Getting started
This is the shortest path from a new account to useful results. Five steps, and the first two matter more than they look: almost everything the CyberOptix CTEM Platform does is scoped to an organization and unlocked by a verified domain.
When you first sign in you will see the Welcome Guide, which links to each of these steps. This page explains what each one does and how to tell it worked.
SCREENSHOT: the Welcome Guide on first sign-in, showing the onboarding steps.
1. Create an organization
An organization is the top-level container. Assets, findings, integrations, users, and permissions all belong to one, and nothing is shared between them unless you explicitly make it so.
If you are a service provider, you will have one per client. If you are a single business, you will usually have exactly one.
Open Organizations, click Add, and fill in:
SCREENSHOT: the Add Organization form with its fields.
| Field | Notes |
|---|---|
| Name | The organization or client name |
| Nickname | A short alias, used where space is tight |
| Primary domain | The domain you will verify in step 2 |
| Enabled | Off means the organization exists but is dormant |
| Ongoing | On for continuous monitoring, off for a point-in-time engagement |
Then switch into it using the organization selector in the top navigation. Until you do, most screens have nothing to show you - they are scoped to an organization and you have not chosen one.
2. Verify your domain
Domain verification proves you own a domain before the platform will search for exposed credentials and leaked data relating to it. That gate exists so nobody can point breach-data monitoring at a domain they do not control.
Until a domain is verified, identity exposure and dark web monitoring do not run for it.
Open Administration → Public DNS. Each domain shows a verification code that looks like this:
SCREENSHOT: the Public DNS page showing a verification code and the two copy icons.
cyberoptix-verification=8rAzUDvLEh142LLZ
That single string is two values, and this is where people go wrong: the part before
the = is the record name, and the part after it is the record value.
| Field | Value |
|---|---|
| Type | TXT |
| Name | cyberoptix-verification.your-domain.com |
| Value | 8rAzUDvLEh142LLZ |
| TTL | 300, or your provider's default |
Verification matches the TXT value against the code exactly. A record whose value is
cyberoptix-verification=8rAzUDvLEh142LLZ will never match, because the expected value
is just 8rAzUDvLEh142LLZ.
The two copy icons next to the code exist for this reason: one copies the record name, the other copies the value. Use them rather than copying the displayed text.
The platform re-checks periodically, so nothing further is needed once the record is live. DNS propagation can take up to 48 hours, though it is usually minutes. The domain shows as Verified when the record is found.
If it stays unverified, query the record yourself - this is the same lookup the platform performs:
dig +short TXT cyberoptix-verification.your-domain.com
If that returns nothing, the record has not propagated or was created at the wrong name. If it returns the code wrapped in extra text, the value contains more than it should.
3. Define what to scan
Verification enables external monitoring, which needs nothing from you. Scanning your internal estate needs scope.
Scope is built from zones: a zone holds subnets and URLs, and has a scanner group assigned to it. See Zones, subnets, URLs, and tags for the detail, and Deployment if you need a scanner in the first place.
You can skip this step initially. External attack surface discovery begins as soon as a domain is verified, so there will be results to look at either way.
4. Review your attack surface
Discovery starts automatically once a domain is verified. Within the hour you should see hosts, services, web applications, and certificates appear under Attack Surface.
This is the answer to "what do we actually have exposed", and it is frequently the first surprise: hosts nobody remembered, services that should not be public, certificates about to expire.
5. Check identity exposure
Identity Exposure → Breach Records shows credentials and personal data for your verified domains that have appeared in known breaches.
Unlike the attack surface, this describes exposure that already happened. Treat anything recent as actionable now - a valid credential in a breach corpus does not become less valid because the breach is old.
6. Work your first finding
Open Findings, sort by severity, and take one.
A finding tells you what was found, where, how severe it is, and what to do about it. Working one end to end - reading it, assigning it, fixing it, confirming it closes - is the fastest way to understand how the platform expects you to operate.
Findings, severity, and risk explains how severity is decided, which is worth reading before you sort by it and start at the top.
Where to go next
| If you want to | Go to |
|---|---|
| Understand the model underneath all of this | Concepts |
| Scan internal networks | Deployment |
| Connect cloud accounts or source control | Integrations |
| Add your team | Users |
| Collect logs and run detections | Security Operations |