When the print dialog opens: choose "Save as PDF", then uncheck "Headers and footers" under More settings.
Platform Overview & Architecture
RECON — One Platform, One Attack Surface
RECON is a single platform that sees your organisation from every angle an attacker does: from the public internet, from inside your network, and from the heart of your identity infrastructure. Three assessments, one correlated attack surface, and board-ready scores your board can read.
Who should read this
- CISOs and security leaders who need one defensible view of organisational risk instead of four disconnected reports.
- IT and security teams responsible for external exposure, internal network hygiene and Active Directory in the same breath.
- Procurement and compliance functions evaluating a consolidated platform against point tools for NIS2, ISO 27001 and DORA evidence.
- Executives and boards who need risk expressed as a single number, not a list of CVE identifiers.
One platform, not four tools
Most organisations stitch together an external scanner, an internal vulnerability tool, an Active Directory auditor and a reporting layer — four contracts, four consoles, four data silos. RECON unifies all of them. The external attack surface, the internal network and the identity layer are scanned by the same platform and correlated into a single picture, so an attack path is never lost at a product boundary.
The Three Sides of Your Attack Surface
An attacker does not respect the boundary between "external" and "internal". They move from an exposed web service to an internal host to Domain Admin. RECON assesses all three layers and correlates them, so you see the same path the attacker would.
Correlated into one picture
The three sides are not separate reports. Domain computers seen in Active Directory enrich the internal asset inventory with authoritative operating-system data; external exposure, internal findings and identity weaknesses converge into a single attack surface. The result is one view in which an attack path can be followed end to end — from an exposed service on the internet to a privileged identity in the domain.
The Scan Engine — From Discovery to Board-Ready, Automatically
Every assessment runs the same disciplined, multi-phase pipeline. Raw discovery becomes a validated, risk-scored, executive-ready output in a single automated pass — with no manual triage, and without the analyst hours a manual exercise would take.
Because the pipeline is fixed and automated, there is no manual triage step between discovery and reporting. A scan that begins with a domain name or a network range ends with a risk-scored, compliance-mapped, board-ready report — produced automatically, without the analyst hours a manual sweep would demand.
The Pipeline, Running Live
Inside the RECON console, each stage of the pipeline reports as it completes — discovery, fingerprinting, exposure, correlation and scoring building the result in front of you, without an analyst driving each step by hand.
CVE Intelligence — Multi-Source, European-Native
A vulnerability missing from one database is often present in another. RECON queries multiple independent vulnerability sources in parallel, deduplicates and cross-references them, and enriches each finding with real-world exploitation signals — so coverage does not depend on any single feed.
RECON natively includes the EU official vulnerability database (ENISA EUVD) alongside US and global sources. For European organisations under NIS2, that means vulnerability intelligence sourced from European authorities, not only US feeds — aligned with where your regulator and your data already are.
RBVM v4 — One Score Your Board Understands
A critical CVE on a disconnected test box is not a crisis; a medium CVE on your payment gateway is. RBVM v4 weighs every finding by four factors and produces a single 0–10 risk score that is documented, reproducible and defensible — not an opaque vendor number.
Each factor, each weight and the final aggregation are documented and reproducible. The score reflects real, validated risk — confirmed findings count for more, false positives count for nothing. Your CISO can defend the number to the board; they cannot defend a list of 427 CVE identifiers.
How a 9.1 CVSS finding produces a 6.9 score
The same score renders in the console as a single gauge with its severity breakdown, so the board reads one number while the team keeps the detail behind it.
AI Analysis & Executive Reporting
RECON turns findings into decisions. An AI layer interprets the data, classifies the organisation against European regulation and produces reporting written for the people who sign off the budget — not only the security team.
Reports are formatted for the supervisor and the board, not only the SOC. Findings are mapped to NIS2, ISO 27001 and CIS, so a single scan produces both the technical detail your team needs and the evidence your auditor and your regulator expect.
Architecture & Security Principles
RECON is built to assess the most sensitive parts of your infrastructure without becoming a risk itself. Four principles are non-negotiable.
Honesty extends to the findings themselves. RECON distinguishes confirmed issues from candidates and clearly marks what is detect-only, so you never read an inflated "critical" that was never proven. The capability count shown to you reflects what actually runs — nothing padded.
Why RECON — and What It Replaces
RECON consolidates what most organisations buy as three or four separate products into one correlated platform, billed per real device and delivered as European sovereign infrastructure.
What RECON replaces
- An external attack-surface tool — RECON maps and risk-scores your internet-facing exposure natively.
- A vulnerability scanner (the role of Nessus, Tenable, Qualys or Rapid7) — RECON delivers vulnerability and misconfiguration coverage, plus OT/ICS and cloud-native checks, from one agentless probe.
- An asset-discovery and inventory tool (the role of runZero) — RECON resolves and inventories every device and reconstructs network topology.
- An Active Directory posture tool (the role of PingCastle or Purple Knight) — RECON brings identity attack-path analysis inside the same platform, with core identity checks live and advanced escalation paths in validation.
- A separate reporting and compliance layer — RECON maps findings to NIS2, ISO 27001 and CIS and renders the executive PDF itself.
Next steps
- Request a guided walkthrough of RECON across all three sides on your own attack surface.
- Run a first external scan to see your real internet-facing exposure and a sample risk score.
- Deploy the Scout probe in one network to see internal, OT/ICS and Active Directory assessment in a single pass.
Contact: [email protected] · orizon.one/services/recon · European sovereign infrastructure.