be presented as though it is.

Deliberately excluded

  • No benchmark data. We publish no figure for what proportion of organisations sit at each level, in any industry or region, because we have not measured it. Any such number you have seen in this market is a survey of the people who answered a survey.
  • No score, grade, rating or certification. Nothing here produces an output that can be shown to a third party as an assessment of your organisation. It is a self-assessment and it says so on every page of the worksheet.
  • No vendor scoring. The model does not rank tools, does not have a column where a product goes, and does not tell you that a level requires a purchase.
  • No claim that the top level is the target. The section above names the estates that should stop at Level 2 or Level 3 in most areas, and that guidance is part of the model rather than a caveat attached to it.
  • No regulatory determination. Reaching a level is not compliance with anything, and no level on this page should be quoted to a regulator, an auditor or a board as evidence that an obligation has been met. What obligations apply to you, and whether they are met, belongs to your compliance function and your own advisers.
  • No universal validation claim. Level 5 describes testing your own estate where it is safe and authorised. It does not describe testing everything, and it never describes testing a third party’s systems on your say-so.

Questions this gets asked

Before you circulate a score

Is this another vendor maturity model where the top level is the vendor’s product?

It would be worth very little if it were, so the model is built to fail that test. The top level is closure — every finding reaching a recorded end state, including the ones accepted in writing and the ones that turned out to belong to somebody else — and closure is mostly organisational work that no platform performs on your behalf. The section on where the ceiling sits names the kinds of estate that should deliberately stop at Level 2 or Level 3 in most areas, which is not a thing a sales document says. Several levels do describe behaviour ShadowMap is one way to reach, and the worksheet says so where that is true rather than pretending the platform is absent.

Do we need to be at Level 6 everywhere?

Almost certainly not, and a model implying otherwise is a price list with levels drawn on it. The top of this model is a defensible target in the areas where somebody outside the security team asks for the record — which areas those are is a question only you can answer, and the section on where the ceiling sits is written to help you answer it. Buying the capability for the rest to sit at Level 6 buys a queue nobody works, and an unworked queue is worse than no queue because it is evidence you knew. The worksheet asks for a target level per area rather than one overall target for exactly this reason.

Who should fill it in, and can we do it without involving a vendor?

It is designed to be scored by the security team alone, in one sitting, with nobody from ShadowMap in the room — that is what makes it usable in a business case, because a self-assessment somebody else performed is a sales artefact. Scoring is more accurate when the person who runs vulnerability management and the person who answers customer security questionnaires both look at it, because they rarely score every area the same way, and the disagreement is the finding. Nothing on the worksheet requires our platform or any other.

How does this relate to a security rating or score from a rating service?

They measure different things and neither substitutes for the other. A rating service produces a number about your externally observable posture, largely so a third party can compare you with other organisations. This model produces a level about your programme — what it is able to observe, join, test and terminate — and it is scored by you, for you. A rating can move because a vendor changed a weighting; a level moves only when the programme’s behaviour changes. So if customers or insurers are asking you about a rating, no level on this page answers them, and raising one is not the way to move the other.

Score the model first. Then see one area of it for real.

An exposure snapshot takes the area you scored lowest and shows you what is actually observable from outside — written up, with nothing installed and no call needed to get it.