What Attack Surface Management Actually Finds

Stand up an attack surface management program and the first discovery pass almost always returns more internet-facing assets than the configuration management database lists. The gap is the finding, and it is usually administrative residue: a marketing subdomain from an agency engagement three years ago, still resolving to a storage bucket that was decommissioned without scrubbing the DNS record; a cloud account opened on a business unit credit card to test an analytics dashboard, now running exposed management interfaces; a pair of file transfer servers inherited in an acquisition and never folded into patch management. None of it appeared on the vulnerability report, because the scanner was never pointed at it.

What Attack Surface Management Finds That Scanners Miss

Attack surface management is the continuous discovery, cataloging, and analysis of every asset an organization operates that is reachable from outside its network boundary, including assets that no internal record claims. Vulnerability management inspects a known inventory for known flaws, while attack surface management establishes what the inventory should have contained in the first place.

The practical difference shows up in what gets found: dangling DNS records, orphaned cloud resources, exposed Remote Desktop Protocol services, forgotten staging environments, and shadow IT deployed outside procurement, which is the same governance gap that makes identity the practical perimeter. Adversaries reach the same assets through the reconnaissance techniques cataloged in MITRE ATT&CK, using public sources that require no access to your network. Point discovery at your own perimeter before someone else does.

EASM and CAASM Solve Different Problems

External attack surface management (EASM) evaluates infrastructure from the outside in, using passive scanning, DNS enumeration, and adversary-style reconnaissance to find internet-facing assets without credentials or prior knowledge. Cyber asset attack surface management (CAASM) evaluates infrastructure from the inside out, using API integrations with cloud providers, directory services, and endpoint tools to consolidate fragmented inventories into a single register.

EASM tells you what an attacker can reach. CAASM tells you what you own. Most organizations buy one, and then cannot explain why the register still disagrees with reality. Start with EASM when the perimeter is unmapped, and with CAASM when the perimeter is mapped but ownership is not.

Set Discovery Cadence at 7 Days

Automated asset discovery should run every 7 days, the interval CISA Binding Operational Directive 23-01 requires of Federal Civilian Executive Branch agencies across the entire IPv4 space the agency uses. Vulnerability enumeration follows every 14 days. The directive binds federal agencies only, and private enterprises borrow the cadence because no stronger public benchmark exists.

Two details get lost in secondhand summaries and both change how you run the program. The 14-day rule requires enumeration to be initiated on schedule whether or not the previous scan has finished, which removes the standard excuse that large estates cannot complete a cycle. And CISA's Cross-Sector Cybersecurity Performance Goals 2.0, the voluntary baseline written for everyone outside the federal branch, is looser: it asks for a regularly updated asset inventory with business-critical assets refreshed more frequently, without naming an interval. An organization citing the CPGs as its discovery standard is holding itself to a weaker line than the federal one, usually without realizing it. Set discovery to 7 days and enumeration to 14, and treat a missed cycle as an incident rather than a backlog item.

Route Every Finding to a Named Owner

Ownership attribution is where attack surface management programs stall, because a discovered asset with no assigned owner produces a ticket that nobody is able to close. Security identifies an unauthenticated staging API, infrastructure disowns it, and DevOps attributes it to a contractor while the exposure stays open. Assets deployed by acquired business units and overseas subsidiaries sit outside standard remediation channels with no engineer assigned. An exposed legacy interface cannot simply be patched, and decommissioning it needs executive sign-off, a functional replacement, or compensating segmentation.

Where ASM Sits Against Vulnerability Management

Attack surface management answers what infrastructure exists and where it is exposed, while vulnerability management determines which software flaws and misconfigurations sit on assets already known. Within Gartner's Continuous Threat Exposure Management framework, attack surface management operationalizes the Discovery stage and feeds Prioritization, Validation, and Mobilization.

An asset you have not discovered cannot be checked against CISA's Known Exploited Vulnerabilities Catalog, cannot be patched, and cannot be assigned. Discovery is one stage of five, and every other stage inherits its blind spots. Automate external discovery on a 7-day cycle, assign every finding to a person, and give the assignment a deadline.


Sources

Cybersecurity and Infrastructure Security Agency, Binding Operational Directive 23-01: Improving Asset Visibility and Vulnerability Detection on Federal Networks
https://www.cisa.gov/news-events/directives/bod-23-01-improving-asset-visibility-and-vulnerability-detection-federal-networks

Cybersecurity and Infrastructure Security Agency, BOD 23-01: Implementation Guidance for Improving Asset Visibility and Vulnerability Detection on Federal Networks
https://www.cisa.gov/news-events/directives/bod-23-01-implementation-guidance-improving-asset-visibility-and-vulnerability-detection-federal

Cybersecurity and Infrastructure Security Agency, Cybersecurity Performance Goals 2.0 (CPG 2.0)
https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0

Cybersecurity and Infrastructure Security Agency, Cross-Sector Cybersecurity Performance Goals, Version 2.0
https://www.cisa.gov/sites/default/files/2025-12/CPG_Report_2.0_508c.pdf

MITRE ATT&CK, Reconnaissance, Tactic TA0043
https://attack.mitre.org/tactics/TA0043/

Cybersecurity and Infrastructure Security Agency, Known Exploited Vulnerabilities Catalog
https://www.cisa.gov/known-exploited-vulnerabilities-catalog


Disclaimer

The information in this article is provided for educational and informational purposes only and does not constitute legal, operational, or cybersecurity consulting advice. CISA Binding Operational Directive 23-01 applies as a mandatory requirement to Federal Civilian Executive Branch agencies; the Cross-Sector Cybersecurity Performance Goals are voluntary. Private organizations should assess adoption of either against their own risk profile, contractual obligations, and sector regulations.


What Attack Surface Management Finds
Frequently Asked

Attack Surface Management

Attack surface management is the continuous discovery, cataloging, and analysis of every asset an organization operates that is reachable from outside its network boundary, including assets that no internal record claims. It establishes what the inventory should have contained, which is a different job from scanning a known inventory for flaws.

EASM evaluates infrastructure from the outside in using passive scanning and DNS enumeration to find internet-facing assets without credentials, while CAASM evaluates from the inside out using API integrations to consolidate fragmented inventories. EASM shows what an attacker can reach, and CAASM shows what the organization owns.

Automated asset discovery should run every 7 days and vulnerability enumeration every 14 days, the intervals CISA Binding Operational Directive 23-01 requires of Federal Civilian Executive Branch agencies. The directive binds federal agencies only, and private enterprises adopt the cadence because no stronger public benchmark exists.

CISA BOD 23-01 is mandatory only for Federal Civilian Executive Branch agencies and carries no legal force for private organizations. Private enterprises use it as an operational benchmark, and the voluntary Cross-Sector Cybersecurity Performance Goals 2.0 that apply to them set a looser inventory standard with no named interval.

Attack surface management answers what infrastructure exists and where it is exposed, while vulnerability management determines which flaws sit on assets already known. In Gartner's Continuous Threat Exposure Management framework, attack surface management operationalizes the Discovery stage and feeds the stages that follow.

Next
Next

SC Malaysia Guidelines on Technology Risk Management