Know What You Expose
Attack Surface Management
You cannot defend an asset you do not know you own. We find everything your organisation exposes to the internet, tell you which parts of it are risky, and keep doing it on a schedule so the picture stays true as your estate changes.
See the engagement path, 6 phasesSee the full Managed Services service index
Overview
Attack surface management is a recurring service that keeps an accurate, current inventory of your internet-facing assets and the exposures on them. We discover the domains, subdomains, IP ranges, cloud-exposed services and certificates that belong to you, check them for misconfiguration and outdated software, and rank what we find by the damage it could do rather than by a scanner's severity label. A tester validates the findings before they reach you, so you are acting on confirmed exposure and not on noise. It suits organisations whose estate changes faster than their asset register does, and it pairs with penetration testing rather than replacing it.
Methodology
How the Engagement Runs
Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.
6 Phases, 6 Named Handovers
Flow
Flow chart of the Attack Surface Management engagement, 6 phases in order, each one selectable. Phase 1, Scope and Seed Assets. We agree what belongs to you and what does not. Everything after this runs from that seed list, so the service never tests an asset you do not own. Activities: Confirm the domains, brands, IP ranges and cloud accounts in scope; Record who owns each asset and who can authorise a change; Agree what is explicitly out of scope, including third-party platforms; Capture written authorisation for the discovery activity. Hands over Agreed Scope and Seed Asset List. Phase 2, External Asset Discovery. We expand the seed list into the full external footprint using public sources, and report the assets you did not know were yours. Activities: Enumerate subdomains from DNS and certificate transparency records; Resolve hosts to IP ranges and identify the hosting provider; Identify cloud-exposed services attributable to your accounts; Diff the inventory against the previous cycle and flag what is new. Hands over External Asset Inventory. Phase 3, Exposure and Misconfiguration Detection. We check each discovered asset for the exposures that give an attacker a starting point, without exploiting anything. Activities: Identify open ports, reachable services and their versions; Flag outdated software and exposed administrative interfaces; Review DNS, SPF, DKIM and DMARC records for weaknesses; Check certificate validity, expiry and TLS configuration. Hands over Exposure Findings Register. Phase 4, Shadow IT and Third-Party Exposure. We look for the assets nobody registered: forgotten staging sites, marketing microsites and supplier-hosted systems carrying your name, all from public sources only. Activities: Identify unregistered subdomains and abandoned staging environments; Attribute look-alike and expired domains associated with your brand; Map supplier-hosted systems that present under your domains; Flag dangling DNS records that point at released infrastructure. Hands over Shadow IT and Third-Party Exposure Review. Phase 5, Validation and Risk-Based Prioritisation. A tester reviews every finding before it reaches you, discards what is not real and ranks the rest by the damage it enables in your business. Activities: Confirm each finding manually and drop false positives; Rate exposures by reachability, sensitivity and business impact; Group related findings into one fix where a single change closes them; Identify the findings that need a full penetration test to prove. Hands over Validated, Prioritised Finding List. Phase 6, Reporting, Remediation and Retest. You get a report each cycle covering what changed, what matters and what to do about it. When you tell us a fix is in, we retest that finding and confirm whether it is closed. Activities: Report new, changed and closed exposures against the last cycle; Give specific remediation guidance to the named asset owner; Retest fixed findings and record whether they genuinely closed; Hand findings that need deeper testing into a scoped VAPT engagement. Hands over Periodic Exposure Report and Retest Record. Each phase begins from the artefact the phase before it produced.
Phase 01 Scope and Seed Assets
We agree what belongs to you and what does not. Everything after this runs from that seed list, so the service never tests an asset you do not own.
What Happens In This Phase
- Confirm the domains, brands, IP ranges and cloud accounts in scope
- Record who owns each asset and who can authorise a change
- Agree what is explicitly out of scope, including third-party platforms
- Capture written authorisation for the discovery activity
The Handover
Agreed Scope and Seed Asset List
The next phase starts from this.
Phase 01 Scope and Seed Assets
We agree what belongs to you and what does not. Everything after this runs from that seed list, so the service never tests an asset you do not own.
