ThingsRecon
An Amsterdam startup mapping external attack surface and multi-tier supplier risk from a single starting domain using a proximity-based scoring model.
Visit Website ↗ + Add to Compare Claim This CompanyOverview
ThingsRecon, founded in 2022 and based in Amsterdam, Netherlands, sells an external attack surface management (EASM) and supply-chain intelligence platform. Starting from a single domain, it performs agentless, outside-in scanning to discover an organization’s known and unknown internet-facing assets, then extends that discovery to map first-, third- and fourth-party supplier infrastructure so security teams can see dependencies and exposure that don’t appear on any official vendor inventory.
The platform’s stated differentiator is “Digital Proximity” (patent pending), a methodology that scores suppliers and assets by how topologically close they sit to an organization’s critical systems rather than by a generic risk letter grade alone. The company’s argument is that a moderately-rated vendor sitting close to core infrastructure is a bigger practical risk than a poorly-rated vendor with no real path in. The platform also layers on continuous drift monitoring (new subdomains, expiring certificates, newly vulnerable components) and a natural-language query interface over the discovery data.
ThingsRecon is a small company — public company trackers put headcount around 11-50 employees — and has not disclosed a funding round to date. It lists named enterprise and public-sector customers including Northumbria Healthcare NHS Foundation Trust and An Post (the Irish postal service), with named executives quoted on the company’s own site describing use for supplier discovery and remediation prioritization; these are vendor-published testimonials rather than independently verified case studies.
Innovation Matrix Assessment
A small, young team has shipped a patent-pending scoring methodology (Digital Proximity), a dedicated supply-chain intelligence product, and a conversational AI query layer within roughly three years, a reasonably fast pace for its size.
Single-domain-start discovery and fourth-party mapping address real gaps (undocumented shadow infrastructure, supplier concentration risk) that matter for supplier onboarding, M&A diligence and incident response, per the company's own product description and customer quotes.
No disclosed funding round and a small (11-50 employee) headcount indicate genuine early-stage scale; named customers (NHS trust, An Post, Sicredi) are a positive signal but the company has far less independently reported adoption evidence than established EASM vendors, so momentum is scored honestly low.
EASM itself is an established category with entrenched players (Censys, CyCognito, Palo Alto Cortex Xpanse, Microsoft Defender EASM); ThingsRecon's proximity-scoring twist is a meaningful refinement, not a new category, so disruption is scored moderately.
Evidence is limited to vendor-published customer quotes and self-reported discovery metrics ("3x more connections than official vendor lists"); no Gartner Peer Insights reviews were found for the product and no independent test results were located, so efficacy is scored conservatively.
Growing regulatory pressure around third- and fourth-party risk (e.g., NIS2, supply-chain due-diligence requirements) makes multi-tier attack-surface visibility a durable, likely-growing need over the next several years.
Why CISOs Should Care
It gives a CISO visibility into internet-facing assets and supplier dependencies they never formally inventoried, including risk introduced by vendors' own vendors, starting from nothing more than the organization's domain.
What Makes It Different
Digital Proximity scores exposure by structural closeness to critical systems rather than by a flat vendor risk grade, aiming to surface dangerous-but-overlooked dependencies that generic scorecards miss.
The Matrix Verdict
50/100 — INCREMENTAL INNOVATOR
ThingsRecon is a genuine, operating early-stage company with a coherent technical angle on a real problem, but with undisclosed funding, a small team and no independent efficacy evidence, it lands at the low end of Incremental Innovator rather than higher — honest early-stage scoring, not a knock on the underlying idea.
Editorial Note: Claims vs. Verified Findings
The company's existence, founders, product mechanics and named customer logos are independently corroborated across its own site and third-party trackers (Tracxn, Dealroom, TechLeap); specific performance claims (3x more connections discovered, 150+ contextual signals) are vendor-stated and have no independent test or analyst verification found.
Sources
- ThingsRecon company site — https://www.thingsrecon.com/
- ThingsRecon About Us — https://www.thingsrecon.com/about-us
- Corporate Compliance Insights (product launch coverage) — https://www.corporatecomplianceinsights.com/thingsrecon-launches-supply-chain-security-product-expands-partner-program/
- Context PR case study — https://contextpr.co.uk/work/thingsrecon/
Alternatives to ThingsRecon
Armis (a ServiceNow company)
Agentless asset intelligence platform discovering and assessing every connected IT, OT, IoT and medical device, now part of…
CybelAngel
External attack surface management and digital risk protection platform that scans the open, deep, and dark web for…
watchTowr
Singapore-based platform combining external attack surface management with continuous automated red teaming to validate whether exposures are actually…
CyCognito
Agentless attack surface management platform that maps organizations' entire external footprint, including subsidiaries and shadow assets, using graph-based…
Axonius
New York-based CAASM pioneer that aggregates data from hundreds of existing tools to build a unified, agentless asset…
Doppel
San Francisco AI-native digital risk protection platform that detects and automatically takes down phishing sites, impersonation accounts, and…