User Guide

HRS Exposure — User Guide

How to run a scan, read your exposure grade and findings, get the full report, and turn results into action.

External exposure scanning · Resources Center · current as of June 2026

HRS Exposure shows you what an attacker sees when they look at your organization from the outside — your people, your brand, and your domains — before that information is used against you. It looks only at what is already discoverable on the public internet, so there's nothing to install and no access to grant. In a couple of minutes you get a graded picture of your external exposure and a clear, prioritized list of what to fix. This guide explains how to run a scan, read your results, and turn them into action.


Contents

  1. What HRS Exposure is
  2. How a scan works
  3. Running a free scan
  4. Your exposure snapshot
  5. Getting the full report
  6. Reading your grade
  7. The five exposure categories
  8. Findings and severity
  9. From a one-time scan to continuous monitoring
  10. Using the console
  11. How exposure connects to your Human Risk Score
  12. Privacy and how it works
  13. FAQ
  14. Glossary

1. What HRS Exposure is

Most security tooling looks inward — at the endpoints, mailboxes, and networks you control. HRS Exposure looks the other way: it takes the attacker's outside-in view of your organization and tells you what they'd find before they ever send a phishing email.

It answers questions an attacker asks first:

Because it works entirely from publicly discoverable sources, there is no agent to deploy, no mailbox to connect, and no scan of your internal systems. You point it at a domain; it reports what the outside world can already see.

The output is a single exposure grade (A–F) with a supporting posture score, broken down into five categories, each with specific, evidence-backed findings you can act on.


2. How a scan works

When you run a scan on a domain, HRS Exposure runs five independent checks ("modules") in parallel and then combines their results:

  1. Discover — it identifies your domain's public footprint: mail configuration, web presence, related and look-alike domains.
  2. Check — each module gathers evidence from public sources and threat intelligence (leaked-credential corpora, infostealer logs, domain registration data, email-authentication records, web/TLS configuration).
  3. Grade — a deterministic scoring engine turns the evidence into a grade for each category and an overall composite, along with a list of findings ranked by severity.
  4. Report — results appear as a snapshot immediately and as a full report you can keep.

A scan typically completes in well under a minute. Nothing about the scan touches your internal systems or requires you to change anything first.


3. Running a free scan

Anyone can run a free scan from the HRS Exposure landing page — no account required.

  1. Enter your domain (for example, yourcompany.com). You can also paste a work email; HRS Exposure will use its domain.
  2. Complete the brief anti-abuse check.
  3. The scan runs and your snapshot appears.

The free scan is rate-limited per network to prevent abuse, and it covers the live, domain-level categories. The deeper, person-level detail (which executives and which employees are exposed) is reserved for the full report and for monitored, domain-verified organizations — see section 9.


4. Your exposure snapshot

The snapshot is the at-a-glance result of a free scan. It's designed to tell you how exposed you are without exposing the details to anyone who happens to run a scan on your domain. It has three parts:

The exposure score. A gauge showing your overall grade letter (A–F), your posture score (0–100), and a plain-language risk band — low, moderate, or high exposure.

The risk summary. Counts of findings by severity — how many critical, high, medium, and low issues the scan surfaced — so you immediately know the shape of the problem.

Category status. A line for each of the five categories showing whether it's clear or has findings. The live categories (email, brand, and web posture) show their status directly; the person-level categories (executive and credential exposure) are summarized but their specifics are held back for the full report.

The snapshot deliberately shows you that you have exposure and how much — it does not print the exploitable specifics on a public page. To see the evidence behind each finding, request the full report.


5. Getting the full report

From the snapshot, choose Email me the full report and enter your work email. HRS Exposure sends you a private link to your complete report.

A few things worth knowing:

The full report is the artifact you share internally to drive remediation and the baseline you measure improvement against on your next scan.


6. Reading your grade

HRS Exposure expresses exposure as a letter grade and a posture score.

Grade Posture score What it means
A ~90–100 Low exposure. Strong external posture; few or no actionable findings.
B ~80–89 Low–moderate exposure. Generally healthy with a few items to tidy up.
C ~65–79 Moderate exposure. Real gaps an attacker could use; worth prioritizing.
D ~50–64 Elevated exposure. Multiple meaningful weaknesses.
F below ~50 High exposure. Serious, exploitable issues that need prompt attention.

The posture score runs 0–100, where higher is better — it measures how strong your posture is, not how much risk you carry. An A with a 95 means the outside world finds very little to work with; an F means an attacker has a lot to work with.

Two important points about how grading works:


7. The five exposure categories

Every scan covers the same five categories. Each one maps to a way attackers actually get in.

Credential exposure

What it checks. Leaked credentials and active infostealer infections associated with your domain, drawn from breach corpora and stealer-log intelligence. It surfaces how many accounts on your domain appear in known breaches and, critically, whether any are tied to active infostealer logs — which often include live session data, not just old passwords.

Why it matters. Reused and stolen credentials are the most common way attackers get an initial foothold. An infostealer hit is more urgent than an old breach because it can mean an attacker has a working session right now.

What you'll see. Counts of exposed accounts and breach categories, with severity raised for infostealer activity. HRS Exposure records only the presence of an exposure — it never stores passwords. With a verified domain and a synced roster, the report can show which employees are affected (see section 9).

What to do. Force resets for affected accounts, prioritize anyone with infostealer activity, and turn on phishing-resistant MFA.

Executive exposure

What it checks. The heightened exposure of your high-value people — executives, finance, and IT admins — whose public professional footprint and breach history make them prime targets for business email compromise (BEC) and impersonation.

Why it matters. Attackers research leadership before they strike. The easier an executive is to profile and the more their details have leaked, the easier they are to impersonate or target.

