Arctic EWS
Answers about the Early Warning Service — what it monitors, how it compares to other tools, setup, and day-to-day operations.
No matches — try a different word, or clear the filter.
General
Classic or Flex — which one is this FAQ about?
Both. EWS Classic and EWS Flex are the same monitoring service in two forms: Classic delivers one set of warnings to one team, and Flex routes each warning to the unit that owns the asset. Most answers on this page apply to both; the few that are specific to one are tagged Classic or Flex.
Related: EWS Classic · EWS Flex
What is Arctic EWS?
Arctic EWS is a complete external monitoring service that identifies the early signs of security breaches and vulnerable services. It provides a 24/7 warning system by correlating global threat intelligence with your organization’s public-facing assets, allowing you to stop incidents before they happen.
Related: EWS Classic · EWS Flex · What is early warning?
Does Arctic EWS replace our current security solutions?
No, it is designed to complement your existing security stack. While your firewalls and endpoint tools protect you from the inside, Arctic EWS acts as an external security guard, catching vulnerabilities, misconfigurations, and threats that may slip through internal defenses.
How EWS compares to other solutions
How does EWS compare to ASM solutions?
EWS takes a more conservative approach to asset discovery than typical Attack Surface Management (ASM) tools, so you see only assets that are actually yours, without noisy false positives to sort through. It also draws on a broader set of data sources, giving wider coverage, and includes signals ASM tools do not cover, such as compromised machines beaconing out to command-and-control infrastructure. The result is a smaller, higher-confidence result set. Instead of a long list you have to triage, every issue EWS surfaces is actionable.
I already have a threat intelligence solution — why do I need EWS?
Threat intelligence gives you the big picture: what threats and campaigns are out there. But on its own, it doesn't tell you which of those threats actually affect your network. EWS closes that gap. It filters through large volumes of CTI and matches it against your actual network assets, so instead of a broad threat landscape, you get a short list of confirmed, specific issues that need attention. Early warning is about actionable findings, not general awareness. Think of it this way: threat intelligence tells you what's happening in the world; EWS tells you what's happening to you.
How does EWS compare to a risk-scoring solution like BitSight or SecurityScorecard?
They answer different questions. Risk-scoring platforms give you an indication of your security posture — a score meant to estimate how well-defended you look from the outside. EWS's purpose is different: it identifies real, specific security issues on your network so you can actually fix them and improve that posture.
That distinction matters because a good score doesn't mean you're safe. You can have a high rating from a risk-scoring tool and still be completely vulnerable to a real, active threat. The score is an estimate, not a finding. EWS gives you the finding: concrete, actionable issues on your actual assets, not just a number to explain to a board.
I already have endpoint security — why do I need EWS?
Endpoint security protects the devices it's installed on. But not everything on your network can run an endpoint agent. Servers, printers, cameras, and other IoT devices are common blind spots where malware can operate undetected. EWS covers that gap from the outside in. It tracks serious vulnerabilities on your externally facing assets and flags exposed services that shouldn't be open to the internet, providing visibility endpoint tools were never designed to provide in the first place.
Features & capabilities
What exactly does the service monitor?
Arctic EWS provides comprehensive visibility into your external attack surface. Key monitoring areas include:
- Asset Discovery: Automatically mapping public-facing assets and external connections so you know exactly what is exposed.
- Vulnerability Tracking: Detecting remotely exploitable services and publicly accessible weak points.
- Compromise Detection: Identifying suspected malware, compromised machines, or data exfiltration to known malicious IP addresses.
Where does the threat data come from?
We collect, purchase, and harmonize data from multiple trusted and vetted third-party commercial sources. These providers perform non-targeted, internet-wide scanning. Once the data is collected, we structure and harmonize it so it can be automatically matched against your specific assets.
Does EWS monitor for leaked credentials on the Dark Web?
Yes, Leaked Data Monitoring is available as an additional service. By configuring your "Email domains" in the portal, EWS can search for usernames, passwords, and session cookies stolen by malware or distributed in Dark Web data dumps.
Why does EWS only track a small number of vulnerabilities?
By design. Research from our partner Root Evidence found that of all published CVEs, only about 1.4% have ever been exploited in the wild. Tracking every CVE means spending most of your remediation effort on issues that pose little real risk. EWS focuses instead on vulnerabilities that are actively being exploited, plus precursor indicators that often signal exploitation is coming. Fixing this smaller, targeted set drastically improves your actual security posture — while skipping the vulnerabilities that don't meaningfully reduce risk, freeing up remediation time for the issues that matter. We've taken this approach since 2019 — well before "evidence-based" vulnerability management became an industry trend, EWS was already built around tracking what's actually being exploited rather than the full CVE list.
Can we integrate Shadowserver data into EWS?
Yes. You can incorporate threat data from The Shadowserver Foundation directly into your EWS platform. We offer a Managed Service option, which allows EWS to automatically manage and synchronize your asset changes with Shadowserver on your behalf. Alternatively, you can connect your existing Shadowserver credentials, though this requires you to manually update Shadowserver whenever your network assets change.
