External attack surface management, including theirs.
External attack surface management is the continuous discovery and monitoring of everything an organisation exposes to the internet, performed entirely from the outside — no agents, no credentials, no cooperation required. That last property is what makes EASM the only assessment technique that works as well on a supplier as it does on yourself. This page covers what your external attack surface consists of, what EASM monitoring involves, and how to use it across a supplier portfolio.
What your external attack surface consists of
Your attack surface is every point where an attacker could attempt to interact with you. The external part is whatever is reachable from the public internet, and it is almost always larger than the asset inventory says.
- Domains and subdomains, including those created for campaigns, testing or products that no longer exist.
- IP ranges and hosts across every cloud account and hosting provider anyone has ever used.
- Web applications and APIs, including undocumented endpoints and staging environments left publicly reachable.
- Remote access services — VPN endpoints, RDP, management interfaces that were only ever meant to be temporary.
- Cloud storage configured for public access.
- Certificates, which both secure services and, through transparency logs, reveal the existence of hostnames nobody published.
- Third-party services operating under your name — marketing platforms, support portals, status pages on subdomains you delegated.
The recurring theme is that the surface grows by ordinary activity — a campaign, an acquisition, a proof of concept, a supplier onboarded onto a subdomain — and shrinks only when someone deliberately removes something. Absent EASM, most organisations only discover the accumulated remainder when it is exploited.
How EASM works
Four stages, all performed without touching anything you have to authorise.
- SeedStart from what identifies the organisation: registered names, primary domains, known IP ranges, corporate structure.
- ExpandFollow DNS records, certificate transparency logs, WHOIS and registration data, internet-wide scan data and cloud provider ranges outward to candidate assets.
- AttributeDecide which candidates genuinely belong to the organisation. This is the step that determines whether the output is usable — too loose and it is full of other people’s assets, too strict and it misses the forgotten estate that motivated the exercise.
- Assess and watchIdentify exposed services, software versions, certificate health and misconfiguration on each asset, then repeat continuously so new assets and new exposures raise an alert rather than waiting for the next review.
Attack surface monitoring: what to watch for
Discovery is a one-off insight. Monitoring is where the operational value is, and a small number of signals carry most of it.
- New assets appearing. Especially outside change control — a new host, a new subdomain, a newly public storage bucket.
- Newly exposed services. A management interface or database port that became reachable, usually by accident.
- Software falling out of support or missing a high-risk patch on something internet-facing.
- Certificate expiry and weak configuration. Cheap to observe and a reliable proxy for whether an estate is maintained at all.
- Dangling DNS. A record still pointing at a decommissioned service, which is the classic subdomain takeover setup.
- Credential and breach exposure associated with the organisation’s domains.
EASM applied to suppliers the reason it belongs in TPRM
Everything above works without the target’s cooperation. That single property changes what supplier assurance can be.
A supplier questionnaire has three structural weaknesses: it is self-reported, it describes one moment, and it requires the supplier to respond before you learn anything. EASM has none of them. It is observed rather than claimed, it updates continuously, and it needs nothing from the supplier at all.
That produces three things a questionnaire cannot:
- Assessment before contact. You can evaluate a prospective supplier during procurement, before anyone has agreed to complete a questionnaire.
- Verification. Where a supplier claims a control and their observable posture contradicts it, you have a finding worth more than either source alone.
- Coverage between cycles. The 364 days a year when the annual assessment is not happening are exactly when a supplier’s posture changes.
It is not a replacement for asking. Governance, accountability, subcontractor arrangements and what happens at offboarding are invisible from the outside. The combination — inside-out evidence reconciled against outside-in observation — is the point. See supplier risk management for the programme, and attack surface management tools for how to compare products in the category.
EASM, answered.
What is external attack surface management?
What is the difference between EASM and ASM?
Is EASM the same as penetration testing?
Is it legal to run EASM against a supplier?
How often should the external attack surface be reviewed?
Go deeper.
Run it against your own domain.
Book a 30-minute call and we will map your external attack surface live — and one supplier’s alongside it, with no questionnaire required.