nexaya

Free external security assessment · Nigeria

See what an attacker can reach. Before your regulator asks.

For banks, fintechs, telcos, and energy firms with 100+ employees. An engineer maps what's reachable from the internet and walks you through it. Mutual NDA first. The report is yours to keep.

A named engineer, not a salesperson.
Replies within one business day

Request your free assessment

Mutual NDA signed first. Findings stay yours.

By submitting you confirm you own, or are authorised to test, the domain above. Nothing is tested before a mutual NDA and written authorisation.

  • Mutual NDA first
  • External view in 5 working days
  • 45-minute walkthrough
  • No obligation

Why teams in Nigeria ask for this

Evidence beats policy documents.

Regulators, bank partners and clients increasingly ask what is actually exposed. An external view gives you something tested to point to.

CBN framework and CSAT evidence

The CBN's risk-based cybersecurity framework covers vulnerability management and third-party connections, and the CSAT asks institutions to back their self-assessment with evidence. An external view helps you support that evidence with something tested.

NDPC audit returns

Preparing a compliance audit return? Know what personal data is exposed on the internet today, before you file.

Bank-partner and client questionnaires

Bank partners and enterprise clients increasingly ask how exposed your systems and APIs are. Answer with what an engineer actually found.

New launches

A new app, API or environment opens new doors. Forgotten subdomains and test environments often still answer from the internet after a launch.

This page describes how the assessment can support your evidence. It does not state what any regulator requires of you.

What you receive

Five things, at no cost.

  • 01

    An external view of what an attacker can reach

    Internet-facing services, forgotten subdomains, exposed admin panels, email and DNS configuration, TLS weaknesses, and credentials already circulating in breach data.

  • 02

    A short executive summary

    Written in business risk, so your board can read it.

  • 03

    A prioritised list of findings

    Each one with a practical fix.

  • 04

    A regulatory lens

    Each finding mapped to the relevant ISO 27001 Annex A control and, where relevant, the national framework.

  • 05

    A 45-minute walkthrough

    With the named engineer who ran it.

No cost. No obligation. The report is yours to keep.

How it works

From request to walkthrough.

  1. 01

    Request

    Tell us who you are and which domain to assess. A named engineer replies within one business day.

  2. 02

    Sign first

    We sign a mutual NDA and get written authorisation before anything is tested. You must own, or be authorised to test, every asset in scope.

  3. 03

    Assess

    The engineer maps what is reachable from the internet. External perimeter only. Delivered in five working days.

  4. 04

    Walkthrough

    A 45-minute session with the engineer who ran it. Findings first, regulatory lens second.

What it is, and what it is not

Honest about the boundaries.

What it is

An external view that shows you where to look first.

What it is not

This isn't a full penetration test or a regulatory filing. It is not an internal test, a certification, or a regulated audit. If a deeper test makes sense, we'll say so. That would be a separate, scoped engagement.

Who you will deal with

A named engineer, not a salesperson.

Lagos office

nexaya
12 Landbridge Avenue
Victoria Island, Lagos

One business day

A named engineer replies within one business day to confirm scope and sign the NDA.

Questions we get asked

Is it really free?

Yes. No cost and no obligation. The report is yours to keep whether or not we work together afterwards.

Is this a full penetration test?

No. It is an external view of what is reachable from the internet, so you know where to look first. A full penetration test is a separate, scoped engagement.

What do you need from us?

The domain you want assessed, a signed mutual NDA, and written authorisation. You must own, or be authorised to test, every asset in scope.

Will you test our internal network?

No. External perimeter only, and nothing is tested until scope is agreed in writing.

Who can request it?

The assessment is built for organisations with 100+ employees: banks, fintechs, telcos, and energy and logistics firms. Please use your work email so we can verify authorisation before anything starts.

Who will I speak to?

A named engineer, not a salesperson. You will hear back within one business day.

What happens to the information I submit?

We use it to contact you about this assessment. See the privacy notice linked under the form.

Know what an attacker can reach, before someone asks.

Request my free assessment