Skip to main content
Industries · Government

Public services are public attack surface

Benefits portals, licensing systems, tax filing, records access — services that must be open to everyone by design, running on estates that were often built decades apart and connected later.

AIPTx tests them repeatedly rather than annually, and produces evidence written for the packages your authorising officials already require.

A government building ringed by a lit shield, with unauthorised access, malware and exploits, and data breaches approaching from one side, and the properties the estate has to hold on the other: open by design, secure by default, accessible to every citizen, and resilient.
01

Industry Overview

Government estates are the accumulated result of every technology decision made since computing arrived, and almost none of those decisions can be reversed.

A modern citizen-facing portal fronts a services layer, which fronts a records system built in a different era, which integrates with another agency's system under an arrangement documented in a memorandum rather than in code. Each layer was secured according to the assumptions of its own time. Three characteristics shape security here.

The service cannot be selective about who reaches it. A commercial platform can restrict access to customers.

A benefits portal must be reachable by anyone eligible, from any device, often including people with limited digital access. Rate limiting and bot mitigation are constrained by an obligation to serve. Consequence is measured in trust as well as data. A breach of a citizen service is not only a data incident. It is a political event, and it damages participation in the service itself. Evidence is procedural. Authorisation packages, continuous monitoring obligations and audit cycles mean that security work which cannot be evidenced does not count, regardless of how good it was.

02

Security Challenges

  1. R01

    Legacy systems that cannot be replaced on a security timeline

    Replacement programmes run for years and are funded politically. Security has to work with what exists, which means knowing precisely what exists.

  2. R02

    Inter-agency integration

    Data crosses organisational boundaries under agreements that predate current threat models. Each connection is a trust relationship, and the receiving system frequently assumes the sending one has already validated.

  3. R03

    Identity and eligibility logic

    Determining who someone is and what they are entitled to is the core function of many public services, and it is business logic, the class with no signature. Eligibility manipulation and status escalation are the abuses that matter here.

  4. R04

    Large, poorly-inventoried external surfaces

    Agencies accumulate domains, subdomains and services across programmes, campaigns and departments. Consolidation is rare. Assets outlive the programmes that created them.

  5. R05

    Contractor and supply chain exposure

    Much of the estate is built and operated by third parties, and the boundary of responsibility is often clearer in the contract than in the network.

  6. R06

    Testing cadence set by budget cycles

    Annual or biennial assessment against systems that receive continuous minor changes, with the gap covered by nothing.

03

How AIPTx Helps

  1. Stage 1

    Repeatable assessment with a consistent methodology

    The same tests, the same depth, the same output format every run, which is what makes trend comparison meaningful across an authorisation period rather than a set of unrelated reports.

  2. Stage 2

    NIST and CIS control mapping

    Findings map to NIST and CIS alongside ISO 27001, SOC 2, GDPR, PCI DSS and HIPAA, with control assessment and gap analysis in the reports. For agencies whose authorisation frameworks are built on NIST control families, this is the mapping that does the work.

  3. Stage 3

    Discovery before assessment

    Reconnaissance enumerates subdomains, ports, services and endpoints and fingerprints what responds, which for a large agency estate typically surfaces services nobody has an owner for.

  4. Stage 4

    Legacy systems assessed at the layer they expose

    Internal network assessment via a Docker-deployed agent covers internal IP ranges and CIDR blocks: port and service detection, version detection, CVE matching, TLS posture and default credentials. Where a system cannot be changed, knowing its exact exposure is what lets compensating controls be placed accurately rather than generously.

  5. Stage 5

    Eligibility and identity logic tested as logic

    Business logic testing in Standard mode, with race conditions and complex multi-step chains in Deep mode. Multi-role configuration allows a citizen role, a caseworker role and an administrator role to be cross-tested against each other.

  6. Stage 6

    Evidence built for a package

    Every confirmed finding carries the exact HTTP request, the response proving it worked, and a reproducible curl command, with CVSS 3.1, a CWE class and control mapping. Status is tracked as open, fixed, accepted or false_positive, with attribution and timestamps, which is the form continuous monitoring obligations actually require.

04Features & Solutions

Relevant Features and Solutions

NIST and CIS control mapping

Alongside ISO 27001, SOC 2, GDPR, PCI DSS and HIPAA, with gap analysis.

AI risk engine

Attack surface discovery

Subdomain and asset enumeration, service and version fingerprinting across large estates.

External attack surface management

Internal network assessment

Docker-deployed agent, outbound connectivity only, across IP ranges and CIDR blocks.

Multi-role authenticated testing

Citizen, caseworker, administrator, with bearer, basic, cookie, custom header and OAuth2/OIDC support.

