Situation
A leading UK university needed to regain control of a fast-growing digital footprint created by decentralised departments, research groups, cloud services, and third-party suppliers. While the security team had strong internal controls, they lacked a complete view of what was visible from the internet, including assets created outside central IT and services operated by suppliers on the university’s behalf.
At a glance
Organisation: UK University
Sector: Higher Education
Situation: The university lacked a complete view of what was externally visible from an attacker's perspective
Challenges: Unknown assets, supply chain and third-party risk
Solution: Utilising NCC Group's EASM solution to provide continuous discovery and monitoring of internet-facing assets, including third-party services
Results: Improved visibility of external assets, enhanced supplier assurance, faster remediation, and reduced third-party cyber risk
The challenge: a complex university ecosystem with limited external visibility
Like many higher education institutions, the university operated in a highly distributed environment. Academic departments, research centres, student services, alumni teams, and external partners all relied on different platforms, domains, applications, and cloud-hosted services to support teaching, research, administration, and engagement.
This created three major security challenges:
• Unknown and unmanaged assets: Legacy microsites, forgotten subdomains, test environments, exposed cloud services, and externally hosted applications were not always recorded in internal inventories.
• Supply chain exposure: Third-party platforms used for learning, recruitment, research collaboration, events, and student engagement created risk beyond the university’s direct control.
• Manual, fragmented assurance: Supplier reviews and internal asset checks were periodic, making it difficult to keep pace with new services, configuration changes, and emerging vulnerabilities.
The result was a widening visibility gap. The security team knew that attackers would not distinguish between an official university system, a departmental platform, or a supplier-managed service. If it carried the university’s brand, data, or connectivity, it could become an entry point.
The solution: continuous discovery from the attacker’s perspective
NCC Group worked with the university to map its external attack surface from the outside in. Rather than relying only on existing asset registers or supplier-provided information, the solution continuously discovered internet-facing assets associated with the university, its departments, and its supply chain.
NCC Group's External Attack Surface Management (EASM) solution helped the university:
• Build a more complete inventory of public-facing assets, including domains, subdomains, IP addresses, cloud services, exposed applications, certificates, and supplier-hosted services.
• Identify assets that were unknown to central IT, no longer owned by an active team, or missing from security monitoring processes.
• Detect third-party exposures linked to suppliers, partners, and platforms operating on behalf of the university.
• Prioritise findings based on exploit intelligence, business context, and potential impact rather than overwhelming the team with unfiltered alerts.
• Route remediation actions to the right team, improving accountability and reducing time to resolution.
With continuous monitoring in place, the university moved from periodic reviews to proactive exposure management - helping the security team spot risky changes quickly and reduce the likelihood of unknown assets becoming exploitable weaknesses.
The outcome: stronger visibility, faster action, and reduced third-party risk
Within the first phase of the programme, the university established a clearer, risk-prioritised view of its external exposure. The security team could see which assets were legitimate, which required remediation, and which third-party services introduced avoidable risk.
The engagement delivered measurable operational improvements:
• Improved asset visibility: Unknown and unmanaged internet-facing assets were discovered and brought into governance.
• Reduced exposure: High-risk misconfigurations, outdated services, and unnecessary public-facing assets were prioritised for remediation.
• Better supplier assurance: The university gained evidence-led insight into third-party services connected to its brand, data, and operations.
• Faster remediation: Findings were assigned to the right internal teams or suppliers, reducing ambiguity and accelerating action.
• Stronger board-level reporting: Security leaders could communicate external exposure and third-party risk in a clearer, more defensible way.
Customer quote
“We knew our university’s digital footprint was expanding, but we didn’t have a reliable way to see everything attackers could see, especially assets created by departments or managed by suppliers. NCC Group helped us close that visibility gap, prioritise the risks that mattered most, and build a more proactive approach to third-party cyber risk.”
See and secure every internet-facing asset across your institution with our free personalised External Attack Surface Management report.
Understand how your institution can reduce exposure, protect sensitive data, and strengthen cyber resilience across a distributed campus environment.