What Happens In This Phase
- Confirm the domains, brands, IP ranges and cloud accounts in scope
- Record who owns each asset and who can authorise a change
- Agree what is explicitly out of scope, including third-party platforms
- Capture written authorisation for the discovery activity
The Handover
Agreed Scope and Seed Asset List
The next phase starts from this.
- 01
Scope and Seed Assets
We agree what belongs to you and what does not. Everything after this runs from that seed list, so the service never tests an asset you do not own.
OutputAgreed Scope and Seed Asset ListActivities
- Confirm the domains, brands, IP ranges and cloud accounts in scope
- Record who owns each asset and who can authorise a change
- Agree what is explicitly out of scope, including third-party platforms
- Capture written authorisation for the discovery activity
- 02
External Asset Discovery
We expand the seed list into the full external footprint using public sources, and report the assets you did not know were yours.
OutputExternal Asset InventoryActivities
- Enumerate subdomains from DNS and certificate transparency records
- Resolve hosts to IP ranges and identify the hosting provider
- Identify cloud-exposed services attributable to your accounts
- Diff the inventory against the previous cycle and flag what is new
- 03
Exposure and Misconfiguration Detection
We check each discovered asset for the exposures that give an attacker a starting point, without exploiting anything.
OutputExposure Findings RegisterActivities
- Identify open ports, reachable services and their versions
- Flag outdated software and exposed administrative interfaces
- Review DNS, SPF, DKIM and DMARC records for weaknesses
- Check certificate validity, expiry and TLS configuration
- 04
Shadow IT and Third-Party Exposure
We look for the assets nobody registered: forgotten staging sites, marketing microsites and supplier-hosted systems carrying your name, all from public sources only.
OutputShadow IT and Third-Party Exposure ReviewActivities
- Identify unregistered subdomains and abandoned staging environments
- Attribute look-alike and expired domains associated with your brand
- Map supplier-hosted systems that present under your domains
- Flag dangling DNS records that point at released infrastructure
- 05
Validation and Risk-Based Prioritisation
A tester reviews every finding before it reaches you, discards what is not real and ranks the rest by the damage it enables in your business.
OutputValidated, Prioritised Finding ListActivities
- Confirm each finding manually and drop false positives
- Rate exposures by reachability, sensitivity and business impact
- Group related findings into one fix where a single change closes them
- Identify the findings that need a full penetration test to prove
- 06
Reporting, Remediation and Retest
You get a report each cycle covering what changed, what matters and what to do about it. When you tell us a fix is in, we retest that finding and confirm whether it is closed.
OutputPeriodic Exposure Report and Retest RecordActivities
- Report new, changed and closed exposures against the last cycle
- Give specific remediation guidance to the named asset owner
- Retest fixed findings and record whether they genuinely closed
- Hand findings that need deeper testing into a scoped VAPT engagement
Specification
What We Run, and What We Measure You Against
The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.
What Is Examined, and What it Is Measured Against
Map
Map of the Attack Surface Management scope, running left to right in three stages. Stage one, what we run, 7 tools and techniques: DNS and certificate transparency sources, Subdomain enumeration tooling, Port and service scanners, TLS and mail record checkers, Provider asset inventory APIs, Open-source intelligence sources, Asset inventory register. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 5 published standards: CIS Controls v8 Controls 1 and 2, NIST CSF 2.0 ID.AM, ISO/IEC 27001:2022 Annex A 5.9 and 8.8, CERT-In Directions, MITRE ATT&CK Reconnaissance (TA0043).
What We Run
7 tools
- DNS and certificate transparency sources
- Subdomain enumeration tooling
- Port and service scanners
- TLS and mail record checkers
- Provider asset inventory APIs
- Open-source intelligence sources
- Asset inventory register
Converges On
One Set of Proven Findings
Every issue is reproduced by hand before it is written down, and it is written down once.
Measured Against
5 standards
- CISControls
- NIST CSF 2.0 ID.AM
- ISO/IEC 27001:2022 Annex A 5.9 and 8.8
- CERTCERT-In Directions
- MITRE ATT&CK Reconnaissance (TA0043)
Deliverables
What You Receive
- Inventory of internet-facing assets, refreshed each cycle
- Validated exposure findings ranked by business impact
- Shadow IT and third-party exposure review
- Remediation guidance for each named asset owner
- Periodic exposure report with a retest record for closed findings
Scope This Engagement
Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.
