Platform · Attack surface

Vendor attack surface, mapped from outside.

Domains, subdomains, exposed services, IPs, fourth-party hops. Continuously discovered, fingerprinted and monitored — the way an attacker would see them, not the way the vendor self-reports them.

What is vendor attack surface management?

An organisation's attack surface is everything of theirs an attacker can reach from the internet: domains and subdomains, IP ranges, exposed services and ports, cloud storage, login portals, APIs, certificates and the software versions running behind all of it. Attack surface management is the practice of discovering that continuously — because the surface changes without anyone announcing it — and reducing what should not be exposed.

Vendor attack surface management applies the same method to the organisations you depend on. The reasoning is that your exposure does not stop at your own perimeter: a supplier's forgotten staging environment, expired-but-live subdomain or unpatched edge appliance is a route into data you are accountable for, and you will not find it in their questionnaire because they have usually forgotten it too.

It matters most for the assets nobody is maintaining. Discovery routinely surfaces infrastructure the vendor's own security team cannot account for — the output of an acquisition, a contractor's project, a migration that left the old host running. For the discipline in general see our attack surface management page and EASM explainer.

The numbers your team already knows.

Most attack-surface programmes track what the vendor told you about. The actual attack surface — shadow assets, forgotten subdomains, exposed admin panels — sits outside that list.

3-7×
External assets per vendor versus what they self-disclose
Industry estimate
40%+
Of breaches start at an asset the vendor didn't know was exposed
Industry estimate
5M+
Companies continuously monitored across the RX network

REX maps it. ARIA cross-checks it. TARA acts on it.

Attack-surface mapping is REX's core remit. ARIA verifies what's exposed against what the vendor's documents claim. TARA tiers the findings and routes the urgent ones into remediation.

REX avatar
REX
Risk & Breach Intelligence

The outside-in scanner that doesn't blink. REX maps every vendor's external footprint, fingerprints exposed services, and watches for new assets and new breaches around the clock.

What you get
  • Digital Footprint Scanner — domains, subdomains, IPs, exposed services
  • Continuous monitoring across 5M+ companies
  • Fourth-party discovery — the vendors of your vendors
ARIA avatar
ARIA
Assessment & Risk Intelligence

External findings, validated against the vendor's own claims. ARIA cross-checks REX's discoveries against the vendor's trust centre, SOC 2 and policies — flagging where reality and self-attestation diverge.

What you get
  • Trust-portal ingestion mapped to the 157 Universal Controls
  • Response Validator catches contradictions automatically
  • Combined-signal analysis pairs scans with documented evidence
TARA avatar
TARA
Tiering & Remediation

Findings tiered by impact, not alphabet. TARA classifies every exposure by inherent risk and assigns SLA-bound remediation — so a Critical-tier vendor's exposed RDP doesn't queue behind a Low-tier banner grab.

What you get
  • Smart tiering — Critical / High / Medium / Low
  • SLA-driven remediation actions, automatically assigned
  • Security Enhancement Agent prioritises by risk impact

From asset list to live attack surface.

Concrete differences in how the team works the surface — not aspirational outcomes, just a more honest map of what an attacker can actually see.

Shadow assets stop being a surprise

Forgotten subdomains, dev environments and old VPN endpoints surface in REX before they surface in an incident.

Vendor self-disclosure becomes a check, not the source

What the vendor says they have is verified against what's actually reachable. ARIA flags the gap.

Findings arrive ranked

TARA tiers exposures by impact so your team works Critical first — not whichever scan finished last.

Fourth-party blind spots close

REX maps the vendors of your vendors. The hop you didn't know about stops being a hop you can't see.

Within two weeks REX surfaced four exposed admin panels across our top-twenty vendors that nobody — including the vendors — knew were live. That's the attack surface you actually need to see.

PD
Head of Cyber
European retail bank

What teams ask about attack surface.

Discovery, attribution, and how vendor attack surface differs from your own.

How is a vendor's attack surface discovered without their cooperation?
From public and observable sources, the same ones an attacker uses: DNS records and passive DNS history, certificate transparency logs — which are a particularly rich source, because every issued TLS certificate publishes the hostname it was issued for — WHOIS and IP registry data, internet-wide scan data, and reverse-DNS relationships. Assets are then attributed to the organisation and fingerprinted to establish what software is running. None of this requires access or permission, which is exactly why it reflects what an attacker can see.
What is shadow IT, and why does it show up in vendor assessments?
Infrastructure running outside the knowledge or control of the team responsible for it — a marketing microsite, a proof-of-concept never decommissioned, a subsidiary's estate inherited in an acquisition. It shows up because discovery finds what exists rather than what is documented, and it is disproportionately risky: unmanaged assets are unpatched, unmonitored, and frequently still hold credentials or data. When a vendor cannot identify an asset you have attributed to them, that is a finding in itself.
What is a fourth party, and how do you find them?
A fourth party is your vendor's vendor — the parties they depend on to deliver to you. They are discoverable from technical evidence rather than disclosure: DNS and CNAME records showing which providers host or front their services, mail exchanger records, CDN and WAF fingerprints, TLS certificate issuers, and third-party scripts loading on their web properties. This is how concentration risk becomes visible — the moment you can see that forty of your vendors terminate at the same provider, you have a different conversation than their individual scores suggest.
How often should attack surface be reassessed?
Continuously, because the failure mode is temporal. A quarterly scan tells you the surface on the day it ran; the exposures that cause incidents are frequently short-lived — a database opened for a migration, a debug interface left on after a release, a certificate that lapsed. The window between exposure and exploitation for an internet-facing vulnerability is now routinely measured in days after public disclosure, which is shorter than most assessment cycles.

See it on your vendors.

Book a 30-minute call and we'll have NOVA, ARIA and REX produce a complete posture report on one of your live vendors inside 24 hours.