EASM & Attack Surface
Fundamentals of External Attack Surface Management
Cybersecurity Audit: Process, Effort, and Cost Factors
How to properly plan cybersecurity audits: audit scope, procedures, roles, evidences, cost drivers, and criteria for comparable quotes.
Vulnerability Scan, Penetration Test, Security Audit, or EASM: Which Approach Is Right for You?
Comparison of vulnerability scans, penetration tests, security audits, and EASM based on criteria such as scope, depth of testing, authorization, timing, and results.
Conducting an IT Risk Analysis: Process, Data Sources, and Results
Here's how to conduct an IT risk analysis—from scope, through data sources and context, to prioritization and documented risk treatment.
Preemptive Intelligence: Early Vulnerability Alerts Before NVD Enrichment
Preemptive Intelligence cross-references early vulnerability alerts with the external attack surface before NVD enrichment is complete.
EASM in the CTEM Process: What Role Does External Attack Detection Play?
CTEM combines scoping, discovery, prioritization, validation, and mobilization. EASM provides an external perspective on this, but does not cover the entire process on its own.
EASM, CAASM, and DRPS: Differences and Applications
EASM, CAASM, and DRPS provide different perspectives on assets and digital risks. This comparison highlights their functions, limitations, and how they interact.
Exposure Management vs. Vulnerability Management
A Comparison of Exposure Management and Vulnerability Management: Scope, data sources, prioritization, workflows, and results clearly categorized.
What a Company Domain Reveals About Its External Attack Surface—and What It Doesn't
DNS, certificates, services, email protection, and technical information provide external indicators. Their significance is limited to assignment, version, and internal controls.
Attack Surface Assessment: From Asset Discovery to Prioritization
Attack Surface Assessment Explained: Discover external assets, attribute findings, evaluate them in context, and prioritize appropriate measures.
What is a security rating?
Security ratings measure IT security from an external perspective and make it comparable. How KPI-based ratings are developed, what they’re used for, and what their limitations are.
What is External Attack Surface Management (EASM)?
EASM Explained Simply: Definition, How It Works, How It Differs from Penetration Testing and Vulnerability Management, and Criteria for Selecting a Solution.
Supplier Risk & TPRM
Supplier Risk Assessment: Criteria, Scoring, and Assessment Methods
A comprehensible model for criticality, inherent risk, controls, evidence, and residual risk in supplier assessment.
Third-Party Risk Management: Tasks, Process, and Technical Data Sources
How companies capture third parties, evaluate them by criticality, control them, and monitor them throughout the entire business relationship.
Regulatory Affairs & Compliance
NIS2, DORA, KRITIS, and More: Explained in Simple Terms
Third-Party ICT Risk Under DORA: Obligations and Implementation
Information Registers, Contractual Clauses, Exit Strategies: What DORA Requires Regarding Third-Party ICT Risks and How to Implement These Obligations in Five Steps.
NIS2 Requirements: The 10 Mandatory Measures Under Section 30 of the BSIG
The Ten Risk Management Measures Under Section 30 of the BSIG: What Is Required, How to Implement Them Successfully, and How They Map to ISO 27001.
NIS2 and Supply Chain Security: Managing Third-Party Risks
NIS2 Makes Supply Chain Compliance Mandatory: Requirements Under Section 30 of the BSIG, a Comparison of Methods, and a 5-Step Workflow with Security Ratings and VRM.
DORA: The Digital Operational Resilience Act Explained
What the Digital Operational Resilience Act Covers: Scope, Five Pillars, BaFin Oversight, Sanctions, and How It Differs from the NIS2 Directive.
NIS2 Directive: What Companies Need to Know Now
The NIS2 Implementation Act has been in effect since December 6, 2025. An overview of sectors, size thresholds, obligations, fines, and BSI deadlines.


