Research Paper ·

Passive exposure analysis: Austrian organizations in a DORA-relevant environment

Attack surface indicators from Certificate Transparency and DNS email-security posture

Summary

I wanted to understand what passive data alone can reveal about the external attack surface of organizations operating in a DORA-relevant environment. To explore this, I examined 195 Austrian domains using Certificate Transparency and DNS data—without active scanning.

From these publicly observable signals, I derive a DORA Exposure Index from 0 to 100. It is neither a quality seal nor a compliance assessment; its purpose is to help prioritize potential issues for closer examination.

Methodology

I use passive data sources only. Certificate Transparency logs provide indications of hostnames and subdomains; for DNS, I review MX, SPF and DMARC. I treat DKIM as an indicator only, because reliable conclusions are not possible without known selector names.

I weigh subdomain signals by category and recency. The email-security assessment includes MX, SPF and DMARC; DKIM deliberately remains an indicative signal only.

Scope and limitations

No active scanning, exploitation attempts, logins or interaction with target systems. The results support prioritization; they are neither evidence of an exploitable vulnerability nor a compliance assessment.

The index is a prioritization tool, nothing more. It cannot replace an authorized security assessment and does not determine whether an organization is compliant or vulnerable.

Full paper

The original German-language PDF provides the methodology, scoring model, limitations and aggregated results of the study.