EASM

EASM four stages of external attack surface discovery explained

EASM answers a question no internal tool can: what does your company look like from the outside, to someone with no credentials and no invitation?

  • Glossary
  • Detection

The short answer

EASM stands for external attack surface management. It continuously discovers every internet-facing asset associated with an organisation, attributes them back to the company, assesses their exposure and watches for change. The defining characteristic is that it works without credentials and without an inventory, because the assets that matter most are the ones nobody remembered to list.

Every other security control assumes you know what you are protecting. This is the one that questions the assumption.

What sits on an external attack surface

Rarely the production application. Almost always the things around it.

AssetHow it ends up exposed
Forgotten subdomainsA campaign site, an old marketing page or a DNS record pointing at infrastructure that no longer exists
Staging and dev environmentsStood up for a sprint, left reachable, usually with weaker controls and real data
Undocumented APIsEndpoints shipped faster than the API inventory was updated
Cloud storage bucketsMade public for one legitimate reason and never reverted
Expiring or misissued certificatesA certificate lapses and a service either breaks or quietly drops to something weaker
Exposed admin interfacesA management console or database port reachable from the internet rather than behind private access
Shadow infrastructureA subscription opened on a personal card, or infrastructure inherited through an acquisition

The four EASM stages

Discover Domains, IPs, certs, services, endpoints Attribute Decide what is actually yours Assess Exposure, weakness, priority Monitor Catch what appears next week Attribute is the hard stage, and the one that decides whether the output is useful. A tool that claims a shared CDN address as yours produces noise nobody will read twice.

EASM, CSPM and vulnerability scanning

All three look for weaknesses. They differ on where they stand when they look.

EASMCSPMVulnerability scanning
Vantage pointOutside, unauthenticatedInside your cloud accountsAgainst a defined target list
Needs credentialsNoYesUsually
Finds unknown assetsYes, that is the purposeOnly within accounts you connectedNo, it scans what you gave it
Blind toAnything not reachable from the internetAssets outside the connected accountsEverything absent from the list
Core questionWhat do we even have out there?Is what we built configured safely?Does this known thing have a known flaw?

Vulnerability scanning inherits your blind spots

A scanner tests the targets you point it at, so a clean report means the assets on your list are healthy. It says nothing about the staging box a contractor stood up in a different account eighteen months ago. That is the gap EASM exists to close, and it is why a clean vulnerability management programme and an unknown exposed asset coexist comfortably.

Why the surface grows on its own

Nobody decides to expand an attack surface. It happens as a side effect of ordinary work: a launch that needed a landing page, a demo environment for a prospect, an integration that required an endpoint, a team that moved fast because moving fast was the instruction.

Two forces make it worse over time. Cloud infrastructure is trivial to create and easy to forget, so the cost of leaving something running is low enough to ignore. And staff turnover means the person who knows why a host exists is often no longer there to ask. The surface does not shrink by itself, which is why the fourth stage, monitoring, matters more than the first. A one-off discovery exercise is accurate for about a week.

How Osto handles EASM

Discovery runs as part of the web and API protection layer rather than as a separate scanning product. Applications and APIs are found automatically and brought under protection once identified, so discovery leads directly to a control rather than to a ticket. Certificate lifecycle is tracked in the same place, which closes the most common quiet failure on the list above.

What a single stack adds is the assessment stage. A newly discovered host is evaluated against cloud posture, scanned for known weaknesses, and its activity correlated in the same SIEM as identity and endpoint events. Finding an unknown asset is useful. Knowing within minutes whether it is dangerous, and protecting it without a separate deployment, is the part that changes what a small team can actually do. That inventory also answers the asset management questions in ISO 27001 and the Identify function of NIST CSF.

Platform walkthrough

Discovery that ends in protection

Applications and APIs discovered automatically and brought under protection once found, with certificates, cloud posture and correlation in the same stack. One owner, one dashboard.

Book a demo

Auto-discovery, auto-protection · Built for lean teams · One platform, everything

Frequently asked questions

What is EASM?

External attack surface management. It discovers every internet-facing asset belonging to an organisation, attributes them, assesses their exposure and monitors for change, all without credentials or a pre-existing inventory.

How is EASM different from vulnerability scanning?

A scanner tests targets you supply. EASM finds the targets. A clean scan report covers only the assets on your list, which is why an organisation can have healthy vulnerability management and still have an unknown host exposed.

Is EASM the same as CSPM?

No. CSPM works inside the cloud accounts you connect and checks configuration. EASM works from outside with no credentials and can find assets in accounts nobody told you about. They are complementary rather than overlapping.

Do small companies need EASM?

Often more than large ones. Small teams create infrastructure quickly, document it lightly and lose institutional memory when someone leaves. The surface is smaller but the proportion of it that is undocumented is usually higher.

Is a one-off discovery scan enough?

No. An attack surface changes as fast as the engineering team ships. A point-in-time inventory is accurate for about a week, which is why continuous monitoring is the stage that produces the value.