Attack surface management tools, judged on what they find.
Attack surface management tools discover the internet-facing assets an organisation owns — including the ones nobody remembers provisioning — and keep watching them for exposure. The discovery half is what separates the category from vulnerability scanning, and it is where products differ most. This page covers what attack surface management is, what the tools do, how to evaluate discovery honestly, and how the category is priced.
What is attack surface management?
Attack surface management is the continuous discovery, inventory and monitoring of everything an organisation exposes to the internet: domains and subdomains, IP ranges, web applications, APIs, cloud storage, remote access services, certificates and the third-party services operating under its name.
The distinction from vulnerability management is worth being precise about, because the two are frequently conflated in procurement:
- Vulnerability management answers “what is wrong with the assets we know about?” It starts from an inventory you supply.
- Attack surface management answers “what do we actually have?” It starts from your organisation’s identity and works outward, which means it can find things absent from your inventory.
That difference matters because the assets that cause incidents are disproportionately the ones nobody was tracking — a forgotten staging environment, a marketing microsite from a campaign three years ago, a subdomain still pointing at a decommissioned cloud service, an acquired company’s estate that never got merged into anyone’s asset list.
What attack surface management solutions do
Five capabilities, present in most products and delivered at very different depths.
- Attack surface discoveryWorking outward from seeds — a company name, a domain, an ASN — to find assets that belong to you, including through acquisitions and subsidiaries. This is the hard part and the differentiator.
- AttributionDeciding what is genuinely yours. Over-attribution buries you in other people’s assets; under-attribution leaves the gaps that matter. Ask how disputes are resolved and how quickly.
- Exposure assessmentWhat is running on each asset, whether it is current, whether it exposes services that should not be public, and whether certificates and configurations are sound.
- Continuous monitoringThe surface changes constantly. A quarterly snapshot is an audit, not attack surface management.
- PrioritisationA raw list of exposures is unusable. What matters is which are reachable, exploitable and attached to something that matters.
Evaluating ASM and EASM tools
Run any evaluation against your own estate rather than a vendor’s demo environment. The comparison that matters is what each product finds that you did not already know about.
| Test | Weak result | Strong result |
|---|---|---|
| Discovery from seeds | Returns what you already gave it | Surfaces assets absent from your CMDB, including from acquisitions |
| Attribution accuracy | Large volume of assets that are not yours | High precision, with a fast route to dispute and correct |
| Refresh cadence | Weekly or on request | Continuous, with alerting on newly appeared assets |
| Change detection | A diff you have to read | Alerts on material change: new exposed service, expiring certificate |
| Prioritisation | Severity from the CVE alone | Reachability and business context factored in |
| Third-party coverage | Your estate only | The same discovery applied to your suppliers |
The last row is the one buyers most often skip and most often need. An ASM tool scoped to your own perimeter cannot tell you anything about the suppliers who hold your data — and that is where a growing share of incidents originate.
How ASM tools are priced
Three models, each with a different failure mode.
- Per asset discovered. Superficially fair and structurally awkward: the tool that finds most costs most, which is an incentive to discover less. Check whether the count is billed on discovery or on assets you confirm as yours.
- Per seed or per domain. Predictable, and usually the easiest to reason about for a single-brand organisation. Gets complicated with subsidiaries.
- Tiered platform fee. A band by company size or estate size, with discovery included.
Whichever the model, ask what happens at renewal if your discovered surface has grown — which it will, because that is the point of the product.
Where RiskXchange fits
RiskXchange’s attack surface capability sits inside a third-party risk platform rather than standing alone, which shapes what it is good for. REX — the outside-in agent — maps the digital footprint, scores posture continuously, watches the time series for material change, correlates breach and dark-web signal, and discovers fourth parties. Because the same machinery runs across a database of 5M+ companies, it applies to your suppliers as readily as to you.
That is the honest positioning: if you want the deepest possible discovery on your own perimeter and nothing else, a dedicated EASM specialist may suit you better. If the question is “what is exposed across us and the companies we depend on, and what changed this week”, that is the problem this is built for. See attack surface risk for the module itself, and external attack surface management for how EASM differs from ASM.
ASM tools, answered.
What is the difference between ASM and EASM?
How is ASM different from vulnerability scanning?
Do ASM tools need agents or credentials?
What is attack surface discovery?
Can ASM cover our suppliers?
Go deeper.
See your surface — and your suppliers’.
Book a 30-minute call and we will run discovery against your own domain and one of your suppliers, and show you what is exposed that nobody had on a list.