What is External Attack Surface Management (EASM)?
This text was generated using artificial intelligence (AI).
External Attack Surface Management, or EASM for short, refers to the continuous identification, assessment, and monitoring of all of a company’s IT systems that are accessible from the Internet. The analysis is conducted from an attacker’s perspective: it reveals which servers, domains, services, and applications are visible to the outside world and what risks this poses. This article explains how EASM works, how it differs from vulnerability management and penetration testing, and what you should look for when selecting a solution.
Key Points at a Glance
EASM identifies all of a company's IT systems accessible via the Internet and assesses the risks they pose from an attacker's perspective.
The analysis requires no agents and no installation. It typically starts with the company's main domain.
EASM complements vulnerability management and penetration testing by providing continuous visibility into unknown and forgotten systems.
According to the BSI 2025 Situation Report, an average of 119 new vulnerabilities were reported each day during the reporting period, about 24 percent more than during the same period the previous year.
Typical findings include shadow IT, forgotten subdomains, open ports, and outdated software that is visible from the outside.
Definition: What Does "External Attack Surface Management" Mean?
A company’s external attack surface encompasses all digital assets that an attacker can access without gaining access to the internal network. These include web servers, mail servers, VPN access points, cloud services, interfaces (APIs), subdomains, certificates, and exposed administrative interfaces. External Attack Surface Management is the process of systematically mapping this attack surface, assessing its risks, and continuously monitoring changes.
In 2021, the research firm Gartner introduced EASM as a separate category in its market analyses. According to Gartner, EASM solutions help companies identify risks from internet-exposed systems that the organization is often completely unaware of. This is precisely what sets EASM apart from traditional security audits: It doesn’t just check what’s on the inventory list, but first determines what actually belongs to the company.
The demand is growing measurably. According to the BSI 2025 Situation Report, published in November 2025, an average of 119 new vulnerabilities were reported per day between July 2024 and June 2025—about 24 percent more than during the same period the previous year. At the same time, corporate systems are spreading across an ever-increasing number of locations and providers due to cloud usage, remote work, and acquisitions. Without continuous external monitoring, part of this attack surface remains unobserved and thus unprotected.
EASM, Vulnerability Management, and Penetration Testing: A Comparison
The three approaches address different questions and complement one another. Vulnerability management regularly checks known, inventoried systems for known vulnerabilities. A penetration test verifies, on a case-by-case basis, whether defined targets can actually be compromised. EASM provides the foundation for this: an up-to-date view of externally accessible systems, including assets that are not listed in any inventory.
Criterion
EASM
Vulnerability Management
Penetration Test
Perspective
The attacker's external view of all accessible systems
An Inside Look at Well-Known, Cataloged Systems
Simulated attack on specified targets
Identifies unknown assets
Yes, Discovery is a core feature
No, the familiar inventory is being checked
Only within the scope of the assignment
Frequency
Continuously or at short intervals
Scheduled Scans
Occasionally, usually once or twice a year
Requirements
No agents, no installation—just a starting point like the main domain
Scanners or agents on the network, access to the systems
Assignment, Scope Definition, Testing Window
Typical result
Current Overview of the External Attack Surface with Risk Assessment
List of Vulnerabilities in Known Systems
Evidence of attack vectors that can be exploited in practice
Role in the security process
Overview, Prioritization, and Monitoring
Ongoing review of known systems
Depth Check of Selected Systems
In practice, these approaches complement one another. EASM identifies the attack surface and prioritizes risks. Based on this, vulnerability scans can be targeted, and penetration tests can be focused on critical systems. This ensures that the budget is allocated where the risk actually lies.
How EASM Works: Discovery, Evaluation, Monitoring
It all starts with discovery. Beginning with a starting point—usually the main domain—the solution identifies all associated assets: subdomains, IP addresses and network ranges, mail and name servers, certificates, cloud instances, and web applications. To do this, it analyzes DNS data, Certificate Transparency logs, and public registration data, among other sources. No agents or installations on the corporate network are required.
In the second step, the solution evaluates the systems it has identified. It checks for open ports and accessible services, encryption and certificate configurations, email security mechanisms such as SPF, DKIM, and DMARC, as well as externally detectable software. Detected software versions can be mapped to known vulnerabilities (CVEs). Important for classification: An external analysis reveals exposure and the software in use. Whether a specific installation is actually vulnerable also depends on patch statuses, which are not always detectable from the outside. Reputable solutions clearly highlight this distinction so that your team can accurately verify the findings.
The third step is continuous monitoring. New subdomains, open ports, or expiring certificates trigger alerts as soon as they appear. Aggregated metrics such as a Security Rating make it possible to measure progress over time and ensure that management and supervisory boards can understand it. At LocateRisk, the initial results of the Security Rating within 48 hours.
Typical findings: shadow IT, forgotten subdomains, open ports
Certain patterns emerge consistently across industries and company sizes:
Shadow IT: Business units operate their own tools, test environments, or cloud services that were set up without the IT department's involvement and are not included in any security policy.