What are the different user roles and access levels? classic
The EWS portal operates on a Role-Based Access Control (RBAC) model with three tiers:
- Administrator: Full administrative rights across the entire EWS Classic portal, including the ability to create/delete users and grant Admin privileges.
- User: Broad access rights to configure and use service features and manage Customer Assets.
- Viewer: Read-only access to EWS dashboards, reports, and data.
Can I access my threat data via an API?
Yes. EWS provides a Sharing API that delivers data in both human-readable HTML and machine-readable formats. You can find your unique, auto-generated API key in the Configuration section of the portal.
Is there a way to visualize the data?
Yes, the EWS Dashboard provides a centralized, visual way to monitor your threat data. It comes with five pre-configured views to help you quickly categorize daily observations:
- Public Exposure: Services or ports publicly exposed to the internet.
- Known Vulnerabilities: Technical vulnerabilities (like CVEs) that require a patch or fix.
- Suspected Compromise: Signs of active infections, such as a machine reaching out to a command and control server.
- Potential Threats: Compromised accounts and miscellaneous threats.
- Overview: A comprehensive 30-day summary of all observations related to your organization.
Can I customize the EWS Dashboard?
Absolutely. While EWS provides default views, the dashboard is fully customizable to suit your workflow. You can build custom views using a variety of widgets—including Timelines, Maps, Bar Charts, Pie Charts, and Tables—to visualize both real-time events and aggregated historical data. You can also apply global data filters, set custom timespans, and share your tailored dashboards with other users.
What are the different methods for delivering threat data to our team?
EWS provides multiple delivery methods to ensure you receive threat data in the most effective format for your workflow:
- Email Notifications: Automated daily alerts consolidating new findings, plus a Weekly Assurance Email summarizing the past week's observations.
- Sharing API: A dedicated API endpoint delivering data in multiple formats. Data can be shared in a separate browser-based interactive viewer, in human-readable HTML, or in machine-readable formats. This is especially useful if you want to integrate notifications directly into your existing case management or SIEM systems.
- EWS Dashboard: A real-time, customizable visual interface within the user portal for exploring data and filtering specific threats.
- Observation Reports: Comprehensive monthly summaries available for download, perfect for sharing high-level posture changes with stakeholders.
How often will I receive email notifications, and will I get duplicate alerts?
Email notifications are generated daily based on new observations. To prevent alert fatigue, some notification types are consolidated into summaries using a deduplication window of one calendar month. This means you are only alerted to genuinely new issues rather than receiving repeated notifications for the exact same ongoing event. Additionally, we send a Weekly Assurance Email. (Note: These time intervals are pre-configured).
In addition to daily alerts, why is there a monthly summary report?
Daily alerts are for immediate action — the monthly summary is for the bigger picture. It gives you a clearer view of how your security posture is changing over time, how quickly issues are getting resolved, and information you can share with stakeholders who need visibility but don't need every individual alert. It also serves as an ongoing third-party evaluation — a good proxy for how well your security controls are actually working, beyond any single incident.
Setup & infrastructure
How difficult is the onboarding process?
Implementation is virtually effortless and entirely non-invasive. Because the monitoring is 100% external, there is no hardware to install, no software agents to deploy, and no need to grant internal network access.
What exactly is considered an "asset"?
An "asset" is an IP address or a domain name associated with your IT infrastructure. IP addresses are often delegated in ranges and linked to owned domain names. If you have an Autonomous System Number (ASN), that is considered your asset only if you directly manage it.
Are cloud-hosted services considered my assets?
It depends on how the resource is allocated. If an IP address points to a cloud service dedicated entirely for your use, it is considered your asset. If that system has multiple tenants (shared hosting), it is considered a shared resource. We automatically exclude IPs with a large number of domains pointing to them to prevent noise, though you will still receive results that match your specific domain name.
Are there limits to the number of assets we can monitor?
Unless otherwise specified in your Purchase Agreement, EWS applies default usage limits of 10 unique apex domains for automated discovery. Technical limits may also apply to manually configured IP ranges to prevent configuration errors.
How does EWS discover our assets automatically?
EWS uses a Dynamic Asset Discovery tool that complements manual configuration. By using your main domains as a starting point, EWS leverages various mechanisms to dynamically discover associated sub-domains, apex domains, and related IP networks. You simply review and select the relevant assets, ensuring a comprehensive view of your external attack surface without adding noisy false positives.
What information do I need to provide to configure my assets?
You simply need to verify your organization's basic information (Name, Sector, Country) and add your main domain names. EWS will automatically discover your sub-domains and associated IP addresses. You can also manually add specific IP networks and tag them with a type (e.g., servers, offices) for better organization.
Can I change my registered company domain name?
The primary domain name used to initially register for the service cannot be changed. However, paid subscribers can add multiple additional domains to their accounts to be monitored and included in reports and notifications.
