Skip to content

ISO 27001, SOC 2, the DPDP Act and manual VAPT. Book a Free Scoping Call

Part of Managed Services8 services in this practice area

Know What You Expose

Attack Surface Management

You cannot defend an asset you do not know you own. We find everything your organisation exposes to the internet, tell you which parts of it are risky, and keep doing it on a schedule so the picture stays true as your estate changes.

See the engagement path, 6 phasesSee the full Managed Services service index

Overview

Attack surface management is a recurring service that keeps an accurate, current inventory of your internet-facing assets and the exposures on them. We discover the domains, subdomains, IP ranges, cloud-exposed services and certificates that belong to you, check them for misconfiguration and outdated software, and rank what we find by the damage it could do rather than by a scanner's severity label. A tester validates the findings before they reach you, so you are acting on confirmed exposure and not on noise. It suits organisations whose estate changes faster than their asset register does, and it pairs with penetration testing rather than replacing it.

Methodology

How the Engagement Runs

Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.

The Engagement, End to End

6 Phases, 6 Named Handovers

Flow

Flow chart of the Attack Surface Management engagement, 6 phases in order, each one selectable. Phase 1, Scope and Seed Assets. We agree what belongs to you and what does not. Everything after this runs from that seed list, so the service never tests an asset you do not own. Activities: Confirm the domains, brands, IP ranges and cloud accounts in scope; Record who owns each asset and who can authorise a change; Agree what is explicitly out of scope, including third-party platforms; Capture written authorisation for the discovery activity. Hands over Agreed Scope and Seed Asset List. Phase 2, External Asset Discovery. We expand the seed list into the full external footprint using public sources, and report the assets you did not know were yours. Activities: Enumerate subdomains from DNS and certificate transparency records; Resolve hosts to IP ranges and identify the hosting provider; Identify cloud-exposed services attributable to your accounts; Diff the inventory against the previous cycle and flag what is new. Hands over External Asset Inventory. Phase 3, Exposure and Misconfiguration Detection. We check each discovered asset for the exposures that give an attacker a starting point, without exploiting anything. Activities: Identify open ports, reachable services and their versions; Flag outdated software and exposed administrative interfaces; Review DNS, SPF, DKIM and DMARC records for weaknesses; Check certificate validity, expiry and TLS configuration. Hands over Exposure Findings Register. Phase 4, Shadow IT and Third-Party Exposure. We look for the assets nobody registered: forgotten staging sites, marketing microsites and supplier-hosted systems carrying your name, all from public sources only. Activities: Identify unregistered subdomains and abandoned staging environments; Attribute look-alike and expired domains associated with your brand; Map supplier-hosted systems that present under your domains; Flag dangling DNS records that point at released infrastructure. Hands over Shadow IT and Third-Party Exposure Review. Phase 5, Validation and Risk-Based Prioritisation. A tester reviews every finding before it reaches you, discards what is not real and ranks the rest by the damage it enables in your business. Activities: Confirm each finding manually and drop false positives; Rate exposures by reachability, sensitivity and business impact; Group related findings into one fix where a single change closes them; Identify the findings that need a full penetration test to prove. Hands over Validated, Prioritised Finding List. Phase 6, Reporting, Remediation and Retest. You get a report each cycle covering what changed, what matters and what to do about it. When you tell us a fix is in, we retest that finding and confirm whether it is closed. Activities: Report new, changed and closed exposures against the last cycle; Give specific remediation guidance to the named asset owner; Retest fixed findings and record whether they genuinely closed; Hand findings that need deeper testing into a scoped VAPT engagement. Hands over Periodic Exposure Report and Retest Record. Each phase begins from the artefact the phase before it produced.

Phase 01 Scope and Seed Assets

We agree what belongs to you and what does not. Everything after this runs from that seed list, so the service never tests an asset you do not own.

What Happens In This Phase

  • Confirm the domains, brands, IP ranges and cloud accounts in scope
  • Record who owns each asset and who can authorise a change
  • Agree what is explicitly out of scope, including third-party platforms
  • Capture written authorisation for the discovery activity

The Handover

Agreed Scope and Seed Asset List

The next phase starts from this.