How is attack surface management different from a penetration test?
The two differ in shape rather than quality. Attack surface management is broad, shallow and recurring: it answers what you expose to the internet right now and which parts of that exposure look wrong, across an estate that keeps changing. A penetration test is narrow, deep and point in time: it takes an agreed scope and tests it hard by hand for a fixed window, proving impact with a working exploit. Neither replaces the other. Without discovery, a test scope is only as good as your asset register, and most registers are out of date. Without testing, a discovered exposure stays a suspicion rather than a proven risk. In practice clients run this service through the year and schedule tests against what it surfaces. When a finding needs proving rather than reporting, we hand it into a full VAPT engagement and test it properly.
What exactly do you look for, and what do you not cover?
We discover the domains, subdomains, IP ranges, cloud-exposed services and certificates attributable to you, then check them for exposures an attacker would use as a starting point: open ports and reachable services, outdated software versions, exposed administrative interfaces, weak DNS and email authentication records, and certificate or TLS problems. We also report shadow IT and third-party exposure that we can see from public sources, such as forgotten staging sites and supplier-hosted systems presenting under your domains. We are equally clear about what is outside this service. We do not monitor dark web marketplaces or breach forums, we do not exploit what we find, and we do not watch your estate around the clock; discovery and reporting run on an agreed cycle. Deeper work, such as proving that an exposed service can actually be compromised, belongs in a scoped penetration test.
How often does this run, and what do we receive each cycle?
Discovery and exposure checks run monthly by default, with the shadow IT and third-party review each quarter, and we agree a cadence that matches how fast your estate changes. Each cycle you receive a refreshed inventory of internet-facing assets, the validated exposure findings ranked by business impact, and a report that separates what is new, what changed and what closed since the last cycle. That last part is what makes the service useful over time: the value is not a one-off list but a trend you can act on and show to your leadership. Remediation guidance goes to the named owner of each asset rather than into a general pile, and when you tell us a fix is in, we retest that finding and record whether it genuinely closed. A closed finding means fixed and retested, not acknowledged.
Do we get raw scanner output, or does someone check the findings?
A tester reviews every finding before it reaches you. Automated discovery is how we cover a large external estate quickly, but raw output is a poor deliverable: it mixes assets that are not yours with services that are deliberately open and version guesses that are wrong, and it ranks everything by a generic severity score that knows nothing about your business. So we confirm each finding by hand, discard the false positives, and rank what remains by how reachable it is, how sensitive the system behind it is and what an attacker could do next. Related findings that one change would close are grouped into a single fix rather than listed five times. The result is a shorter list than a scanner would produce, which is the point: you should be able to work through a cycle's findings rather than triage them.
Which frameworks and standards does this service support?
Asset inventory is the first thing almost every framework asks for, and it is the control organisations most often cannot evidence. This service produces that evidence. It maps to CIS Controls v8 Controls 1 and 2, the inventory of enterprise assets and of software, and to the identify function of NIST CSF 2.0, specifically the ID.AM asset management outcomes. Under ISO/IEC 27001:2022 it supports Annex A 5.9, the inventory of information and other associated assets, and Annex A 8.8, the management of technical vulnerabilities, with a dated record of what you exposed and when you fixed it. It also helps in the general sense the CERT-In Directions assume, which is that an organisation knows which internet-facing systems it runs before it has to report an incident on one. We supply the inventory and the exposure history as audit evidence.
Keep Moving Through Managed Services
Service 3 of 8 in this practice area
Practice Area
More in Managed Services
- Red Team AssessmentGoal-based adversary simulation across people, process and technology
- SOC as a ServiceA 24/7 security operations centre run by our analysts
- vCISOSenior security leadership on demand, without a full-time hire
- vDPOA data protection officer as a service for the DPDP Act and beyond
- Phishing SimulationsSafe, realistic phishing tests that build lasting instincts
- Awareness TrainingsSecurity training your people actually remember and use
- Digital and Cyber ForensicsSound investigation and evidence when something has gone wrong