Services · EASM
Find the 30% of your attack surface you do not know about.
The average company has 30% more internet-facing assets than its security team knows about. Forgotten subdomains. Old marketing sites. Cloud accounts spun up by a developer six months ago. Each unknown asset is a possible entry point. External Attack Surface Management (EASM) finds them all, monitors them continuously, and tells you when something new appears that should not be there.
The shadow-IT problem in numbers
What our EASM service covers
Six layers - because asset discovery alone is not enough.
A scanner that knows your assets is straightforward. The hard part is building the asset list in the first place, and getting useful, prioritized signal out of the resulting noise.
Continuous asset discovery
We start from your root domain(s) and IP ranges and discover everything connected: subdomains (via DNS, certificate transparency logs, passive sources), associated IPs, cloud assets (AWS, Azure, GCP), exposed services (open ports, running software, versions), and SSL/TLS certificates. Daily refresh.
Shadow IT detection
SaaS spun up by a marketing team. A staging server that became production. A subdomain pointing to an old hosting provider. We flag assets associated with your domain that do not appear in your asset inventory - and route the alert to the person who should know.
Risk-scored vulnerability findings
Every discovered asset is scanned for vulnerabilities (CVEs, weak SSL/TLS configuration, exposed admin panels, missing security headers, outdated software). Findings are prioritized by exploitability and asset criticality - not just CVSS score - so your team works on what matters first.
Change monitoring + alerting
You are notified when something changes on your attack surface: a new subdomain appears, a port opens, a certificate is about to expire, a service version downgrades, an exposed database becomes publicly reachable. Alerts route via email, Slack, or webhook.
Manual triage by analysts
Automated EASM alerts can generate noise. Every critical finding is reviewed by a human analyst before it reaches you. We give context: "this is exploitable in your stack" or "this is theoretically present but the version is patched."
Remediation guidance, not just findings
Every finding comes with specific remediation steps - what to change, where, in what order. For complex findings, we get on a call with your engineering team and walk them through the fix.
Who needs EASM
If any of these describes your situation, you need it.
Engineering teams that ship to the internet
If developers can spin up infrastructure without security review, you need EASM. The blind spot is built into the workflow.
Companies with acquisitions or mergers
You inherit someone else attack surface. EASM maps it - on day one, not after the auditor asks.
Companies with marketing microsites
Campaign sites, landing pages, partner microsites - created by marketing, forgotten by IT. EASM catches them.
Companies preparing for SOC 2 / ISO 27001
Auditors increasingly ask "how do you know your full asset inventory?" EASM is the answer.
Companies in regulated industries
Fintech (SEC, PCI), healthcare, ecommerce. Regulators expect you to know your exposure - and ask for it specifically.
Companies after a near-miss or breach
Once you have seen an unknown asset bite you, you do not want it to happen again. EASM is the preventive layer.
What EASM is NOT
To be useful, here is what EASM does not replace.
EASM is one layer in a complete security program. We are honest about that - and we will tell you whether you need EASM right now, or whether a different control gives you more value first.
Internal vulnerability scanning
EASM is external-facing. Internal networks need separate scanning.
Manual penetration testing
Automated discovery catches the obvious. Manual testing catches business-logic flaws no automation will find. Both are needed.
Endpoint security
EASM does not see laptops or workstations. EDR / XDR is a separate concern.
SIEM or SOC monitoring
EASM tells you about exposure; a SOC tells you about active attacks. Different signal, different layer.
Pricing
Three tiers - sized by domain count + alert depth.
All tiers include onboarding (asset confirmation, alert routing setup) at no extra cost.
Discover
For small SMBs
- Up to 5 root domains
- Monthly report
- Email alerts
- Daily refresh of asset inventory
Monitor
For growing teams
- Up to 25 root domains
- Daily refresh
- Slack / webhook alerts
- Monthly analyst review call
- Manual triage on critical findings
Manage
For mid-market + SDFs
- Unlimited domains
- Real-time alerting
- Dedicated analyst
- Integration with your ticketing
- Monthly remediation calls
EASM FAQ
How is this different from a vulnerability scanner?
Will this find shadow IT my employees set up?
Is this Vexta?
How fast do you find new assets?
Can I see a sample report?
See your full attack surface.
30-minute demo. We run discovery against one of your domains, walk you through the assets you did not know about, and recommend a tier (or no tier - if you do not need EASM, we will say so).

