Cyber exposure & threat operations

Know what is exposed. Know what it reaches.

Lodemark maps every asset you own across five strata, traces how exposure reaches regulated data, and turns the handful of paths that actually break you into owned work with a date on it.

16,567Assets discovered
7Live paths to Core
58 → 34Exposure score

Illustrative product data. Nothing on this site performs a live scan.

Northfleet Group · exposure surface

Demo data
S1 · Edge1,284S2 · Gateway312S3 · Workload4,870S4 · Identity9,615S5 · Core486supplier-docsedge-proxy-rotanalytics-lakesvc-datalake-ingestnfg-invoice-archiveCHOKE POINT APPLIEDEXPOSURE SCORE34-242 QUARTERS
  • S1 Edge1,284
  • S2 Gateway312
  • S3 Workload4,870
  • S4 Identity9,615
  • S5 Core486

16,567 assets across five strata, from the public edge down to regulated data. Discovery is continuous, and 37 of these appeared this week.

Built for security teams like
  • Harlowe Maritime
  • Vantle Payments
  • Brantford Health
  • Ostergaard Energy
  • Kirkwall Rail
  • Petronell Group
The problem

Four thousand findings is not a security programme. It is a queue.

Posture tools are good at finding things and bad at saying which of them matter. So the backlog grows, engineering learns to ignore security tickets, and the one path that genuinely reaches your customer master sits at position 812 because its CVSS score is a 6.4.

  • Severity describes the vulnerability, not your environmentA critical on an unreachable host is a worse use of a Tuesday than a medium two hops from regulated data.
  • Inventories are written by people who rememberThe staging clone, the acquired subsidiary’s relay and the 2021 vendor portal are never on the list.
  • Nobody can prove the programme is workingOpen-finding counts go up when you look harder. That makes them useless as a board metric.
How it works

Five moves, in the order a security team actually needs them

Every surface in Lodemark maps onto one of these. If a feature does not serve one of them, it is not in the product.

  1. 01

    Discover

    Continuous discovery across domains, cloud accounts, APIs, identities, endpoints and the SaaS holding your data. Ownership is inferred, then confirmed by a human.

  2. 02

    Understand

    Assets are placed on five strata, from the internet edge down to regulated data. Relationships between them become traversable paths, not a wall of dots.

  3. 03

    Prioritise

    A finding matters when it sits on a path that terminates somewhere expensive. Everything else waits its turn, and we say so plainly.

  4. 04

    Act

    Choke points collapse many findings into one fix. Each one becomes a ticket in the tracker the owning team already uses, with an SLA and a named human.

  5. 05

    Prove

    Exposure score, path count and remediation velocity over time, with the measurement method written out so nobody has to trust the number blindly.

Everything you own, including what nobody remembers owning

How exposure actually reaches what matters

The seven paths that break you, not the 4,000 that do not

The model

Exposure has a depth, and depth is what makes it expensive

Assets sit on five strata, from the public edge down to regulated data. A finding on S1 is an inconvenience. A path from S1 to S5 is an incident waiting for a date.

Demo tenant · Northfleet Group

Exposure score, 26 weeks. 78 → 34.

  • S1

    Edge

    Anything the public internet can reach without credentials.

    1,284 assets · 37 exposed
  • S2

    Gateway

    Ingress control: load balancers, WAF, VPN, API gateways.

    312 assets · 14 exposed
  • S3

    Workload

    Compute, containers, functions and the services they run.

    4,870 assets · 61 exposed
  • S4

    Identity

    Human accounts, machine identities, roles and entitlements.

    9,615 assets · 28 exposed
  • S5

    Core

    Regulated data stores, secrets and the systems of record.

    486 assets · 6 exposed
Live path · AP-01

Supplier exchange to invoice archive

An anonymous listing on the supplier exchange leaks object keys. Those keys resolve through the ingest identity, which can read the invoice archive because the bucket policy grants the analytics role without a prefix restriction.

Entry point
supplier-docs.northfleet.io
Destination
nfg-invoice-archive
Blast radius
7 years of invoices · 2,140 supplier records · 4 downstream reports
Choke point: Scope the ingest trust policy to the task role. Removes 4 of 7 live paths and drops the exposure score by 9 points.
How path modelling works
AP-01: Supplier exchange to invoice archiveAttack path from supplier-docs.northfleet.io to nfg-invoice-archive, 5 hops descending through the Edge, Gateway, Workload, Identity, Core strata.S1 · EdgeS2 · GatewayS3 · WorkloadS4 · IdentityS5 · Coresupplier-docs.northfleet.ioedge-proxy-rotnfg-analytics-lakesvc-datalake-ingestnfg-invoice-archiveCHOKE POINT
The product

This is the real interface, not a screenshot

Filter it, sort it, select a node, advance a finding. Every control below works. The data is fictional; the interface is the one that ships with the template.

Open the full console

Nine sections, from asset inventory to executive reporting.