Web application security

Business logic and access control testing

Eligibility manipulation, status escalation, IDOR, privilege escalation.

Autonomous pentesting

API testing

REST via OpenAPI or Swagger, GraphQL with introspection, gRPC with proto files, for inter-agency and partner integrations.

Finding lifecycle with attribution

Open, fixed, accepted, false_positive, each change carrying a person, a date and a reason.

Five export formats

PDF, HTML, JSON, CSV and SARIF, plus a REST API for feeding findings into an existing governance system.

05

Benefits

Coverage between authorisation cycles
Continuous monitoring obligations are easier to meet with continuous testing than with an annual report and a set of scans.
Evidence in the shape the process expects
Control mapping, gap analysis, attributed status history and trend comparison, generated per assessment.
An honest inventory of a sprawling estate
Discovery finds the services that outlived their programmes, which is usually where the unmaintained exposure sits.
Legacy exposure quantified rather than assumed
Precise knowledge of what an unchangeable system exposes allows proportionate compensating controls.
Accepted risk recorded properly
An attributed, dated acceptance is a governance artefact. It is also the answer when an auditor asks why a finding is still open.
Cost that scales with estate, not with consultant days
Which is what makes assessing the whole estate a realistic proposition rather than an aspiration.
06

Use Cases

Citizen portal assessment

Multi-role testing across citizen, caseworker and administrative accounts, with eligibility logic and cross-access tested.

Estate-wide discovery

Enumerating the full external surface across departments and legacy programmes, then assessing what is found.

Pre-authorisation testing

A Deep assessment before an authorisation review, with NIST control mapping and retest history attached.

Continuous monitoring evidence

Scheduled assessment producing the ongoing testing record the obligation requires.

Inter-agency integration review

Assessing the API surface exposed to another agency or a contractor before enabling the connection.

Contractor deliverable verification

Independently assessing a system delivered by a supplier before acceptance.

Vulnerability assessment

FAQs

Do you map to NIST?

Yes. Findings map to NIST and CIS controls alongside ISO 27001, SOC 2, GDPR, PCI DSS and HIPAA, with control assessment and gap analysis included in reports.

Can you assess systems we are not allowed to modify?

Yes, at the layer they expose. Internal network assessment covers hosts and services (ports, versions, CVE matching, TLS posture, default credentials) without requiring any change to the system. Knowing the exact exposure is what allows compensating controls to be placed precisely.

How does this fit continuous monitoring obligations?

Assessments run on a schedule with consistent methodology, and reports carry trend comparison against previous runs. Finding status is tracked with attribution and timestamps, so the record shows not just what was found but what was done about it and by whom.

Can findings feed our existing GRC system?

Findings export as JSON and CSV and are available through the REST API. Each carries CVSS 3.1, a CWE class, control mapping and full status history.

Assess the whole estate, not the part that fits the budget

Consistent, repeatable testing with NIST control mapping and evidence written for the process you already run.

Scope verified before any test runs · Destructive actions off by default

Security testing for other sectors

Same engine, different threat model, different auditor. Each page covers the systems, regulations and attack paths that sector actually lives with.

Financial Services

Payment flows, lending decisions, account servicing, open banking APIs — the logic that handles money is the logic attackers study hardest. It is also the logic no signature database describes.

Explore

Healthcare

Patient portals, scheduling systems, clinical APIs, payer integrations: all of it holds data that carries a lifetime of consequence if it leaks, and much of it runs on systems that cannot be taken offline for a test.

Explore

Manufacturing

Almost nobody breaks into a plant by attacking a controller. They arrive through a corporate account, a supplier portal, an ERP integration or an exposed remote access service, and then walk into a network that was designed for reliability, not for containment.

Explore

Retail

The vulnerabilities that cost retailers money are rarely exotic. A discount that stacks when it should not. A price accepted from the client. A gift card balance that survives a concurrent request. A loyalty account reachable from another customer's session.

Explore

SaaS

Every enterprise deal arrives with a questionnaire, a SOC 2 request and someone technical asking when you last tested. Meanwhile you ship on Tuesday and again on Thursday, and the last pentest describes a product that has since changed twice.

Explore

Telecom

A single authorisation flaw in a subscriber portal is not one exposed account. At operator scale it is a data set — and the same flaw in a provisioning API is an operational one.

Explore

Education

A department stood up a project site in 2019. A research group runs its own server. A faculty subdomain points at infrastructure that was decommissioned two years ago. None of it went through central IT, and all of it is reachable.

Explore

Legal

Clients do not retain a firm because of its document management system. They retain it on the assumption that what they share stays privileged — and increasingly they audit that assumption before instructing.

Explore