Vulnerability & exposure

What is External attack surface management (EASM)?

Definition

Continuously discovering and monitoring everything an organisation exposes to the internet, including forgotten servers, cloud services and domains, to find weaknesses before attackers do.

How it works

Organisations often have more internet-facing assets than they know about: old test servers, shadow IT, cloud services spun up by other teams, or subsidiaries’ systems. EASM looks from the outside, the way an attacker would.

Findings typically include exposed admin interfaces, unpatched services, expired certificates and misconfigured cloud storage.

Key points

  • An outside-in, attacker’s-eye view
  • Finds unknown and forgotten assets
  • Runs continuously as the estate changes
  • Feeds prioritised fixes into vulnerability management

Common questions

Is EASM a pentest?

No. EASM is continuous discovery and monitoring; a pentest is a point-in-time attempt to exploit weaknesses.

Does Touchpoint scan our perimeter?

Yes. Expose, part of Trace, scans your internet-facing and cloud assets and shows where you are exposed.

Talk to someone who does this every day

Questions about EASM? Our team will give you a straight answer.

Contact us