LodemarkDemo tenantNorthfleet Group · 4 cloud accounts · 11 regions · 3 subsidiariesHead of Security OperationsSigned in as Asha Rehman
Security overviewAssessed 16 Sep 2026, 08:40 UTC · Rolling 90 days
Exposure score34-24%vs. 58 at programme start
Live attack paths7-19%reaching a Core asset
Critical findings12-41%open past 7 days
Median remediation4.2d-6.1d%critical severity

Exposure trend

Weekly score across the selected range. Lower is better.

Below 4040–65Above 65

Band: Moderate · method published in the assurance pack.

Coverage

What discovery can currently see.

  • Cloud accounts connected4/4
  • Domains under continuous discovery118/124
  • Workloads with agent or API coverage4,512/4,870
  • Identity providers federated3/3

Strata

Assets by depth, and how many are currently exposed.

  • S1 Edge1,28437 exposed
  • S2 Gateway31214 exposed
  • S3 Workload4,87061 exposed
  • S4 Identity9,61528 exposed
  • S5 Core4866 exposed

Needs a decision today

4 critical findings and 4 live paths reaching Core.

  • Unauthenticated file listing on the partner document exchangeFND-8841 · supplier-docs.northfleet.io · 7d oldin progress
  • EDI gateway runs an end-of-life TLS stackFND-8836 · legacy-edi.northfleet.io · 19d oldopen
  • Machine identity holds write access across three accountsFND-8829 · svc-datalake-ingest · 14d oldtriaged
  • Invoice archive readable by the analytics lake roleFND-8824 · nfg-invoice-archive · 12d oldin progress

Activity

Discovery, intelligence and posture changes in one record.

08:41 UTCLook-alike domain registered

northfleet-invoices[.]co resolved for the first time. Certificate transparency match on the supplier portal name.

07:58 UTCNew edge asset discovered

supplier-docs.northfleet.io began answering on a second origin pool in eu-west-2.

06:12 UTCPath AP-01 re-scored

Blast radius widened after the analytics role gained read on a fourth prefix.

YesterdayChoke point applied on AP-05

Enforcement point deployed between the campus range and the depot gateway.

YesterdayFND-8749 verified remediated

Deploy identity subject claim narrowed to 13 active repositories.

2 days agoHalverstone infrastructure expanded

Three new hosts in 185.214.44.0/24 matched the remote-access scanning pattern.

3 days agoCloud account connected

Subsidiary account nfg-baltics-prod onboarded; 412 assets discovered in the first sweep.

Platform

Six modules on one model

They share an inventory, a graph and an ownership record. That is the whole reason the findings stop contradicting each other.

Threat intelligence

Intelligence that arrives as “this affects these four assets”

Indicators are resolved against your own inventory before anyone sees them. A look-alike domain matters because it imitates the portal you actually run, not because it appeared in a feed.

  • Quiet Ledger · 3 surface matchesInvoice fraud crew that harvests supplier document portals, then re-issues payment instructions from look-alike domains.
  • Halverstone · 2 surface matchesSells footholds obtained from unpatched remote-access concentrators. Broad, opportunistic and fast to weaponise new advisories.
  • Marrow Tide · 1 surface matchesTargets flat operational networks after commodity phishing. Exfiltrates before encryption and negotiates on stolen contracts.
Threat intelligence
Integrations

It has to land where the work already happens

24 connectors across cloud, SIEM, ticketing, DevOps, identity and alerting — plus a documented REST API and signed webhooks for everything else.

AWAZGCK8CFTFGHGLSNSPMSES
Browse every connector
Customer story
We stopped arguing about which list was right. That argument had been eating a day a week for three years.
Emine KavasChief Information Security Officer, Harlowe Maritime
-61%exposure score over ten months
4 → 1asset inventories
91%assets with a confirmed owner
6.4dmedian critical remediation
Trust

A security company should be the easiest vendor you ever assess

Read-only by default. Regional data residency. A published disclosure process with a named inbox and a key. No certification claims on this page that we have not evidenced in the trust centre.

Open the trust centre
  • Read-only discoveryWrite access is requested only for optional remediation actions and is off by default.
  • Residency you chooseEU, UK, US or Canada, selected at tenant creation. Evidence never leaves that region.
  • Disclosure, in publicA monitored security inbox, a published key and a stated response window.
  • Export everythingNo proprietary format, no export fee, no hostage data at renewal.
Questions

The ones security teams ask on the first call

If yours is not here, ask it directly.

Discovery is passive by default: registrars, certificate transparency, cloud control planes, identity providers and endpoint management APIs. Active checks exist, are off until you enable them per scope, and are rate-limited against surfaces you have confirmed you own.

Next step

See your own surface the way an attacker reads it

A four-week proof of value connects one cloud account, your DNS and your identity provider, and ends with a written readout of what was found.

Book a walkthroughOpen the console demo

Illustrative product data. Nothing on this site performs a live scan.