> ## Documentation Index
> Fetch the complete documentation index at: https://docs.leveragecyber.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Quick Start: Your First Exposure Assessment in 48 Hours

> Schedule a confidential exposure review, provide your domain, and receive a full attack surface map with ALE-based risk scores in 48 hours.

By the end of this process, you will have a complete external attack surface map of your organization — every exposed domain, leaked credential, misconfigured service, and third-party risk that an attacker could leverage against you, each quantified as Annual Loss Expectancy (ALE) in dollars. No software to install, no network access to grant, no disruption to your operations. From first contact to actionable risk report, the entire engagement is designed to deliver maximum clarity with minimum friction.

<Steps>
  <Step title="Schedule Your Confidential Exposure Review">
    The first step is a brief, no-obligation conversation with the Leverage Cyber team to scope the engagement. Reach out through either of these channels:

    * **Email:** [contact@leveragecyber.com](mailto:contact@leveragecyber.com)
    * **Website:** Use the request form at [leveragecyber.com](https://leveragecyber.com) to book directly.

    There are no prerequisites to getting started:

    * **No NDA required to initiate.** You can have an introductory conversation and receive a sample deliverable before signing anything.
    * **No software to install.** Leverage Cyber's reconnaissance is entirely external — nothing is deployed inside your environment.
    * **No network access needed.** You do not provide credentials, VPN access, or firewall exceptions of any kind.

    The scoping call typically runs 20–30 minutes. You will leave with a clear understanding of the engagement timeline, deliverable format, and what Leverage Cyber will cover in the initial assessment.
  </Step>

  <Step title="Provide Your Organization Details">
    Once the engagement is confirmed, you provide a small set of seed information. This is all Leverage Cyber needs to begin autonomous discovery:

    | What You Provide                    | Why It Matters                                                                             |
    | ----------------------------------- | ------------------------------------------------------------------------------------------ |
    | Primary domain (e.g., `acme.com`)   | The root anchor for all subdomain, certificate, and DNS enumeration                        |
    | Known subsidiaries or brand domains | Ensures related entities and acquired companies are included in scope                      |
    | Legal entity name                   | Used to trace corporate relationships, registered trademarks, and employer-linked accounts |

    From these inputs, Leverage Cyber autonomously discovers and maps the full scope of your external footprint — including assets your team may not know exist. You do not need to provide an asset inventory, a network diagram, or any internal documentation.
  </Step>

  <Step title="Receive Your 48-Hour Initial Assessment">
    Within 48 hours of receiving your seed details, Leverage Cyber delivers your Initial Assessment as a secure, structured report. The assessment covers:

    * **Domain and subdomain map** — every public-facing hostname, IP address, and DNS record associated with your organization, including forgotten or abandoned subdomains.
    * **Credential exposures** — employee and executive email addresses found in breach databases, credential stuffing lists, and paste sites, with breach source and exposure date.
    * **Email security gaps** — SPF, DKIM, and DMARC configuration review across all identified sending domains, flagging gaps that enable phishing and spoofing.
    * **Shadow IT findings** — unsanctioned SaaS accounts, exposed cloud storage (S3 buckets, Azure Blobs, GCS), and third-party integrations tied to your domain that fall outside IT's control.
    * **Third-party exposure** — key vendors, suppliers, and technology partners whose own exposure creates downstream risk to your organization.

    The report is delivered through a secure channel agreed upon during scoping. A member of the Leverage Cyber team is available to walk you through the findings immediately upon delivery.
  </Step>

  <Step title="Review and Act on Your Risk Report">
    At the end of week one, you receive your full **Risk Report and Remediation Roadmap** — the complete analytical output of the engagement. This is the document your security team, CTO, and board can all read from the same page.

    The Risk Report includes:

    * **Prioritized remediation roadmap** — every finding ranked by Annual Loss Expectancy (ALE), so you address the highest-dollar-risk items first regardless of technical severity.
    * **ALE per finding** — each exposure is assigned an expected annual financial loss figure derived from breach likelihood, industry loss data, and organizational context. You see exactly how much each unresolved issue is costing you in expected terms.
    * **ROI calculation** — the report frames the cost of remediation against the ALE it eliminates, giving you a straightforward return-on-investment case for every action item.
    * **Executive summary** — a non-technical narrative your leadership team can use for board reporting, cyber insurance applications, and internal prioritization discussions.

    Remediation steps are specific and actionable — not generic best-practice suggestions. Each item tells you what to fix, which team owns it, and what the expected risk reduction is once resolved.
  </Step>
</Steps>

## What Happens Next

After you complete the initial engagement, Leverage Cyber activates continuous monitoring on your attack surface. This is not a scheduled rescan — it is ongoing, passive surveillance that runs 24 hours a day, seven days a week.

When something changes — a new subdomain appears, a credential batch containing your employees' addresses surfaces in a breach dump, a lookalike domain is registered — your team receives a real-time alert with context and recommended action. You stop finding out about exposures after the fact.

Every quarter, Leverage Cyber conducts a full reassessment of your organization. Quarterly reassessments account for business changes that reshape your attack surface: new hires and departures, technology stack changes, acquisitions, office expansions, and shifts in your vendor ecosystem. Your risk profile stays accurate and current throughout the year.

<Tip>
  After receiving your Initial Assessment or Risk Report, schedule a findings review call with the Leverage Cyber team. Walking through the report live — with a practitioner who can answer questions in real time — dramatically accelerates your team's ability to triage, assign ownership, and begin remediation. Email [contact@leveragecyber.com](mailto:contact@leveragecyber.com) to book your review session.
</Tip>
