Nearly every intrusion starts with something reachable from the public internet. Attackers enumerate that surface continuously — most companies have never enumerated it once.
A forgotten host, an expired DNS record pointing at an unclaimed cloud resource, a mail domain anyone can spoof. None of it shows up in your ticketing system, and all of it is one search away for someone scanning the internet.
Marketing microsites, trial SaaS tenants, staging hosts, contractor-built subdomains — each is stood up in minutes and remembered by no one. The asset that gets breached is usually the one nobody knew was still live.
A 40-person company has the same public DNS, certificates, cloud footprint and brand to impersonate as an enterprise — without a dedicated security team, a SIEM, or an asset inventory to check the findings against. Attackers don't scale their targeting by headcount.
Patching, MDR, penetration testing and insurance questionnaires all assume you already know what you own. External discovery is the cheapest control you can buy, and the one that makes everything you already pay for actually worth it.
This isn't a replacement for the tools you already run. It's the layer underneath them — the inventory everything else assumes you have.
Everything we run is passive OSINT — nothing is touched, no agents are installed, and no change window is needed. It's priced per monitored domain, with the baseline audit and continuous monitoring included in one subscription.
The case for discovery isn't a marketing claim — it's the shape of how breaches actually start and what they cost. Figures below are from published 2025 industry research.
of breaches now begin with vulnerability exploitation — up 34% year over year, and second only to stolen credentials as a way in.
Source: Verizon DBIR 2025
of that exploitation targeted internet-facing edge devices and VPNs — up from 3% the year before. Only about 54% of those zero-days were fully patched, and the median took 32 days.
Source: Verizon DBIR 2025
is the average time to identify and contain a breach — the lowest in nine years, but still eight months of exposure before anyone notices.
Source: IBM Cost of a Data Breach 2025
is the global vs. US average cost of a single data breach. The US figure rose 9% in a year, driven mainly by heavier regulatory penalties.
Source: IBM Cost of a Data Breach 2025
A simple, checkable framing for a small or mid-sized team — not a borrowed enterprise statistic.
| Essential plan | $3,600 | / year, per domain |
|---|---|---|
| Baseline audit | Included | at purchase |
| Three-year total | $10,800 | one domain, 3 years |
| US average cost of one breach | $10,220,000 | IBM 2025 |
| Break-even reduction in breach probability | ~0.1% | over three years |
The program pays for itself if it removes a single exposed host, expired delegation or spoofable mail domain that would otherwise have become the way in — and vulnerability exploitation of internet-facing assets is now roughly one in five breaches.
Independent Forrester Total Economic Impact studies of EASM platforms measured 297% ROI and payback under six months for enterprise buyers. Those figures come from larger deployments, but they show discovery programs consistently return more than they cost.
External attack surface management is the practice of continuously discovering everything your organization exposes to the public internet — domains, subdomains, hosts, IP addresses, certificates, cloud tenants, mail records and brand assets — and assessing each of them for risk. It answers a question most companies can't: what does an attacker see when they look us up?
A vulnerability scan tests assets you already know about. A penetration test tries to break into a scope you define up front. External Recon works one step earlier: it discovers the assets themselves, from the outside, using passive sources only. It's how you build the list that the scanner and the pen tester should be working from.
Smaller organizations carry the same public exposure as large ones — the same DNS, certificates, cloud footprint and brand to impersonate — but rarely have a dedicated security team, an asset inventory or a SIEM to check against. Attackers don't scale their targeting by company size; they scan the whole internet and pick whatever answers. External discovery is the cheapest way for a lean team to close that gap.
Shadow IT is any internet-facing asset stood up outside the normal process — a marketing microsite, a trial SaaS tenant, a staging host, a contractor-built subdomain, an old cloud bucket. We surface it from public records: certificate transparency logs, DNS, passive internet scan data, search indexes and 100+ OSINT sources, then correlate it back to your organization.
No. Every check is passive and read-only. We query public data sources and public DNS — we never exploit, never brute force credentials, and never install agents on your systems.
The program pays for itself if it removes a single exposed host, expired delegation or spoofable mail domain that would otherwise have become the way in. Vulnerability exploitation of internet-facing assets is now roughly one in five breaches, and the US average cost of a breach is $10.22 million. A $3,600-a-year Essential subscription breaks even if it lowers your three-year breach probability by about 0.1% — and that is before counting the avoided disruption, regulatory fines and reputational damage. Independent Forrester Total Economic Impact studies of EASM platforms found 297% ROI and payback under six months for enterprise buyers; those figures come from larger deployments, but they show discovery programs consistently return more than they cost.
That is the more common case, and we now report it as its own risk. Many typo domains never copy your branding — they sell whoever mis-typed your address to whoever pays most that second: fake virus warnings, forced downloads, crypto wallet drains, prize bait, adult or gambling pages. We visit each live typo domain more than once, because these traffic brokers hand back a different destination on every visit, and we list every destination we observed rather than describing the domain by whichever page answered first. An AI reader judges what the page actually does to a visitor, so novel scam formats are caught and a page that merely mentions scams is not flagged. Because the destinations rotate, the remediation is not a takedown of one landing page — it is blocking and sinkholing the typo domain itself on your DNS firewall, mail gateway and proxy, which is exactly what the playbook tells you to do.
Your attack surface changes between audits — new subdomains, expiring certificates, DNS records pointed at services that were decommissioned, and fresh lookalike domains registered overnight. The average breach goes 241 days before it's identified and contained; monthly re-scanning compresses that window by flagging new exposures the month they appear instead of the quarter a pen test happens to run. Coverage is priced per monitored domain ($3,600/year), not per seat, and it keeps the remediation playbook you already received current against the live surface.
Ready to see your surface? Run the free preview scan or compare pricing & what's included.