Can I monitor domains that belong to partners or third parties?
No. Based on the End-User License Agreement (EULA), you can only configure and monitor domains that directly belong to your organization.
Does Arctic EWS actively scan our network?
No, EWS does not actively scan your network. Instead, it continuously (24/7/365) monitors your configured public-facing assets and matches them against global cybersecurity observations from multiple external threat intelligence sources. This non-intrusive approach gives you round-the-clock visibility into external threats without adding traffic, triggering internal alarms, or requiring agents to be installed.
Where is my data stored, and are you GDPR-compliant?
Yes, we are fully GDPR-compliant with customer data management. Arctic EWS data is stored securely in the EU, utilizing AWS in Ireland. When external threat data is matched against your organization, that matched data is only retained long enough to produce the service (such as overtime reporting) and is then automatically dropped from the database.
Troubleshooting & operations
What are your support hours and response times?
Arctic Security provides email-based support during Finnish business days and hours. Support requests are acknowledged on the following business day, and our team will initiate work to resolve a reported issue within three (3) business days.
How do I update my contact or billing information?
You can update your personal contact information at any time directly within the EWS portal, and the change takes effect immediately. For billing and credit card updates, please contact our support team at ews-support@arcticsecurity.com, and the changes will be processed within three business days.
How long is our threat data retained in the system?
Data retention periods are built to give you ample time to respond while ensuring data hygiene. Current retention lengths are:
- Portal dashboard visibility: Up to 180 days
- API access to standard Observations: 30 days
- API access to leaked data Observations: 180 days
Can my notification be a false positive?
Yes, while we use highly vetted data sources to ensure accuracy, false positives can occasionally occur. This is usually due to inaccurate or outdated asset information in your configuration, or if a third-party shared hosting server (where your site resides) becomes compromised to host phishing URLs or malware.
Why am I getting a "404 Not Found" error when clicking a report link?
System-generated notification links have a default lifespan of 30 days. If you click a link older than this, the temporary token has expired, and the system will return a 404 error. A new report link will need to be generated. If you need help adjusting link expiration or generating a new link, please contact our support team.
Why am I getting a "401 Unauthorized" error on a report link?
A 401 error means the link is reachable, but access has been revoked. This usually happens if the specific Share configuration or Customer account has been disabled in the EWS UI, or if the API keys were recently regenerated (which invalidates all previously sent links). If you have verified the account is active and still face issues, please reach out to support.
Why was my account deleted, or how can I request deletion?
To maintain system hygiene, we periodically clean up and delete user accounts that show no sign of activity for 12 months (though you are free to register again). If you wish to manually cancel your subscription or delete your active Arctic EWS account, please contact our support team. Upon cancellation of a paid subscription, you will still retain access to the free asset discovery and assessment service.
Business & compliance value
Will this create more work for our IT team?
No, Arctic EWS is designed to significantly reduce the security burden. By minimizing false positives and delivering only highly relevant, prioritized alerts, it empowers IT teams to take immediate remediation action without spending hours analyzing raw data.
My team and I are busy. How does EWS save us time? flex
EWS triages issues for you, so your team can focus on what actually matters instead of sorting through noise. Rather than every issue landing on one overloaded queue, EWS can automatically route issues to the group best positioned to fix them — whether that's a specific team, location, or third-party supplier. Over time, this has a compounding effect: as root causes get fixed and processes improve, the number of new issues surfacing drops, freeing up even more of your team's time.
How does EWS help improve my overall security posture?
EWS surfaces issues that would otherwise go unseen. Because it runs 24/7, you're notified the moment a new issue is found — not weeks later during a periodic review. Beyond fixing individual issues, EWS supports longer-term improvement too. Running root cause analysis on the issues it surfaces often reveals gaps in your processes or security control configurations — insight you can use to prevent similar issues from recurring, not just resolve them one at a time. It also acts as an independent, third-party evaluation of your security investments — an outside check on whether your existing controls are actually working, which helps guide where to improve.
What is the ROI of using EWS?
An independent ROI analysis by TAG Cyber found that EWS delivers a 200% ROI — for every dollar spent, two dollars are saved in incident response costs.
The analysis compared a typical enterprise with and without EWS, assuming one major incident per year. Without EWS, that incident costs roughly $150K in legal, response, reporting, and consulting fees. With EWS, those costs are largely avoided, offsetting the license investment and producing a net positive return.
Beyond the number itself, TAG also noted qualitative benefits: better security readiness, improved use of existing threat intelligence investments, and fewer emergency triage situations. (Note: Figures are based on TAG's representative case study model, not a guarantee for any specific deployment. See the full TAG ROI Report for details and assumptions.)
Can Arctic EWS help with regulatory compliance?
Yes. An active subscription helps check several compliance boxes right from the start, supporting key NIST 800-172 and CMMC requirements related to situational awareness, incident response, risk management, and continuous security assessment.
Related: What is early warning?
Didn't find your answer?
Write to ews-support@arcticsecurity.com — we reply the next business day.