How to Run External Attack Surface Management Properly

by Rebecca Sutton

External attack surface management is how a business finds out what an attacker can already see, before the attacker gets there first. It means continuously discovering, checking and tracking every internet-facing asset a company has. That runs from registered domains to a cloud storage bucket someone set up two years ago and forgot about. This guide covers how to actually run the process, not just what the term means.

Colleagues reviewing findings on laptops during external attack surface management

Why external attack surface management exists

Ask most IT teams for a list of every system reachable from the public internet and you get a confident answer. Check that answer against reality and it is usually incomplete. New subdomains get registered for a marketing campaign and never documented. A developer spins up a test API and leaves it running after the project ends. A supplier integration opens an endpoint nobody logged. None of that shows up in a register built from memory and old documentation.

External attack surface management, EASM for short, exists precisely because the register and the reality drift apart. NCSC’s own guidance frames it as a continuous cycle. Discover what is actually out there, assess it for weaknesses, then fix what needs fixing.

Running the discovery step

Start wider than feels comfortable. A thorough discovery pass covers:

  • Every domain and subdomain your business has registered, including old ones nobody uses any more.
  • Cloud accounts across every provider in use, not just the main one IT manages directly.
  • Third-party services and APIs connected to your core systems, especially anything set up by a team outside IT.
  • Certificates and DNS records, which often reveal forgotten infrastructure that stopped being actively maintained.

Most of what turns up here is not a critical vulnerability. It is simply something nobody knew was there. That alone is worth knowing, since an attacker scanning your IP ranges does not care whether an asset was intentional.

Assessing what discovery finds

Once an asset is confirmed, it needs the same scrutiny as anything on your known estate. Check for missing patches, weak or default credentials, unnecessary services left running, and configuration that exposes more than intended. NCSC’s vulnerability management guidance recommends checking your estate at least monthly, with tighter cycles for anything internet-facing. A newly discovered asset should go straight into that same assessment rhythm, not sit in a separate, lower-priority queue.

EASM, vulnerability scanning and penetration testing, working together

Activity Answers
EASM What is actually exposed to the internet, including things we did not know about?
Vulnerability scanning What known weaknesses exist on the assets we already track?
Penetration testing Can someone genuinely exploit this, and how far could they get?

Run them in that order and each stage sharpens the next. Discovery expands the picture. Scanning flags weaknesses across it on a schedule. A properly scoped penetration test then proves which of the serious findings are genuinely dangerous. Our guide on judging a provider’s penetration testing methodology covers what a scope built on real discovery should look like. That beats one based on a list agreed a year ago and never revisited.

What good ongoing practice looks like

A one-off discovery exercise is useful, but the value compounds when it repeats. Set a cadence: monthly is a reasonable default, tighter for a business that changes fast. Assign an owner for triaging new findings, not just running the scan. Fold confirmed exposures into the same remediation process as any other vulnerability, rather than treating them as a separate project. And feed the highest-risk findings into the scope of your next penetration test, so testing time goes where the real exposure sits.

Doing this without enterprise tooling

A smaller business does not need a dedicated EASM platform to get real value from the practice. A quarterly manual pass covers a meaningful share of what a paid platform automates continuously. Check your domain registrar’s full list, your cloud provider consoles, and run a basic subdomain enumeration tool. It will not catch everything a live monitoring service would. But it beats not looking at all, which is the actual starting point for most smaller organisations.

Common mistakes when getting started

The first mistake is scoping discovery too narrowly. Limiting a first pass to one domain misses subsidiaries, acquired businesses, and marketing microsites registered under a different name. Cast the net wider than feels necessary at first.

The second mistake is treating a discovery report as the finish line. External attack surface management only creates value once findings get triaged, assigned and closed. A report that sits in an inbox protects nobody.

The third mistake is running discovery once and stopping. The whole point of external attack surface management is that it keeps working after the first pass. New assets appear constantly. A programme that runs once behaves like a vulnerability scan, not genuine external attack surface management.

What to do with the findings once they land

A discovery pass that produces a list and stops there has not achieved much. Every newly found asset needs a decision: bring it under active management, patch and secure it properly, or decommission it if nobody actually needs it any more. Decommissioning is often the fastest fix. An asset that no longer exists cannot be exploited, and plenty of what discovery turns up is genuinely no longer needed by the business.

Track the outcome of each finding the same way you would track any other security issue, with an owner and a target date. External attack surface management works best when it plugs into a process that already exists, rather than becoming a parallel system nobody checks. A quarterly review of open findings, alongside your usual patching cycle, keeps the list from quietly growing unattended in the background.

Frequently asked questions

How is this different from a vulnerability assessment?

A vulnerability assessment checks systems you already know about against a database of weaknesses. External attack surface management starts earlier, discovering which systems are exposed in the first place.

Do we need to buy a platform to do this properly?

No. A manual review of domains, cloud accounts and third-party integrations covers much of the same ground for a smaller footprint. Dedicated tools earn their cost once the estate gets large enough that manual tracking becomes impractical.

How often should discovery repeat?

Monthly is a reasonable starting cadence for most mid-sized businesses, matching NCSC’s general guidance on vulnerability assessment frequency. Anything that changes faster, such as frequent new product launches, needs tighter cycles.

What happens to a finding once discovery flags it?

It should enter the same remediation process as any other vulnerability: an owner, a priority based on real risk, and a deadline. A finding that sits in a report nobody actions delivers no value at all.

Can this replace an annual penetration test?

No. It tells you what is exposed, not whether it is genuinely exploitable or how damaging a breach would be. Those questions still need hands-on testing.

Aardwolf Security can help scope a penetration test around what is genuinely exposed, if your discovery process has turned up more footprint than expected. Get in touch to talk it through, or see our full penetration testing services.

Subscribe to our newsletter

Honest updates, straight to your inbox. Unsubscribe any time.

You may also like