Why external attack surface discovery matters

Nearly every intrusion starts with something reachable from the public internet. Attackers enumerate that surface continuously — most companies have never enumerated it once.

Attackers start where you aren't looking

A forgotten host, an expired DNS record pointing at an unclaimed cloud resource, a mail domain anyone can spoof. None of it shows up in your ticketing system, and all of it is one search away for someone scanning the internet.

Shadow IT and forgotten assets outgrow the team

Marketing microsites, trial SaaS tenants, staging hosts, contractor-built subdomains — each is stood up in minutes and remembered by no one. The asset that gets breached is usually the one nobody knew was still live.

Smaller teams carry the same exposure as large ones

A 40-person company has the same public DNS, certificates, cloud footprint and brand to impersonate as an enterprise — without a dedicated security team, a SIEM, or an asset inventory to check the findings against. Attackers don't scale their targeting by headcount.

Discovery comes before every other control

Patching, MDR, penetration testing and insurance questionnaires all assume you already know what you own. External discovery is the cheapest control you can buy, and the one that makes everything you already pay for actually worth it.

Where external attack surface management fits in your security program

This isn't a replacement for the tools you already run. It's the layer underneath them — the inventory everything else assumes you have.

Know what you own
External Recon — passive discovery of your public surface
Fix what's exposed
Your IT team or MSP, guided by the remediation playbook included in every paid report
Test what's hardened
Penetration testing, scoped to the assets discovery actually found
Watch what's running
EDR / MDR / managed SOC on the endpoints and servers you control
Prove it to others
Cyber insurance applications, SOC 2 evidence, client security reviews

Everything we run is passive OSINT — nothing is touched, no agents are installed, and no change window is needed. It's priced per monitored domain, with the baseline audit and continuous monitoring included in one subscription.

What the research says

The case for discovery isn't a marketing claim — it's the shape of how breaches actually start and what they cost. Figures below are from published 2025 industry research.

20%

of breaches now begin with vulnerability exploitation — up 34% year over year, and second only to stolen credentials as a way in.

Source: Verizon DBIR 2025

22%

of that exploitation targeted internet-facing edge devices and VPNs — up from 3% the year before. Only about 54% of those zero-days were fully patched, and the median took 32 days.

Source: Verizon DBIR 2025

241 days

is the average time to identify and contain a breach — the lowest in nine years, but still eight months of exposure before anyone notices.

Source: IBM Cost of a Data Breach 2025

$4.44M / $10.22M

is the global vs. US average cost of a single data breach. The US figure rose 9% in a year, driven mainly by heavier regulatory penalties.

Source: IBM Cost of a Data Breach 2025

Does this pay for itself?

A simple, checkable framing for a small or mid-sized team — not a borrowed enterprise statistic.

Essential plan$3,600/ year, per domain
Baseline auditIncludedat purchase
Three-year total$10,800one domain, 3 years
US average cost of one breach$10,220,000IBM 2025
Break-even reduction in breach probability~0.1%over three years

The program pays for itself if it removes a single exposed host, expired delegation or spoofable mail domain that would otherwise have become the way in — and vulnerability exploitation of internet-facing assets is now roughly one in five breaches.

Independent Forrester Total Economic Impact studies of EASM platforms measured 297% ROI and payback under six months for enterprise buyers. Those figures come from larger deployments, but they show discovery programs consistently return more than they cost.

External attack surface management FAQ

What is external attack surface management (EASM)?

External attack surface management is the practice of continuously discovering everything your organization exposes to the public internet — domains, subdomains, hosts, IP addresses, certificates, cloud tenants, mail records and brand assets — and assessing each of them for risk. It answers a question most companies can't: what does an attacker see when they look us up?

How is this different from a vulnerability scan or a penetration test?

A vulnerability scan tests assets you already know about. A penetration test tries to break into a scope you define up front. External Recon works one step earlier: it discovers the assets themselves, from the outside, using passive sources only. It's how you build the list that the scanner and the pen tester should be working from.

Why do small and mid-sized companies need external attack surface discovery?

Smaller organizations carry the same public exposure as large ones — the same DNS, certificates, cloud footprint and brand to impersonate — but rarely have a dedicated security team, an asset inventory or a SIEM to check against. Attackers don't scale their targeting by company size; they scan the whole internet and pick whatever answers. External discovery is the cheapest way for a lean team to close that gap.

What is shadow IT, and how do you find it?

Shadow IT is any internet-facing asset stood up outside the normal process — a marketing microsite, a trial SaaS tenant, a staging host, a contractor-built subdomain, an old cloud bucket. We surface it from public records: certificate transparency logs, DNS, passive internet scan data, search indexes and 100+ OSINT sources, then correlate it back to your organization.

Is anything touched or attacked during the scan?

No. Every check is passive and read-only. We query public data sources and public DNS — we never exploit, never brute force credentials, and never install agents on your systems.

What return should we expect from an external attack surface audit?

The program pays for itself if it removes a single exposed host, expired delegation or spoofable mail domain that would otherwise have become the way in. Vulnerability exploitation of internet-facing assets is now roughly one in five breaches, and the US average cost of a breach is $10.22 million. A $3,600-a-year Essential subscription breaks even if it lowers your three-year breach probability by about 0.1% — and that is before counting the avoided disruption, regulatory fines and reputational damage. Independent Forrester Total Economic Impact studies of EASM platforms found 297% ROI and payback under six months for enterprise buyers; those figures come from larger deployments, but they show discovery programs consistently return more than they cost.

What if a lookalike domain isn't pretending to be us at all?

That is the more common case, and we now report it as its own risk. Many typo domains never copy your branding — they sell whoever mis-typed your address to whoever pays most that second: fake virus warnings, forced downloads, crypto wallet drains, prize bait, adult or gambling pages. We visit each live typo domain more than once, because these traffic brokers hand back a different destination on every visit, and we list every destination we observed rather than describing the domain by whichever page answered first. An AI reader judges what the page actually does to a visitor, so novel scam formats are caught and a page that merely mentions scams is not flagged. Because the destinations rotate, the remediation is not a takedown of one landing page — it is blocking and sinkholing the typo domain itself on your DNS firewall, mail gateway and proxy, which is exactly what the playbook tells you to do.

Why a subscription rather than a one-off audit?

Your attack surface changes between audits — new subdomains, expiring certificates, DNS records pointed at services that were decommissioned, and fresh lookalike domains registered overnight. The average breach goes 241 days before it's identified and contained; monthly re-scanning compresses that window by flagging new exposures the month they appear instead of the quarter a pen test happens to run. Coverage is priced per monitored domain ($3,600/year), not per seat, and it keeps the remediation playbook you already received current against the live surface.

Ready to see your surface? Run the free preview scan or compare pricing & what's included.