Forgotten Subdomains: Old project pages, staging systems, or campaign pages remain online even though no one maintains them anymore. If a DNS record points to an abandoned cloud resource, there is also a risk of subdomain hijacking.
Open Ports: Databases, remote desktop access, and administrative interfaces are accessible directly from the Internet, even though they are intended for internal use only.
Outdated Software: Version numbers of web servers, content management systems, or frameworks that are visible to the outside world indicate that updates are missing.
Configuration error: Expired certificates, weak TLS settings, or a lack of email security mechanisms such as DMARC make phishing and the interception of connections easier.
These findings rarely seem spectacular, but they are precisely the entry points that attackers are looking for. The BSI Situation Report 2025 illustrates just how widespread the problem is: According to the report, sensitive information—including indications of potential vulnerabilities—was publicly accessible at 47 percent of the reachable IP addresses associated with .de domains. Every neglected system lowers the barrier to a successful attack, regardless of how well the known systems are protected.
What are the benefits of EASM?
The immediate benefit is transparency. You see your own IT the way an attacker sees it and obtain a reliable inventory of externally accessible systems. Based on this, EASM prioritizes the risks: An open database port on a production system carries more weight than an expired certificate on an informational page. This allows IT teams to focus on the areas with the highest risk, and management receives a clear overview through key metrics without needing in-depth technical knowledge.
Added to this are the regulatory benefits. The NIS-2 Directive requires affected companies to implement systematic risk management. The German implementing law took effect on December 6, 2025, and, according to estimates, applies to approximately 29,500 companies in Germany. A continuously updated overview of a company’s own attack surface provides verifiable evidence of this. For financial firms, DORA additionally requires the management of Third-Party ICT Risks.
Another advantage stems from the method itself. Because the analysis works without requiring any installation or involvement on the part of the audited company, it can also be applied to service providers and suppliers. This makes EASM the technical foundation for managing supplier risks.
Selection Criteria: What to Look for in an EASM Solution
The market for EASM solutions has grown significantly since 2021. The following criteria can help with the evaluation:
Discovery Quality and Traceability: The solution should document why an asset was assigned to the company. It must be easy to make adjustments to the scope.
Clear Evaluation: Metrics such as a KPI-based security rating must be understandable to both technical staff and management alike and must justify priorities.
Continuity: One-time scans quickly become outdated. Make sure to set up ongoing monitoring with notifications for relevant changes.
Low implementation effort: An external analysis should begin without agents, without installation, and without a long project lead time. Initial results should be available within a few days—within 48 hours with LocateRisk.
Timeliness of vulnerability data: An EASM solution should be able to classify new vulnerability reports even if a final NVD assessment is not yet available. LocateRisk uses the following for this purpose: Preemptive Intelligence and cross-checks reports from multiple sources against the attack surface. This allows potential risks to be prioritized earlier.
Privacy and Hosting: For companies in Germany, key criteria include GDPR compliance, hosting in certified German data centers, and an ISO 27001-certified ISMS provided by the service provider.
Extensibility to suppliers: If you also plan to evaluate service providers in the future, the solution should Vendor Risk Management support.
It's best to test the criteria against your own attack surface. Running a test on your own primary domain will quickly show how well the discovery process identifies accessible systems and how clearly the results are presented.
All systems accessible via the Internet: domains and subdomains, IP addresses, web applications, APIs, mail and name servers, VPN and remote access, cloud services, and certificates. This also includes systems belonging to subsidiaries or acquired companies, provided they are attributable to the company.
No. EASM continuously shows which systems are accessible and where risks lie. A penetration test conducts selective, in-depth checks to determine whether specific systems can be compromised. The two approaches complement each other: EASM provides an overview and prioritization, while the penetration test performs an in-depth assessment of critical targets.
No. EASM works exclusively with information that is visible from the outside. It requires neither agents nor login credentials nor any installation. That is precisely where its methodological value lies: The analysis reveals the same view that an attacker would see.
Since no agents need to be installed, the analysis begins immediately without any project setup. The duration depends on the size of the attack surface. LocateRisk provides the initial analysis results within 48 hours. After that, the monitoring system continuously updates the results.
For any company with its own website. It is particularly relevant for organizations with established IT infrastructure, multiple locations, or acquisitions, as well as for companies subject to NIS-2 or DORA that are required to maintain records of their risk management practices.
The easiest way to get started is to take a look at your own attack surface. Request a Free Security Rating Sign up and see which of your company's systems are visible from the outside, how your security posture compares to others, and where the biggest risks lie.
We use cookies to optimize our website and our service.
Functional
Always active
Technical storage or access is strictly necessary for the lawful purpose of enabling the use of a particular service expressly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a message over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that have not been requested by the subscriber or user.
Statistics
The technical storage or access, which is carried out exclusively for statistical purposes.Technical storage or access used solely for anonymous statistical purposes. Without a subpoena, the voluntary consent of your Internet service provider, or additional records from third parties, information stored or accessed for this purpose alone generally cannot be used to identify you.
Marketing
Technical storage or access is necessary to create user profiles, to send advertisements, or to track the user on a website or across multiple websites for similar marketing purposes.