Every security scan ends with a number, and everyone hopes it's zero. But zero has two very different meanings: we looked and found nothing, or we couldn't look. Most scanning tools don't tell you which one you got. TONK, our external attack surface management (EASM) platform, now does.
The quiet failure mode of security scanning
Modern web estates are built to resist automated probing — and that's a good thing, right up until it isn't. A web application firewall (WAF) that answers every request on a host's behalf doesn't just block attackers; it blocks the scanner you've engaged to find your weaknesses. The scan runs, finds nothing, and reports a clean host. The vulnerabilities are still there. The firewall simply hid them from the one party you wanted to see them.
It's not only firewalls. Scans time out. Hosts drop connections halfway through. Some targets have no web surface to test at all. In every one of those cases, the traditional answer is the same reassuring green zero — and a security team makes decisions on assurance the scan never actually provided.
A finding you can act on. A false clean you can't even see.
What's new: every result carries a coverage verdict
TONK now attaches an explicit coverage verdict to every host in an active scan — across web infrastructure analysis, application testing, and infrastructure probing. Each host reports whether it was fully scanned, whether the scan was incomplete, whether the host was skipped because there was nothing to test, or whether a firewall masked it from us.
The verdict follows the result everywhere it goes: the scan results pages, the exported reports, and the monthly review our managed-service clients receive. A host we could not fully see displays exactly that — never an unqualified clean. And when we can tell before a long scan starts that a firewall is going to answer every request identically, we skip the wasted effort and record the host as masked, so the time goes into targets we can genuinely assess.
What this means for your team
- No false assurance — a green zero now means the scan genuinely looked, on every actively scanned host.
- Masked hosts become visible work — a firewall-masked host is surfaced as its own item, so you can decide whether to allow-list your scanning partner or accept the blind spot knowingly.
- Honest reports — coverage status appears in reporting alongside findings, so the audience reading the report sees the same caveats your analysts do.
Honesty extends to reporting: the OWASP Top 10 report
The same principle now shapes our newest report. TONK's Reporting Centre can map your active web and application findings onto the OWASP Top 10 (2021) — the framework auditors, boards and development teams already use as a shared language for web risk.
Crucially, the report includes a per-category coverage note. Some OWASP categories — security logging and monitoring failures, for instance — simply cannot be observed from outside your network. Rather than leaving those rows blank and letting a reader assume a clean bill, the report says plainly what external assessment can and cannot see. Findings that don't fit a category are listed explicitly, not silently dropped.
We think this is what security reporting owes its readers: a result you can defend in front of an auditor, because the report states its own limits.
Why we built it this way
External attack surface management exists to show you what attackers see. But an attacker probing your estate knows when a firewall is stonewalling them — they adapt, route around it, or move to a softer target. A scanner that doesn't notice the same thing isn't showing you the attacker's view; it's showing you the firewall's marketing. Coverage honesty closes that gap: every result now tells you not just what we found, but how far we could genuinely see.