What you'll see. An assessment of which high-value roles are most exposed and why, in the full report.

What to do. Tighten executive impersonation controls (DMARC enforcement, display-name protection), brief high-value staff, and consider executive-specific monitoring.

Email spoofing (SPF / DKIM / DMARC)

What it checks. Whether your domain's email authentication actually stops someone from sending mail that looks like it came from you. It evaluates your SPF, DKIM, and DMARC records and policy.

Why it matters. Weak or missing email authentication is what lets attackers spoof your domain to phish your staff, customers, and partners. A DMARC policy of p=none, for instance, monitors but doesn't block spoofing.

What you'll see. A plain reading of each mechanism and the specific weaknesses — missing records, soft-fail SPF, or an unenforced DMARC policy.

What to do. Move DMARC toward enforcement (p=quarantine then p=reject), tighten SPF, and ensure DKIM is signing.

Look-alike domains

What it checks. Registered domains that resemble yours — typosquats and "cousin" domains — that could be used to impersonate you in phishing or fraud.

Why it matters. A convincing look-alike domain is the staging ground for credential-harvesting pages and invoice fraud. Knowing they exist lets you get ahead of them.

What you'll see. The look-alike domains discovered, so you can assess and act on the ones that matter.

What to do. Monitor the riskiest look-alikes, consider defensive registration of the most dangerous variants, and prepare takedown paths.

Web & TLS

What it checks. The security posture of your public web presence and TLS configuration.

Why it matters. A weak public web/TLS posture is both a direct risk and a credibility signal — it's part of the attack surface attackers probe first.

What you'll see. The specific web and TLS weaknesses found.

What to do. Address the flagged configuration issues with whoever runs your web infrastructure.


8. Findings and severity

Within each category, HRS Exposure emits findings — specific, evidence-backed observations. Every finding carries a severity:

Severity Read it as
Critical Act now. Directly exploitable or already being exploited (e.g., active infostealer sessions).
High Address soon. A clear, usable weakness.
Medium Plan to fix. Meaningful but not immediately dangerous.
Low Tidy up. Minor hygiene.

A good way to work a report: start at the top of the severity list, fix the criticals and highs first, and re-scan to confirm they've cleared and your grade has improved. Because each finding states why it was raised and the evidence behind it, you can hand individual findings to the right owner without re-explaining the context.


9. From a one-time scan to continuous monitoring

A free scan is a point-in-time snapshot. Your exposure changes constantly — new credentials leak, new look-alike domains get registered, DNS records drift. Monitored organizations get the continuous version:

Monitoring and per-employee detail are managed in the console by your administrator — see the Administrator Guide for setup.


10. Using the console

If your organization runs HRS Exposure as a monitored service, signed-in users get a console. What you can see and do depends on your role (your administrator assigns it):

The main areas:

Console (dashboard). Your at-a-glance posture: latest grade, number of monitored domains, your count of critical and high findings, exposed-account totals, and a list of recent scans.

Scan detail. Click any recent scan to open its full result — the composite grade and a breakdown by category, with every finding's severity, title, explanation, and count. Complete scans offer a downloadable report.

Domains. The list of domains under continuous monitoring, each with its status, re-scan cadence, next scheduled scan, and latest grade. Analysts and admins can add a domain, pause or resume it, remove it, or trigger an immediate re-scan.

Profile. Your account and password.

Everything you see is scoped to your own organization. You only ever see your organization's scans, domains, and findings.


11. How exposure connects to your Human Risk Score

HRS Exposure isn't a standalone scanner bolted onto the side — it's the external-signal source for the wider HumanRisk Shield platform.

When you run Exposure as part of HRS, external findings feed your people's Human Risk Score. A person whose credentials show up in an active infostealer log, or an executive who's highly exposed, carries more real-world risk — and Exposure's findings let that risk be reflected where it drives action: targeted training, tighter controls, and reinforcement aimed at the people who actually need it. In other words, what attackers can see about your people becomes a signal that helps protect them.

This connection is what separates "a list of exposures" from a closed loop: discover the external exposure, attribute it to real people, and reduce it through the rest of the platform.


12. Privacy and how it works

A few principles worth being explicit about, because they shape what HRS Exposure is and isn't:


13. FAQ

Do I need to install anything or give access to my systems? No. HRS Exposure works entirely from public sources. You point it at a domain.

Is the free scan really free, and is it limited? Yes, it's free. It covers the domain-level categories and is rate-limited per network to prevent abuse. Person-level detail requires the full report and, for the deepest detail, a verified domain.

Why does the snapshot hide some details until I get the report? So that running a scan on a domain doesn't hand exploitable specifics to just anyone. The snapshot shows your grade and the shape of your exposure; the full report — sent to your email — contains the evidence.

What does the grade actually measure? Posture. The score runs 0–100 where higher is better; the letter A–F summarizes it. Higher posture means less for an attacker to work with.

My grade is an A — am I safe? An A means low external exposure from what's publicly discoverable. It's a strong signal, not a guarantee, and it doesn't speak to your internal controls. Always read the category breakdown.

How often should I scan? Exposure changes continuously. A one-off scan is a useful baseline; continuous monitoring (re-scanning on a cadence) is how you actually stay ahead of new exposure.

Can I see which of my employees are affected? Yes — once your organization verifies ownership of the domain and syncs its roster. This is gated by design so no one can see another organization's people.

An attachment or check shows "not checked." What does that mean? A source couldn't be consulted for that item, so HRS Exposure says so honestly instead of implying it's clean.


14. Glossary


For setting up monitored domains, users, multi-tenant (MSP) portfolios, and reporting, see the HRS Exposure Administrator Guide. For onboarding support, contact your HRS administrator or the HRS team.