Attack Surface Management: Seeing Yourself the Way an Attacker Does
An attacker's reconnaissance and your asset inventory are looking at the same organisation and seeing different things. Your inventory shows what you meant to deploy. The attacker's scan shows what is actually exposed — including the forgotten subdomain, the shadow cloud account, the staging server someone left public, the acquired company's estate nobody folded in. Attack Surface Management is the discipline of closing that gap: continuously discovering everything of yours that faces the internet, from the outside in.
ASM starts from a deceptively hard question: what do we actually expose to the internet? Not what the CMDB says — what is genuinely reachable right now. It works the way an attacker does: begin from what is known (your domains, IP ranges, organisation names) and pivot outward through DNS, certificate transparency logs, cloud footprints, and code repositories to discover assets you didn't know you had. The unknown assets are the point, because those are the ones nobody is patching.
Why the surface keeps growing behind your back
External attack surface expands continuously and mostly without anyone deciding it should. A developer spins up a cloud instance for a demo and forgets it. A marketing team registers a subdomain through a third party. An acquisition brings an entire unmapped estate. A SaaS integration exposes an API. None of these pass through a central review, so none land on the inventory — but all of them are reachable, and an attacker enumerating your organisation finds them precisely because they don't rely on your inventory to know what exists.
Discovery is continuous, not annual
The fatal flaw in treating this as a periodic project is that the surface changes daily while the audit happens yearly. An asset exposed the week after your annual review sits unmanaged for eleven months. ASM has to be continuous — always discovering, always re-assessing — because the window that matters is the one between an asset appearing and you noticing. Attackers scan the entire internet constantly; a once-a-year look at your own footprint is bringing a snapshot to a live fight.
- Discover from the outside in. Start from your own attacker’s-eye reconnaissance, not from the inventory that already excludes what you’ve forgotten.
- Pay special attention to mergers and acquisitions. Acquired estates are the classic source of unknown, unmanaged, and often long-vulnerable exposure.
- Prioritise by exploitability, not just presence. An exposed static site and an exposed admin panel are both ‘on the internet’ and worlds apart in risk. Triage accordingly.
- Feed discoveries into a real process. A list of unknown assets is only useful if something claims, assesses, and remediates each one. Discovery without ownership just documents the risk.
- Take one of your domains and look at its certificate transparency history. If subdomains appear that nobody on your team recognises, you’ve just seen your attack surface the way an attacker does.
- Ask whether anyone can produce a current list of everything your organisation exposes to the internet. If the honest answer is ‘the inventory, but we know it’s incomplete,’ the gap is your real exposure.
Continuous, attacker’s-eye discovery of your full external estate — including the shadow and acquired assets your inventory misses — is core to what our assessment and discovery tooling do, because you can’t defend what you haven’t discovered.
Attack Surface Management is, at its heart, the same principle this entire blog is built on, pointed at your internet-facing footprint: defence begins with discovery. The attacker is not constrained by your documentation, so neither can your defence be. See yourself the way they see you — continuously, from the outside, including the assets you forgot — and the forgotten server stops being their easiest way in. You cannot defend what you haven't discovered, and the surface you haven't mapped is the one they're already scanning.