Attack surface management (ASM) is the continuous process of discovering, inventorying and monitoring the assets an organization exposes to potential attackers, especially systems reachable from the internet. It looks for things IT knows about and things it does not: forgotten websites, test servers, cloud services set up by a business unit, expired domains, exposed login pages and services left open by mistake. The goal is to see your organization the way an attacker would and close openings before someone uses them.
At a glance
- ASM’s defining job is discovery: finding internet-facing assets, including unknown or unmanaged ones, not only scanning a known list.
- It runs continuously, because cloud services, domains and vendors change faster than a yearly inventory.
- Discovery typically starts from your domains, IP ranges and brand names and expands using public internet data.
- Findings are ranked by risk, such as exposed remote access, outdated software or expired certificates, and need an owner to fix them.
- External ASM (EASM) is the most common form; some products extend into cloud accounts and internal assets.
What problem it solves
You cannot protect what you do not know you have. Most organizations’ records of their internet-facing systems are incomplete. Marketing launches a campaign site with a contractor, a developer spins up a cloud test server, an acquired company brings its own domains, and an old VPN appliance stays online after a migration. These forgotten assets are often unpatched and unmonitored, which makes them attractive targets.
Traditional vulnerability management scans the assets on its list, so anything missing from the list is missing from the scans. ASM closes that gap by looking outward, finding what is actually exposed and comparing it with what you think you have. It also gives security teams a way to track shadow IT on the internet-facing side.
How it works
Seeding. You give the tool or provider starting points: domain names, company and brand names, known IP address ranges and cloud accounts.
Discovery. The platform expands from those seeds using public and commercial data sources, such as DNS records, certificate transparency logs, domain registration data, internet-wide scan data and cloud provider address ranges. It links what it finds back to your organization with varying levels of confidence.
Classification and risk scoring. Each asset is fingerprinted: what software it runs, which ports are open, whether it shows a login page, whether its certificate is valid. Issues are ranked, for example exposed remote desktop, end-of-life software, misconfigured storage or leaked credentials tied to your domain. Many tools blend in threat intelligence about what attackers are currently exploiting.
Monitoring and handoff. The platform watches for changes, such as a new subdomain or a newly opened port, and alerts you. Confirmed assets are assigned an owner and fed into vulnerability scanning, patching or decommissioning. Some programs use ASM findings to scope penetration tests.
When it matters for buyers
- After a merger or acquisition. The acquired company’s internet footprint is usually poorly documented, and ASM gives a fast outside-in view.
- After a peer gets hacked. Many attacks start with an exposed, unpatched internet-facing system; ASM shows whether you have similar exposure.
- When moving quickly to the cloud. New accounts and services appear faster than inventories are updated.
- When building an exposure management program. ASM is often the discovery stage of continuous threat exposure management (CTEM).
- When insurers or customers ask about external exposure. Some insurers run their own outside-in scans, so it helps to see the same view first.
Questions to ask vendors
- What data sources do you use for discovery, and how often is the data refreshed?
- How do you decide an asset belongs to us, and how are false positives handled?
- Does the product cover only internet-facing assets, or also cloud accounts, internal networks and identities?
- How are findings prioritized, and do you factor in what attackers are actively exploiting?
- Does it integrate with our vulnerability scanner, ticketing system and asset inventory?
- Is a person reviewing findings as part of the service, or do we get the raw list?
- How is pricing calculated: by domain, by asset count or by organization size?
How it differs from vulnerability management
Vulnerability management scans assets you already know about, in depth, for missing patches and weaknesses, and tracks them through to remediation. ASM works from the outside in, discovering what you actually expose, including assets nobody listed, and doing lighter checks on each one. In practice they work as a pair: ASM finds the asset, vulnerability management examines and fixes it. See our vulnerability management overview for how buyers combine the two.
