{"id":9295,"date":"2026-08-06T07:44:10","date_gmt":"2026-08-06T07:44:10","guid":{"rendered":"http:\/\/locaterisk.com\/de\/?post_type=wissen&#038;p=9295"},"modified":"2026-08-06T09:08:20","modified_gmt":"2026-08-06T09:08:20","slug":"what-is-easm","status":"publish","type":"wissen","link":"https:\/\/locaterisk.com\/en\/know\/what-is-easm\/","title":{"rendered":"What is External Attack Surface Management (EASM)?"},"content":{"rendered":"<h1 class=\"wp-block-heading\">What is External Attack Surface Management (EASM)?<\/h1><span class=\"lr-ai-disclosure\" style=\"display:block;max-width:843px;margin:8px auto 28px;font-size:14px;line-height:1.4;color:#8b93a7;font-family:inherit;font-style:italic;\">This text was generated using artificial intelligence (AI).<\/span>\n<p>External Attack Surface Management, or EASM for short, refers to the continuous identification, assessment, and monitoring of all of a company\u2019s IT systems that are accessible from the Internet. The analysis is conducted from an attacker\u2019s perspective: it reveals which servers, domains, services, and applications are visible to the outside world and what risks this poses. This article explains how EASM works, how it differs from vulnerability management and penetration testing, and what you should look for when selecting a solution.<\/p>\n<h2 class=\"wp-block-heading\">Key Points at a Glance<\/h2>\n<ul class=\"wp-block-list\"><li>EASM identifies all of a company's IT systems accessible via the Internet and assesses the risks they pose from an attacker's perspective.<\/li><li>The analysis requires no agents and no installation. It typically starts with the company's main domain.<\/li><li>EASM complements vulnerability management and penetration testing by providing continuous visibility into unknown and forgotten systems.<\/li><li>According to the BSI 2025 Situation Report, an average of 119 new vulnerabilities were reported each day during the reporting period, about 24 percent more than during the same period the previous year.<\/li><li>Typical findings include shadow IT, forgotten subdomains, open ports, and outdated software that is visible from the outside.<\/li><\/ul>\n<h2 class=\"wp-block-heading\">Definition: What Does \"External Attack Surface Management\" Mean?<\/h2>\n<p>A company\u2019s external attack surface encompasses all digital assets that an attacker can access without gaining access to the internal network. These include web servers, mail servers, VPN access points, cloud services, interfaces (APIs), subdomains, certificates, and exposed administrative interfaces. External Attack Surface Management is the process of systematically mapping this attack surface, assessing its risks, and continuously monitoring changes.<\/p>\n<p>In 2021, the research firm Gartner introduced EASM as a separate category in its market analyses. According to Gartner, EASM solutions help companies identify risks from internet-exposed systems that the organization is often completely unaware of. This is precisely what sets EASM apart from traditional security audits: It doesn\u2019t just check what\u2019s on the inventory list, but first determines what actually belongs to the company.<\/p>\n<p>The demand is growing measurably. According to the BSI 2025 Situation Report, published in November 2025, an average of 119 new vulnerabilities were reported per day between July 2024 and June 2025\u2014about 24 percent more than during the same period the previous year. At the same time, corporate systems are spreading across an ever-increasing number of locations and providers due to cloud usage, remote work, and acquisitions. Without continuous external monitoring, part of this attack surface remains unobserved and thus unprotected.<\/p>\n<h2 class=\"wp-block-heading\">EASM, Vulnerability Management, and Penetration Testing: A Comparison<\/h2>\n<p>The three approaches address different questions and complement one another. Vulnerability management regularly checks known, inventoried systems for known vulnerabilities. A penetration test verifies, on a case-by-case basis, whether defined targets can actually be compromised. EASM provides the foundation for this: an up-to-date view of externally accessible systems, including assets that are not listed in any inventory.