Step 1 — Request an Exposure Review
1
Schedule or Email to Request Access
Visit leveragecyber.com and click Schedule a Confidential Exposure Review to book time directly on an analyst’s calendar. Alternatively, send an email to contact@leveragecyber.com with your name, organization, and a brief description of what you’re looking to assess.
2
Expect a Response Within One Business Day
A Leverage Cyber analyst will contact you within one business day to confirm your request and schedule a 30-minute kickoff call. The call covers your organization’s scope, your primary concerns, and the expected delivery timeline for your initial report.
3
No Legal Agreement Required to Start
You do not need to sign an NDA, a master services agreement, or any other legal document to participate in the initial consultation. Leverage Cyber treats all pre-engagement conversations as confidential by default. Formal agreements are executed before report delivery, not before the conversation begins.
What You’ll Need to Provide
Leverage Cyber conducts entirely passive reconnaissance — meaning your only obligation is to identify the scope of what you want assessed. Before or during the kickoff call, have the following information ready:- Primary organization domain — the main public-facing domain your company operates under (e.g.,
yourcompany.com) - Subsidiary and acquired company names or domains — any brands, business units, or recently acquired companies you want included in scope
- Legal entity name — the registered legal name of your organization, which helps analysts identify assets registered under different names than your trade name
- Primary point of contact — the name, email address, and phone number of the person who will receive reports and alerts
What You Do NOT Need to Provide
Leverage Cyber’s passive reconnaissance methodology is designed to operate without any access to your internal environment. You will never be asked for:- Network credentials or administrative passwords
- VPN access or remote access to internal systems
- Installation of any agent, sensor, or software on your infrastructure
- Firewall rule changes, allowlisting of IP addresses, or network configuration changes
- Involvement from your IT or network operations teams
After Kickoff
Once the kickoff call concludes and scope is confirmed, Leverage Cyber begins passive reconnaissance immediately. No further action is required from you until your report is ready for delivery. You will receive a confirmation email within a few hours of the kickoff call that includes:- A summary of the agreed scope (domains, subsidiaries, entity names)
- The expected delivery date for your initial 48-hour assessment report
- The name and contact details of your assigned analyst
- Instructions for accessing your secure report delivery portal
Engagement Types
- One-Time Assessment
- Continuous Monitoring Subscription
A one-time assessment gives you a point-in-time snapshot of your external attack surface. It is ideal for organizations that want to understand their current exposure before committing to ongoing monitoring, or for teams preparing for a merger, acquisition, audit, or compliance review.Scope: All domains, subsidiaries, and entity names agreed upon during the kickoff call.Timeline: Initial assessment report delivered within 48 hours of scope confirmation.Deliverables:
- 48-hour external attack surface assessment report
- Full inventory of discovered assets (domains, subdomains, IPs, exposed services, email infrastructure)
- All findings quantified as Annual Loss Expectancy (ALE) in dollars
- Prioritized remediation recommendations ranked by ALE impact
All communications, report delivery, and findings data are handled through secure, encrypted channels. Reports are never transmitted via unencrypted email. Your data is accessible only to authorized contacts on your account and to the Leverage Cyber analysts assigned to your engagement.