External attack surface management (EASM) is the ongoing practice of discovering, inventorying and monitoring every internet-facing asset your organisation exposes — including the ones nobody remembers deploying. Attackers already do this to you, continuously and for free. EASM is doing it to yourself first, so the forgotten staging server gets found by your team instead of theirs.
Why organisations don't know what they expose
Almost no organisation of any size has an accurate picture of its own internet footprint. The reasons are structural, not careless:
- Accumulation — years of product launches, marketing campaigns, migrations and experiments each leave behind domains, DNS records and hosts.
- Cloud makes exposure trivial — anyone with a corporate card can put a service on the internet in minutes, with no change ticket and no entry in any register. See our post on shadow IT discovery.
- Decentralisation — subsidiaries, acquired companies, regional teams and agencies all deploy under your brand, often on infrastructure you've never seen.
- Dev and staging drift — non-production environments get exposed 'temporarily' and stay that way, usually with weaker controls than production.
- Inventories track purchases, not exposure — the CMDB records what was procured; it says nothing about what's actually answering on the internet right now. In our experience the two rarely agree.
What your external attack surface includes
More than websites. A realistic inventory covers domains and subdomains, IP ranges and ASNs, cloud resources and tenants, exposed services and open ports, TLS certificates, mail infrastructure, public code repositories, assets hosted for you by third parties, and — arguably — your staff's credentials sitting in breach data.
Discovery techniques, in general terms
Passive discovery
Passive techniques use data that already exists publicly, without touching your systems: certificate transparency logs, passive DNS datasets, WHOIS and registration data, internet-wide scan databases, BGP and ASN records, search engines and public code search. This is where most of the surprises come from, because it surfaces assets created outside any official process.
Active discovery
Once candidate assets are identified, active techniques confirm and enrich them: DNS resolution and permutation, port and service scanning, technology fingerprinting and screenshotting. Active work touches your infrastructure, so it should be authorised and attributable.
Attribution
The hardest part of EASM isn't finding assets — it's deciding which ones are actually yours. Shared hosting, CDNs, third-party platforms and similarly named companies all create noise. False positives waste effort; false negatives leave real exposure unmonitored. Good attribution is where automated discovery most needs human judgement.
Continuous vs point-in-time
A point-in-time discovery exercise — typically done at the start of an annual penetration test — is genuinely valuable, but it's a snapshot. In most organisations it starts going stale within weeks: new deployments appear, certificates expire, DNS records start dangling, credentials leak.
Continuous monitoring catches the changes that matter between assessments:
- New subdomains and hosts appearing under your domains
- Newly opened ports and exposed services
- DNS records that have started pointing at unclaimed resources — the precursor to subdomain takeover
- Certificates expiring, or being issued for names you don't recognise
- Fresh credential leaks affecting your domains
The two models answer different questions. Continuous discovery answers 'what do we expose right now?'. Deep manual testing, like an external network penetration test, answers 'can what we expose actually be exploited?'. Mature programs run both: continuous discovery feeding scope and priorities into periodic human-led testing.
Getting started, practically
- Build a seed list: root domains, known IP ranges, cloud accounts, registrars, subsidiary names.
- Run discovery from the seeds and compare the results against your internal inventory. The delta is your unknown surface.
- Assign an owner to every confirmed asset, and decommission the zombies nobody claims.
- Put monitoring in place so new exposure is flagged when it appears, not at next year's audit.
- Feed the inventory into your penetration testing scope, so testing covers what you actually expose rather than what you think you do.
FAQ
How is EASM different from vulnerability scanning?
Vulnerability scanning tests known assets for known weaknesses. EASM finds the assets in the first place. A scanner can't scan what isn't in its target list — and the assets missing from that list are usually the ones in the worst shape.
Is EASM a product or a service?
Both exist, and plenty of organisations use a mix. What matters more than the label is discovery coverage, attribution accuracy, and whether a human triages the output — raw discovery feeds are noisy, and an unread dashboard protects nobody.
How often should discovery run?
Monitoring should be continuous, or weekly at minimum. Pair it with a deeper human review quarterly and full manual testing annually or after major change — a migration, an acquisition, a big release.
If you want an attacker's-eye view of what your organisation exposes, our OSINT and reconnaissance team maps external attack surfaces for clients globally, with a fixed quote within one business day of a free scoping call — get in touch.
Need cybersecurity expertise?
Drop your email and we'll be in touch within one business day.