<\/p>\n<figure class=\"wp-block-table\"><table><thead><tr><th>Criterion<\/th><th>EASM<\/th><th>Vulnerability Management<\/th><th>Penetration Test<\/th><\/tr><\/thead><tbody><tr><td>Perspective<\/td><td>The attacker's external view of all accessible systems<\/td><td>An Inside Look at Well-Known, Cataloged Systems<\/td><td>Simulated attack on specified targets<\/td><\/tr><tr><td>Identifies unknown assets<\/td><td>Yes, Discovery is a core feature<\/td><td>No, the familiar inventory is being checked<\/td><td>Only within the scope of the assignment<\/td><\/tr><tr><td>Frequency<\/td><td>Continuously or at short intervals<\/td><td>Scheduled Scans<\/td><td>Occasionally, usually once or twice a year<\/td><\/tr><tr><td>Requirements<\/td><td>No agents, no installation\u2014just a starting point like the main domain<\/td><td>Scanners or agents on the network, access to the systems<\/td><td>Assignment, Scope Definition, Testing Window<\/td><\/tr><tr><td>Typical result<\/td><td>Current Overview of the External Attack Surface with Risk Assessment<\/td><td>List of Vulnerabilities in Known Systems<\/td><td>Evidence of attack vectors that can be exploited in practice<\/td><\/tr><tr><td>Role in the security process<\/td><td>Overview, Prioritization, and Monitoring<\/td><td>Ongoing review of known systems<\/td><td>Depth Check of Selected Systems<\/td><\/tr><\/tbody><\/table><\/figure>\n<p>In practice, these approaches complement one another. EASM identifies the attack surface and prioritizes risks. Based on this, vulnerability scans can be targeted, and penetration tests can be focused on critical systems. This ensures that the budget is allocated where the risk actually lies.<\/p>\n<h2 class=\"wp-block-heading\">How EASM Works: Discovery, Evaluation, Monitoring<\/h2>\n<p>It all starts with discovery. Beginning with a starting point\u2014usually the main domain\u2014the solution identifies all associated assets: subdomains, IP addresses and network ranges, mail and name servers, certificates, cloud instances, and web applications. To do this, it analyzes DNS data, Certificate Transparency logs, and public registration data, among other sources. No agents or installations on the corporate network are required.<\/p>\n<p>In the second step, the solution evaluates the systems it has identified. It checks for open ports and accessible services, encryption and certificate configurations, email security mechanisms such as SPF, DKIM, and DMARC, as well as externally detectable software. Detected software versions can be mapped to known vulnerabilities (CVEs). Important for classification: An external analysis reveals exposure and the software in use. Whether a specific installation is actually vulnerable also depends on patch statuses, which are not always detectable from the outside. Reputable solutions clearly highlight this distinction so that your team can accurately verify the findings.<\/p>\n<p>The third step is continuous monitoring. New subdomains, open ports, or expiring certificates trigger alerts as soon as they appear. Aggregated metrics such as a <a href=\"\/en\/know\/what-is-a-security-rating\/\">Security Rating<\/a> make it possible to measure progress over time and ensure that management and supervisory boards can understand it. At LocateRisk, the initial results of the <a href=\"\/en\/landing\/it-risk-analysis\/\">Security Rating<\/a> within 48 hours.<\/p>\n<h2 class=\"wp-block-heading\">Typical findings: shadow IT, forgotten subdomains, open ports<\/h2>\n<p>Certain patterns emerge consistently across industries and company sizes:<\/p>\n<ul class=\"wp-block-list\"><li><strong>Shadow IT:<\/strong> Business units operate their own tools, test environments, or cloud services that were set up without the IT department's involvement and are not included in any security policy.<\/li><li><strong>Forgotten Subdomains:<\/strong> Old project pages, staging systems, or campaign pages remain online even though no one maintains them anymore. If a DNS record points to an abandoned cloud resource, there is also a risk of subdomain hijacking.<\/li><li><strong>Open Ports:<\/strong> Databases, remote desktop access, and administrative interfaces are accessible directly from the Internet, even though they are intended for internal use only.<\/li><li><strong>Outdated Software:<\/strong> Version numbers of web servers, content management systems, or frameworks that are visible to the outside world indicate that updates are missing.<\/li><li><strong>Configuration error:<\/strong> Expired certificates, weak TLS settings, or a lack of email security mechanisms such as DMARC make phishing and the interception of connections easier.