Read the handover cards on their own and you have the paper trail. Select a phase to see what happens inside it.
  1. 01

    Scope and Seed Assets

    We agree what belongs to you and what does not. Everything after this runs from that seed list, so the service never tests an asset you do not own.

    OutputAgreed Scope and Seed Asset List

    Activities

    • Confirm the domains, brands, IP ranges and cloud accounts in scope
    • Record who owns each asset and who can authorise a change
    • Agree what is explicitly out of scope, including third-party platforms
    • Capture written authorisation for the discovery activity
  2. 02

    External Asset Discovery

    We expand the seed list into the full external footprint using public sources, and report the assets you did not know were yours.

    OutputExternal Asset Inventory

    Activities

    • Enumerate subdomains from DNS and certificate transparency records
    • Resolve hosts to IP ranges and identify the hosting provider
    • Identify cloud-exposed services attributable to your accounts
    • Diff the inventory against the previous cycle and flag what is new
  3. 03

    Exposure and Misconfiguration Detection

    We check each discovered asset for the exposures that give an attacker a starting point, without exploiting anything.

    OutputExposure Findings Register

    Activities

    • Identify open ports, reachable services and their versions
    • Flag outdated software and exposed administrative interfaces
    • Review DNS, SPF, DKIM and DMARC records for weaknesses
    • Check certificate validity, expiry and TLS configuration
  4. 04

    Shadow IT and Third-Party Exposure

    We look for the assets nobody registered: forgotten staging sites, marketing microsites and supplier-hosted systems carrying your name, all from public sources only.

    OutputShadow IT and Third-Party Exposure Review

    Activities

    • Identify unregistered subdomains and abandoned staging environments
    • Attribute look-alike and expired domains associated with your brand
    • Map supplier-hosted systems that present under your domains
    • Flag dangling DNS records that point at released infrastructure
  5. 05

    Validation and Risk-Based Prioritisation

    A tester reviews every finding before it reaches you, discards what is not real and ranks the rest by the damage it enables in your business.

    OutputValidated, Prioritised Finding List

    Activities

    • Confirm each finding manually and drop false positives
    • Rate exposures by reachability, sensitivity and business impact
    • Group related findings into one fix where a single change closes them
    • Identify the findings that need a full penetration test to prove
  6. 06

    Reporting, Remediation and Retest

    You get a report each cycle covering what changed, what matters and what to do about it. When you tell us a fix is in, we retest that finding and confirm whether it is closed.

    OutputPeriodic Exposure Report and Retest Record

    Activities

    • Report new, changed and closed exposures against the last cycle
    • Give specific remediation guidance to the named asset owner
    • Retest fixed findings and record whether they genuinely closed
    • Hand findings that need deeper testing into a scoped VAPT engagement

Specification

What We Run, and What We Measure You Against

The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.

Scope

What Is Examined, and What it Is Measured Against

Map

Map of the Attack Surface Management scope, running left to right in three stages. Stage one, what we run, 7 tools and techniques: DNS and certificate transparency sources, Subdomain enumeration tooling, Port and service scanners, TLS and mail record checkers, Provider asset inventory APIs, Open-source intelligence sources, Asset inventory register. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 5 published standards: CIS Controls v8 Controls 1 and 2, NIST CSF 2.0 ID.AM, ISO/IEC 27001:2022 Annex A 5.9 and 8.8, CERT-In Directions, MITRE ATT&CK Reconnaissance (TA0043).

What We Run

7 tools

  • DNS and certificate transparency sources
  • Subdomain enumeration tooling
  • Port and service scanners
  • TLS and mail record checkers
  • Provider asset inventory APIs
  • Open-source intelligence sources
  • Asset inventory register

Converges On

One Set of Proven Findings

Every issue is reproduced by hand before it is written down, and it is written down once.

