EASM

External attack surface management, including theirs.

External attack surface management is the continuous discovery and monitoring of everything an organisation exposes to the internet, performed entirely from the outside — no agents, no credentials, no cooperation required. That last property is what makes EASM the only assessment technique that works as well on a supplier as it does on yourself. This page covers what your external attack surface consists of, what EASM monitoring involves, and how to use it across a supplier portfolio.

What your external attack surface consists of

Your attack surface is every point where an attacker could attempt to interact with you. The external part is whatever is reachable from the public internet, and it is almost always larger than the asset inventory says.

  • Domains and subdomains, including those created for campaigns, testing or products that no longer exist.
  • IP ranges and hosts across every cloud account and hosting provider anyone has ever used.
  • Web applications and APIs, including undocumented endpoints and staging environments left publicly reachable.
  • Remote access services — VPN endpoints, RDP, management interfaces that were only ever meant to be temporary.
  • Cloud storage configured for public access.
  • Certificates, which both secure services and, through transparency logs, reveal the existence of hostnames nobody published.
  • Third-party services operating under your name — marketing platforms, support portals, status pages on subdomains you delegated.

The recurring theme is that the surface grows by ordinary activity — a campaign, an acquisition, a proof of concept, a supplier onboarded onto a subdomain — and shrinks only when someone deliberately removes something. Absent EASM, most organisations only discover the accumulated remainder when it is exploited.

How EASM works

Four stages, all performed without touching anything you have to authorise.

  1. Seed
    Start from what identifies the organisation: registered names, primary domains, known IP ranges, corporate structure.
  2. Expand
    Follow DNS records, certificate transparency logs, WHOIS and registration data, internet-wide scan data and cloud provider ranges outward to candidate assets.
  3. Attribute
    Decide which candidates genuinely belong to the organisation. This is the step that determines whether the output is usable — too loose and it is full of other people’s assets, too strict and it misses the forgotten estate that motivated the exercise.
  4. Assess and watch
    Identify exposed services, software versions, certificate health and misconfiguration on each asset, then repeat continuously so new assets and new exposures raise an alert rather than waiting for the next review.

Attack surface monitoring: what to watch for

Discovery is a one-off insight. Monitoring is where the operational value is, and a small number of signals carry most of it.

  • New assets appearing. Especially outside change control — a new host, a new subdomain, a newly public storage bucket.
  • Newly exposed services. A management interface or database port that became reachable, usually by accident.
  • Software falling out of support or missing a high-risk patch on something internet-facing.
  • Certificate expiry and weak configuration. Cheap to observe and a reliable proxy for whether an estate is maintained at all.
  • Dangling DNS. A record still pointing at a decommissioned service, which is the classic subdomain takeover setup.
  • Credential and breach exposure associated with the organisation’s domains.

EASM applied to suppliers the reason it belongs in TPRM

Everything above works without the target’s cooperation. That single property changes what supplier assurance can be.

A supplier questionnaire has three structural weaknesses: it is self-reported, it describes one moment, and it requires the supplier to respond before you learn anything. EASM has none of them. It is observed rather than claimed, it updates continuously, and it needs nothing from the supplier at all.

That produces three things a questionnaire cannot:

  • Assessment before contact. You can evaluate a prospective supplier during procurement, before anyone has agreed to complete a questionnaire.
  • Verification. Where a supplier claims a control and their observable posture contradicts it, you have a finding worth more than either source alone.
  • Coverage between cycles. The 364 days a year when the annual assessment is not happening are exactly when a supplier’s posture changes.

It is not a replacement for asking. Governance, accountability, subcontractor arrangements and what happens at offboarding are invisible from the outside. The combination — inside-out evidence reconciled against outside-in observation — is the point. See supplier risk management for the programme, and attack surface management tools for how to compare products in the category.

EASM, answered.

What is external attack surface management?
The continuous discovery, attribution and monitoring of an organisation’s internet-facing assets, performed from the outside using public data — no agents, no credentials and no cooperation from the organisation being assessed.
What is the difference between EASM and ASM?
EASM is explicitly the internet-facing subset. ASM is sometimes used more broadly to include internal and cloud attack surface, though in practice most products marketed as ASM are performing EASM and the terms are used interchangeably.
Is EASM the same as penetration testing?
No. EASM is continuous, broad and non-intrusive — it establishes what exists and what is exposed. A penetration test is a point-in-time, deep, authorised attempt to exploit a defined scope. EASM is often what tells you what the penetration test should be scoped to.
Is it legal to run EASM against a supplier?
Passive external assessment uses public data — DNS records, certificate transparency logs, published scan data — and is how security ratings services have operated for years. It is distinct from active testing of someone else’s systems, which needs authorisation. If in doubt, note that assessing supplier security posture is increasingly an explicit regulatory expectation under NIS2 and DORA.
How often should the external attack surface be reviewed?
Continuously. The surface changes through ordinary business activity — a campaign, a deployment, an acquisition — and the assets that cause incidents are usually the ones that appeared without anyone recording them. A quarterly review is an audit, not monitoring.

Run it against your own domain.

Book a 30-minute call and we will map your external attack surface live — and one supplier’s alongside it, with no questionnaire required.