<\/li><\/ul>\n<p>These findings rarely seem spectacular, but they are precisely the entry points that attackers are looking for. The BSI Situation Report 2025 illustrates just how widespread the problem is: According to the report, sensitive information\u2014including indications of potential vulnerabilities\u2014was publicly accessible at 47 percent of the reachable IP addresses associated with .de domains. Every neglected system lowers the barrier to a successful attack, regardless of how well the known systems are protected.<\/p>\n<h2 class=\"wp-block-heading\">What are the benefits of EASM?<\/h2>\n<p>The immediate benefit is transparency. You see your own IT the way an attacker sees it and obtain a reliable inventory of externally accessible systems. Based on this, EASM prioritizes the risks: An open database port on a production system carries more weight than an expired certificate on an informational page. This allows IT teams to focus on the areas with the highest risk, and management receives a clear overview through key metrics without needing in-depth technical knowledge.<\/p>\n<p>Added to this are the regulatory benefits. The <a href=\"\/en\/know\/nis2-directive-overview\/\">NIS-2 Directive<\/a> requires affected companies to implement systematic risk management. The German implementing law took effect on December 6, 2025, and, according to estimates, applies to approximately 29,500 companies in Germany. A continuously updated overview of a company\u2019s own attack surface provides verifiable evidence of this. For financial firms, DORA additionally requires the management of <a href=\"\/en\/know\/dora-ict-third-party-risk\/\">Third-Party ICT Risks<\/a>.<\/p>\n<p>Another advantage stems from the method itself. Because the analysis works without requiring any installation or involvement on the part of the audited company, it can also be applied to service providers and suppliers. This makes EASM the technical foundation for managing supplier risks.<\/p>\n<h2 class=\"wp-block-heading\">Selection Criteria: What to Look for in an EASM Solution<\/h2>\n<p>The market for EASM solutions has grown significantly since 2021. The following criteria can help with the evaluation:<\/p>\n<ul class=\"wp-block-list\"><li><strong>Discovery Quality and Traceability:<\/strong> The solution should document why an asset was assigned to the company. It must be easy to make adjustments to the scope.<\/li><li><strong>Clear Evaluation:<\/strong> Metrics such as a KPI-based security rating must be understandable to both technical staff and management alike and must justify priorities.<\/li><li><strong>Continuity:<\/strong> One-time scans quickly become outdated. Make sure to set up ongoing monitoring with notifications for relevant changes.<\/li><li><strong>Low implementation effort:<\/strong> An external analysis should begin without agents, without installation, and without a long project lead time. Initial results should be available within a few days\u2014within 48 hours with LocateRisk.<\/li><li><strong>Timeliness of vulnerability data:<\/strong> An EASM solution should be able to classify new vulnerability reports even if a final NVD assessment is not yet available. LocateRisk uses the following for this purpose: <a href=\"\/en\/landing\/preemptive-intelligence-identifying-cyber-risks-before-they-become-apparent\/\">Preemptive Intelligence<\/a> and cross-checks reports from multiple sources against the attack surface. This allows potential risks to be prioritized earlier.<\/li><li><strong>Privacy and Hosting:<\/strong> For companies in Germany, key criteria include GDPR compliance, hosting in certified German data centers, and an ISO 27001-certified ISMS provided by the service provider.<\/li><li><strong>Extensibility to suppliers:<\/strong> If you also plan to evaluate service providers in the future, the solution should <a href=\"\/en\/landing\/vendor-risk-management-made-easy\/\">Vendor Risk Management<\/a> support.<\/li><\/ul>\n<p>It's best to test the criteria against your own attack surface. Running a test on your own primary domain will quickly show how well the discovery process identifies accessible systems and how clearly the results are presented.<\/p>\n\n<div class=\"wp-block-lr-faq-module\"><div class=\"content\"><h3>Frequently asked questions<\/h3><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">What does the external attack surface include?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">All systems accessible via the Internet: domains and subdomains, IP addresses, web applications, APIs, mail and name servers, VPN and remote access, cloud services, and certificates. This also includes systems belonging to subsidiaries or acquired companies, provided they are attributable to the company.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">Does EASM replace a penetration test?