Measured Against

5 standards

  • CISControls
  • NIST CSF 2.0 ID.AM
  • ISO/IEC 27001:2022 Annex A 5.9 and 8.8
  • CERTCERT-In Directions
  • MITRE ATT&CK Reconnaissance (TA0043)
One pass of testing and analysis, one set of findings, then that single set is graded against every standard on the right. You are not paying for the same work once per framework.

Deliverables

What You Receive

  • Inventory of internet-facing assets, refreshed each cycle
  • Validated exposure findings ranked by business impact
  • Shadow IT and third-party exposure review
  • Remediation guidance for each named asset owner
  • Periodic exposure report with a retest record for closed findings

Scope This Engagement

Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

How is attack surface management different from a penetration test?

The two differ in shape rather than quality. Attack surface management is broad, shallow and recurring: it answers what you expose to the internet right now and which parts of that exposure look wrong, across an estate that keeps changing. A penetration test is narrow, deep and point in time: it takes an agreed scope and tests it hard by hand for a fixed window, proving impact with a working exploit. Neither replaces the other. Without discovery, a test scope is only as good as your asset register, and most registers are out of date. Without testing, a discovered exposure stays a suspicion rather than a proven risk. In practice clients run this service through the year and schedule tests against what it surfaces. When a finding needs proving rather than reporting, we hand it into a full VAPT engagement and test it properly.

What exactly do you look for, and what do you not cover?

We discover the domains, subdomains, IP ranges, cloud-exposed services and certificates attributable to you, then check them for exposures an attacker would use as a starting point: open ports and reachable services, outdated software versions, exposed administrative interfaces, weak DNS and email authentication records, and certificate or TLS problems. We also report shadow IT and third-party exposure that we can see from public sources, such as forgotten staging sites and supplier-hosted systems presenting under your domains. We are equally clear about what is outside this service. We do not monitor dark web marketplaces or breach forums, we do not exploit what we find, and we do not watch your estate around the clock; discovery and reporting run on an agreed cycle. Deeper work, such as proving that an exposed service can actually be compromised, belongs in a scoped penetration test.

How often does this run, and what do we receive each cycle?

Discovery and exposure checks run monthly by default, with the shadow IT and third-party review each quarter, and we agree a cadence that matches how fast your estate changes. Each cycle you receive a refreshed inventory of internet-facing assets, the validated exposure findings ranked by business impact, and a report that separates what is new, what changed and what closed since the last cycle. That last part is what makes the service useful over time: the value is not a one-off list but a trend you can act on and show to your leadership. Remediation guidance goes to the named owner of each asset rather than into a general pile, and when you tell us a fix is in, we retest that finding and record whether it genuinely closed. A closed finding means fixed and retested, not acknowledged.

Do we get raw scanner output, or does someone check the findings?

A tester reviews every finding before it reaches you. Automated discovery is how we cover a large external estate quickly, but raw output is a poor deliverable: it mixes assets that are not yours with services that are deliberately open and version guesses that are wrong, and it ranks everything by a generic severity score that knows nothing about your business. So we confirm each finding by hand, discard the false positives, and rank what remains by how reachable it is, how sensitive the system behind it is and what an attacker could do next. Related findings that one change would close are grouped into a single fix rather than listed five times. The result is a shorter list than a scanner would produce, which is the point: you should be able to work through a cycle's findings rather than triage them.

Which frameworks and standards does this service support?

Asset inventory is the first thing almost every framework asks for, and it is the control organisations most often cannot evidence. This service produces that evidence. It maps to CIS Controls v8 Controls 1 and 2, the inventory of enterprise assets and of software, and to the identify function of NIST CSF 2.0, specifically the ID.AM asset management outcomes. Under ISO/IEC 27001:2022 it supports Annex A 5.9, the inventory of information and other associated assets, and Annex A 8.8, the management of technical vulnerabilities, with a dated record of what you exposed and when you fixed it. It also helps in the general sense the CERT-In Directions assume, which is that an organisation knows which internet-facing systems it runs before it has to report an incident on one. We supply the inventory and the exposure history as audit evidence.

Keep Moving Through Managed Services

Service 3 of 8 in this practice area