VITI Security

Services · EASM

Find the 30% of your attack surface you do not know about.

The average company has 30% more internet-facing assets than its security team knows about. Forgotten subdomains. Old marketing sites. Cloud accounts spun up by a developer six months ago. Each unknown asset is a possible entry point. External Attack Surface Management (EASM) finds them all, monitors them continuously, and tells you when something new appears that should not be there.

The shadow-IT problem in numbers

30%
More assets than security teams know about (industry avg)
60-80%
Of internet footprint most orgs are actually aware of
< 24 hr
Most new assets appear in your dashboard

What our EASM service covers

Six layers - because asset discovery alone is not enough.

A scanner that knows your assets is straightforward. The hard part is building the asset list in the first place, and getting useful, prioritized signal out of the resulting noise.

Continuous asset discovery

We start from your root domain(s) and IP ranges and discover everything connected: subdomains (via DNS, certificate transparency logs, passive sources), associated IPs, cloud assets (AWS, Azure, GCP), exposed services (open ports, running software, versions), and SSL/TLS certificates. Daily refresh.

Shadow IT detection

SaaS spun up by a marketing team. A staging server that became production. A subdomain pointing to an old hosting provider. We flag assets associated with your domain that do not appear in your asset inventory - and route the alert to the person who should know.

Risk-scored vulnerability findings

Every discovered asset is scanned for vulnerabilities (CVEs, weak SSL/TLS configuration, exposed admin panels, missing security headers, outdated software). Findings are prioritized by exploitability and asset criticality - not just CVSS score - so your team works on what matters first.

Change monitoring + alerting

You are notified when something changes on your attack surface: a new subdomain appears, a port opens, a certificate is about to expire, a service version downgrades, an exposed database becomes publicly reachable. Alerts route via email, Slack, or webhook.

Manual triage by analysts

Automated EASM alerts can generate noise. Every critical finding is reviewed by a human analyst before it reaches you. We give context: "this is exploitable in your stack" or "this is theoretically present but the version is patched."

Remediation guidance, not just findings

Every finding comes with specific remediation steps - what to change, where, in what order. For complex findings, we get on a call with your engineering team and walk them through the fix.

Who needs EASM

If any of these describes your situation, you need it.

Engineering teams that ship to the internet

If developers can spin up infrastructure without security review, you need EASM. The blind spot is built into the workflow.

Companies with acquisitions or mergers

You inherit someone else attack surface. EASM maps it - on day one, not after the auditor asks.

Companies with marketing microsites

Campaign sites, landing pages, partner microsites - created by marketing, forgotten by IT. EASM catches them.

Companies preparing for SOC 2 / ISO 27001

Auditors increasingly ask "how do you know your full asset inventory?" EASM is the answer.

Companies in regulated industries

Fintech (SEC, PCI), healthcare, ecommerce. Regulators expect you to know your exposure - and ask for it specifically.

Companies after a near-miss or breach

Once you have seen an unknown asset bite you, you do not want it to happen again. EASM is the preventive layer.

What EASM is NOT

To be useful, here is what EASM does not replace.

EASM is one layer in a complete security program. We are honest about that - and we will tell you whether you need EASM right now, or whether a different control gives you more value first.

Internal vulnerability scanning

EASM is external-facing. Internal networks need separate scanning.

Manual penetration testing

Automated discovery catches the obvious. Manual testing catches business-logic flaws no automation will find. Both are needed.

Endpoint security

EASM does not see laptops or workstations. EDR / XDR is a separate concern.

SIEM or SOC monitoring

EASM tells you about exposure; a SOC tells you about active attacks. Different signal, different layer.

Pricing

Three tiers - sized by domain count + alert depth.

All tiers include onboarding (asset confirmation, alert routing setup) at no extra cost.

Discover

For small SMBs

$119/ month
  • Up to 5 root domains
  • Monthly report
  • Email alerts
  • Daily refresh of asset inventory
Start with Discover
Most popular

Monitor

For growing teams

$299/ month
  • Up to 25 root domains
  • Daily refresh
  • Slack / webhook alerts
  • Monthly analyst review call
  • Manual triage on critical findings
Start with Monitor

Manage

For mid-market + SDFs

Custom
  • Unlimited domains
  • Real-time alerting
  • Dedicated analyst
  • Integration with your ticketing
  • Monthly remediation calls
Discuss a Manage engagement

EASM FAQ

How is this different from a vulnerability scanner?
A vulnerability scanner takes a list of assets you give it and reports vulnerabilities. EASM builds the list, then scans it. The hard part is discovery, not scanning.
Will this find shadow IT my employees set up?
Yes, if it is internet-facing and associated with your domain or IP space. SaaS tools accessed via employees personal credentials (e.g., personal Dropbox) are out of scope - for that you need a separate Shadow SaaS discovery tool.
Is this Vexta?
Vexta is the platform we use for scanning. EASM is the service layer on top - adding manual triage, remediation guidance, and analyst support. You can buy Vexta as a self-serve product, OR buy this EASM service which bundles Vexta with our team.
How fast do you find new assets?
Most new assets appear in your dashboard within 24 hours of going public. Certificate transparency logs (where every new SSL cert is logged) give us a fast signal - usually within minutes of certificate issuance.
Can I see a sample report?
Yes. Book a demo and we will run a discovery against one of your domains in advance and walk you through what we find. No commitment - you keep the report regardless.

See your full attack surface.

30-minute demo. We run discovery against one of your domains, walk you through the assets you did not know about, and recommend a tier (or no tier - if you do not need EASM, we will say so).