Attack Surface Management, In Practice

The campaign ended three years ago. In a first discovery sweep at a mid-market company, its subdomain still points to a decommissioned host. A cloud application leads back to an account a business unit opened on a corporate card. Infrastructure inherited through an acquisition appears nowhere in the asset register.

The scan has produced leads, not established ownership. Confirm which assets the company controls, preserve the evidence, and assign someone to investigate each mismatch.

What attack surface management actually discovers

Attack surface management identifies assets and exposures so the organization can reduce what an attacker could reach.

External attack surface management (EASM) builds an outside-in inventory of internet-facing assets. Cyber asset attack surface management (CAASM) builds a consolidated inventory of internal and external assets through integrations with existing tools. Gartner’s ASM framework.

What does that uncover? Forgotten subdomains, exposed services, cloud resources, and acquired infrastructure missing from the approved inventory. Shadow IT asset discovery can reveal a service; billing records may be needed to establish who bought it. A dangling DNS record needs validation before anyone declares a takeover vulnerability.

Identity controls belong in Identity Is the New Perimeter. For this sweep, reconcile confirmed assets into the register and record how each was attributed.

How often the sweep has to run

If discovery happens only at the annual pentest, the next eleven months run against a point-in-time inventory. That is a cadence failure before it is a tooling failure.

The Cybersecurity and Infrastructure Security Agency (CISA), in BOD 23-01, requires automated asset discovery every seven days and initiation of vulnerability enumeration every fourteen days. Discovery must cover, at minimum, the agency’s entire IPv4 space. Enumeration covers all discovered assets in scope, including roaming devices. For managed endpoints and network devices, privileged credentials are required to the maximum extent possible where technology supports them; qualifying agent-based methods also count.

The directive binds Federal Civilian Executive Branch agencies and covers more than internet-facing assets. CISA urges other organizations to adopt its guidance; it is not a private-sector mandate. Separately, CISA’s voluntary Cross-Sector Cybersecurity Performance Goals, version 1.0.1, recommend updating IP-addressed IT and OT asset inventories at least monthly.

For an external estate, set weekly discovery as a starting cadence and check again after launches, cloud changes, or acquisitions. Track coverage and missed runs, not just whether a job completed.

Why the findings list does not shrink

A list of eleven hundred findings can still leave nobody accountable for the next action. Discovery without a named owner and a remediation service-level agreement (SLA) produces a backlog, not an operating program.

Give each validated finding an accountable person, an affected service, evidence, a priority, and a due date. Define when the remediation clock starts, who can approve an exception, and where overdue work escalates. Set deadlines by exposure and business impact. CISA’s Known Exploited Vulnerabilities catalog records exploitation observed in the wild, including flaws in public-facing products such as MOVEit Transfer; use it to inform priority.

Attribution disputes need an interim triage owner and a deadline for resolution. “The subsidiary owns it” needs a person’s name. The abandoned campaign may require marketing to approve retiring DNS. The acquired system may need a migration decision before anyone can shut it down.

Keep approved risk exceptions visible with an expiration date. Separate them from verified fixes. Recheck the exposure after remediation, then report unassigned findings, overdue work, and time to verified closure.

Where ASM sits against vulnerability management and CTEM

Attack surface management asks what exists and what is exposed. Vulnerability management identifies, prioritizes, and remediates known flaws on those assets.

Gartner’s continuous threat exposure management (CTEM) program has five stages: scope, discover, prioritize, validate, and mobilize. ASM supplies discovery; it does not replace the program.

ASM finds what an attacker could reach. Threat hunting looks for an attacker already inside—the subject of Threat Hunting Beyond the Alerts, planned for October 22.

Start with one discovery cycle: reconcile the assets, assign the findings, agree on remediation deadlines, and verify closure. Put the next sweep on the calendar before closing the first.


Sources

  1. CISA — BOD 23-01: Improving Asset Visibility and Vulnerability Detection on Federal Networks. October 3, 2022. Establishes seven-day automated discovery and fourteen-day initiation of vulnerability enumeration, with scope and credential requirements.

  2. CISA — CISA Directs Federal Agencies to Improve Cybersecurity Asset Visibility and Vulnerability Detection. October 3, 2022. Official CISA bulletin confirming the recommendation to organizations outside federal agencies.

  3. CISA — Cross-Sector Cybersecurity Performance Goals. Version 1.0.1, March 2023; Goal 1.A, Asset Inventory. Supports the separately identified monthly inventory recommendation.

  4. CISA — Known Exploited Vulnerabilities Catalog. Supports observed exploitation and remediation prioritization; relevant example: MOVEit Transfer, CVE-2023-34362.

  5. Gartner — Innovation Insight for Attack Surface Management. Mitchell Schneider, John Watts, and Pete Shoard; March 24, 2022. Original Gartner report, publicly hosted copy; definitions on pages 4–5.

  6. Jeremy D’Hoinne, Gartner — Gartner: How to Manage Cybersecurity Threats, Not Episodes. September 7, 2023. Gartner analyst’s article published by Express Computer; verifies the five CTEM stages.


Disclaimer

The opening scenario is a composite illustration, not a report of a specific client engagement. Operational recommendations are general guidance; organizations should set assessment scope and remediation deadlines according to their environment and applicable obligations.


Next
Next

PCI DSS : What SaaS Platforms Owe Their Customers Under v4.0.1