Attack surface management

Attack surface management tools, judged on what they find.

Attack surface management tools discover the internet-facing assets an organisation owns — including the ones nobody remembers provisioning — and keep watching them for exposure. The discovery half is what separates the category from vulnerability scanning, and it is where products differ most. This page covers what attack surface management is, what the tools do, how to evaluate discovery honestly, and how the category is priced.

What is attack surface management?

Attack surface management is the continuous discovery, inventory and monitoring of everything an organisation exposes to the internet: domains and subdomains, IP ranges, web applications, APIs, cloud storage, remote access services, certificates and the third-party services operating under its name.

The distinction from vulnerability management is worth being precise about, because the two are frequently conflated in procurement:

  • Vulnerability management answers “what is wrong with the assets we know about?” It starts from an inventory you supply.
  • Attack surface management answers “what do we actually have?” It starts from your organisation’s identity and works outward, which means it can find things absent from your inventory.

That difference matters because the assets that cause incidents are disproportionately the ones nobody was tracking — a forgotten staging environment, a marketing microsite from a campaign three years ago, a subdomain still pointing at a decommissioned cloud service, an acquired company’s estate that never got merged into anyone’s asset list.

What attack surface management solutions do

Five capabilities, present in most products and delivered at very different depths.

  • Attack surface discovery
    Working outward from seeds — a company name, a domain, an ASN — to find assets that belong to you, including through acquisitions and subsidiaries. This is the hard part and the differentiator.
  • Attribution
    Deciding what is genuinely yours. Over-attribution buries you in other people’s assets; under-attribution leaves the gaps that matter. Ask how disputes are resolved and how quickly.
  • Exposure assessment
    What is running on each asset, whether it is current, whether it exposes services that should not be public, and whether certificates and configurations are sound.
  • Continuous monitoring
    The surface changes constantly. A quarterly snapshot is an audit, not attack surface management.
  • Prioritisation
    A raw list of exposures is unusable. What matters is which are reachable, exploitable and attached to something that matters.

Evaluating ASM and EASM tools

Run any evaluation against your own estate rather than a vendor’s demo environment. The comparison that matters is what each product finds that you did not already know about.

TestWeak resultStrong result
Discovery from seedsReturns what you already gave itSurfaces assets absent from your CMDB, including from acquisitions
Attribution accuracyLarge volume of assets that are not yoursHigh precision, with a fast route to dispute and correct
Refresh cadenceWeekly or on requestContinuous, with alerting on newly appeared assets
Change detectionA diff you have to readAlerts on material change: new exposed service, expiring certificate
PrioritisationSeverity from the CVE aloneReachability and business context factored in
Third-party coverageYour estate onlyThe same discovery applied to your suppliers

The last row is the one buyers most often skip and most often need. An ASM tool scoped to your own perimeter cannot tell you anything about the suppliers who hold your data — and that is where a growing share of incidents originate.

How ASM tools are priced

Three models, each with a different failure mode.

  • Per asset discovered. Superficially fair and structurally awkward: the tool that finds most costs most, which is an incentive to discover less. Check whether the count is billed on discovery or on assets you confirm as yours.
  • Per seed or per domain. Predictable, and usually the easiest to reason about for a single-brand organisation. Gets complicated with subsidiaries.
  • Tiered platform fee. A band by company size or estate size, with discovery included.

Whichever the model, ask what happens at renewal if your discovered surface has grown — which it will, because that is the point of the product.

Where RiskXchange fits

RiskXchange’s attack surface capability sits inside a third-party risk platform rather than standing alone, which shapes what it is good for. REX — the outside-in agent — maps the digital footprint, scores posture continuously, watches the time series for material change, correlates breach and dark-web signal, and discovers fourth parties. Because the same machinery runs across a database of 5M+ companies, it applies to your suppliers as readily as to you.

That is the honest positioning: if you want the deepest possible discovery on your own perimeter and nothing else, a dedicated EASM specialist may suit you better. If the question is “what is exposed across us and the companies we depend on, and what changed this week”, that is the problem this is built for. See attack surface risk for the module itself, and external attack surface management for how EASM differs from ASM.

ASM tools, answered.

What is the difference between ASM and EASM?
EASM — external attack surface management — is the internet-facing subset: assets reachable from outside, discovered without credentials or agents. ASM is sometimes used more broadly to include internal and cloud attack surface. In practice most products sold as ASM are doing EASM, and the terms are used interchangeably.
How is ASM different from vulnerability scanning?
A vulnerability scanner tests assets you point it at. Attack surface management works out what the assets are in the first place, starting from your organisation’s identity rather than your inventory. The two are complementary — ASM finds the estate, vulnerability management assesses it in depth.
Do ASM tools need agents or credentials?
No. Discovery is performed from the outside using public data, which is what makes the approach usable against third parties as well as your own estate — nobody has to grant access or agree to anything.
What is attack surface discovery?
The process of finding assets that belong to an organisation by working outward from known seeds — domains, IP ranges, company records — through DNS, certificate transparency logs, internet-wide scan data and corporate structure, then attributing what is found back to the right owner.
Can ASM cover our suppliers?
Yes, and this is where the technique earns most of its value in a third-party risk programme. Because discovery needs no cooperation, the same analysis can run against a supplier continuously — which is the only assessment method that keeps working between questionnaire cycles.

See your surface — and your suppliers’.

Book a 30-minute call and we will run discovery against your own domain and one of your suppliers, and show you what is exposed that nobody had on a list.