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">No. EASM continuously shows which systems are accessible and where risks lie. A penetration test conducts selective, in-depth checks to determine whether specific systems can be compromised. The two approaches complement each other: EASM provides an overview and prioritization, while the penetration test performs an in-depth assessment of critical targets.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">Does EASM need access to the internal network?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">No. EASM works exclusively with information that is visible from the outside. It requires neither agents nor login credentials nor any installation. That is precisely where its methodological value lies: The analysis reveals the same view that an attacker would see.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">How quickly does an EASM analysis produce results?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">Since no agents need to be installed, the analysis begins immediately without any project setup. The duration depends on the size of the attack surface. LocateRisk provides the initial analysis results within 48 hours. After that, the monitoring system continuously updates the results.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">For which companies is EASM a good fit?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">For any company with its own website. It is particularly relevant for organizations with established IT infrastructure, multiple locations, or acquisitions, as well as for companies subject to NIS-2 or DORA that are required to maintain records of their risk management practices.<\/p><\/div><\/div><\/div><\/div>\n\n<p>The easiest way to get started is to take a look at your own attack surface. Request a <a href=\"\/en\/landing\/free-rating\/\">Free Security Rating<\/a> Sign up and see which of your company's systems are visible from the outside, how your security posture compares to others, and where the biggest risks lie.<\/p>","protected":false},"excerpt":{"rendered":"<p>EASM Explained Simply: Definition, How It Works, How It Differs from Penetration Testing and Vulnerability Management, and Criteria for Selecting a Solution.<\/p>","protected":false},"author":6,"featured_media":0,"template":"","wissen_thema":[818],"class_list":["post-9295","wissen","type-wissen","status-publish","hentry","wissen_thema-easm-angriffsflaeche"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>EASM: Definition, Funktionsweise, Nutzen \u2013 LocateRisk<\/title>\n<meta name=\"description\" content=\"Was ist EASM? Definition, Abgrenzung zu Pentest und Schwachstellenmanagement, typische Funde und Auswahlkriterien. Mit kostenlosem Security-Rating.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"http:\/\/locaterisk.com\/en\/know\/what-is-easm\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"EASM: Definition, Funktionsweise, Nutzen \u2013 LocateRisk\" \/>\n<meta property=\"og:description\" content=\"Was ist EASM? Definition, Abgrenzung zu Pentest und Schwachstellenmanagement, typische Funde und Auswahlkriterien. Mit kostenlosem Security-Rating.\" \/>\n<meta property=\"og:url\" content=\"http:\/\/locaterisk.com\/en\/know\/what-is-easm\/\" \/>\n<meta property=\"og:site_name\" content=\"LocateRisk\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-06T09:08:20+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_Generisch_03-1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1080\" \/>\n\t<meta property=\"og:image:height\" content=\"1080\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"http:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/was-ist-easm\\\/\",\"url\":\"http:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/was-ist-easm\\\/\",\"name\":\"EASM: Definition, Funktionsweise, Nutzen \u2013 LocateRisk\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#website\"},\"datePublished\":\"2026-08-06T07:44:10+00:00\",\"dateModified\":\"2026-08-06T09:08:20+00:00\",\"description\":\"Was ist EASM? Definition, Abgrenzung zu Pentest und Schwachstellenmanagement, typische Funde und Auswahlkriterien. Mit kostenlosem Security-Rating.\",\"breadcrumb\":{\"@id\":\"http:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/was-ist-easm\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"http:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/was-ist-easm\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"http:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/was-ist-easm\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"http:\\\/\\\/locaterisk.com\\\/de\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Wissen\",\"item\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Was ist External Attack Surface Management (EASM)?