MICROSOFT 365ILLUSTRATIVE
SCOUTz product evidence supporting Outside-In Scores Are Estimates. Tenant Data Is Evidence.

There's a booming category of tools that will hand you a security score for any company on the planet. Type in a domain, wait a minute, get a letter grade. No permission needed, no access granted, no one inside the company ever involved. The scores look authoritative: a big letter, a percentile, sometimes a projected breach likelihood down to a decimal point.

It's worth understanding how those numbers get made, because the method defines the limit. Outside-in scoring collects what's publicly observable, DNS records, exposed services, certificate data, breach corpuses, sometimes marketing signals like job postings, and runs it through a model that infers everything else. The key word is infers. The model has never seen the company's identity configuration, its mail rules, its app permissions, its MFA coverage. It's estimating the interior of a house from the condition of the lawn.

Sometimes the lawn tells the truth. Often it doesn't. A company can present a spotless exterior while running no MFA on its admin accounts, or look shabby outside while being genuinely well-run inside. The decimal points are the tell: precision is being performed on top of probability. It's a horoscope with a confidence interval.

Here's where this stops being an academic complaint and starts costing MSPs money. Take an outside-in score into a sales meeting and present it as fact, and eventually, inevitably, the prospect's IT person says "that's wrong, we remediated that in March." Now the meeting has flipped. You're no longer the expert; you're the vendor defending a third party's guess. I've watched credibility leave a room in under a minute this way, and it doesn't come back, because the prospect has learned the one thing you can't afford them learning: your data might be wrong.

Authenticated findings don't carry that risk, and the reason is structural. When a scan reads tenant configuration through consented access, there's no inference layer. The finding isn't "companies with your profile typically lack MFA enforcement." It's "these nineteen accounts do not have MFA, as of Tuesday, here they are by name." The tenant said it, not a model. If the prospect's IT person wants to challenge it, they can go look, and what they'll find is the finding. Verifiability is the whole ballgame: a blood test can be rechecked, a horoscope can only be argued with.

This is why I tell partners that ground truth compounds. The first accurate finding buys you the benefit of the doubt on the second. Ten accurate findings and the client stops double-checking you at all, which is the actual definition of trusted advisor, earned the only way it can be. Guesses can't compound. Every guess is a fresh gamble with your reputation as the stake.

Use outside-in for what it's honestly good for: a conversation starter, a wide-net screen, a knock on the window. But when money, remediation plans, and your name are on the line, get consent and read the tenant. In a market full of confident estimates, being the one whose numbers are simply true is a durable, defensible, compounding advantage.

Scores estimate. Tenants testify. Know which one you're holding.