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#website\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/\",\"name\":\"LocateRisk\",\"description\":\"IT-Sicherheit messen und vergleichen\",\"publisher\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#organization\",\"name\":\"LocateRisk\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2020\\\/11\\\/Kettenglieder_V0216-9.jpg\",\"contentUrl\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2020\\\/11\\\/Kettenglieder_V0216-9.jpg\",\"width\":1920,\"height\":1080,\"caption\":\"LocateRisk\"},\"image\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/company\\\/locaterisk\\\/\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"EASM: Definition, How It Works, Benefits \u2013 LocateRisk","description":"What is EASM? Definition, differences from penetration testing and vulnerability management, typical findings, and selection criteria. Includes a free security rating.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"http:\/\/locaterisk.com\/en\/know\/what-is-easm\/","og_locale":"en_US","og_type":"article","og_title":"EASM: Definition, Funktionsweise, Nutzen \u2013 LocateRisk","og_description":"Was ist EASM? Definition, Abgrenzung zu Pentest und Schwachstellenmanagement, typische Funde und Auswahlkriterien. Mit kostenlosem Security-Rating.","og_url":"http:\/\/locaterisk.com\/en\/know\/what-is-easm\/","og_site_name":"LocateRisk","article_modified_time":"2026-08-06T09:08:20+00:00","og_image":[{"width":1080,"height":1080,"url":"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_Generisch_03-1.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"http:\/\/locaterisk.com\/de\/wissen\/was-ist-easm\/","url":"http:\/\/locaterisk.com\/de\/wissen\/was-ist-easm\/","name":"EASM: Definition, How It Works, Benefits \u2013 LocateRisk","isPartOf":{"@id":"https:\/\/locaterisk.com\/de\/#website"},"datePublished":"2026-08-06T07:44:10+00:00","dateModified":"2026-08-06T09:08:20+00:00","description":"What is EASM? Definition, differences from penetration testing and vulnerability management, typical findings, and selection criteria. Includes a free security rating.","breadcrumb":{"@id":"http:\/\/locaterisk.com\/de\/wissen\/was-ist-easm\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["http:\/\/locaterisk.com\/de\/wissen\/was-ist-easm\/"]}]},{"@type":"BreadcrumbList","@id":"http:\/\/locaterisk.com\/de\/wissen\/was-ist-easm\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"http:\/\/locaterisk.com\/de\/"},{"@type":"ListItem","position":2,"name":"Wissen","item":"https:\/\/locaterisk.com\/de\/wissen\/"},{"@type":"ListItem","position":3,"name":"Was ist External Attack Surface Management (EASM)?"}]},{"@type":"WebSite","@id":"https:\/\/locaterisk.com\/de\/#website","url":"https:\/\/locaterisk.com\/de\/","name":"LocateRisk","description":"Measure and compare IT security","publisher":{"@id":"https:\/\/locaterisk.com\/de\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/locaterisk.com\/de\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/locaterisk.com\/de\/#organization","name":"LocateRisk","url":"https:\/\/locaterisk.com\/de\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/locaterisk.com\/de\/#\/schema\/logo\/image\/","url":"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_V0216-9.jpg","contentUrl":"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_V0216-9.jpg","width":1920,"height":1080,"caption":"LocateRisk"},"image":{"@id":"https:\/\/locaterisk.com\/de\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.linkedin.com\/company\/locaterisk\/"]}]}},"_links":{"self":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen\/9295","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen"}],"about":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/types\/wissen"}],"author":[{"embeddable":true,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/users\/6"}],"version-history":[{"count":6,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen\/9295\/revisions"}],"predecessor-version":[{"id":9334,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen\/9295\/revisions\/9334"}],"wp:attachment":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/media?parent=9295"}],"wp:term":[{"taxonomy":"wissen_thema","embeddable":true,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen_thema?post=9295"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}