Definition · External attack surface
What is the external attack surface?
Every organisation has one, larger than it thinks, and it moves without any decision. What it is made of, why it drifts, what EASM does and does not do, how to reduce it. Every organisation has one, larger than it thinks, and it moves without any explicit decision. Here is what it is made of, why it drifts, what EASM does and does not do, and how to reduce it without dedicating a team to it.
- Guide
- Definition
- Reading
- 6 min read
- Published
- Last updated
In one sentence
The external attack surface is everything an organisation exposes on the internet that an attacker can reach without any account: hosts, ports, services, certificates, applications, subdomains and the assets of subsidiaries or contractors, including those the internal inventory ignores; managing it (EASM) means discovering, monitoring and reducing it continuously.
An attacker does not start with your firewall. They start with a list: everything that answers under your domains and addresses, with the advertised versions, the certificates, the login pages, the forgotten test environments. That list is your external attack surface, and ANSSI notes, in its Panorama de la cybermenace 2025, that inadequately maintained internet-facing equipment is, with legitimate access, the primary target of attackers.
Managing it needs neither an agent nor access to your systems: one observes from the internet, as anyone could, and compares one observation with the next.
What it is made of
Domains and subdomains, IP addresses and ranges, services answering on ports (web, email, remote access, databases), certificates and their dates, applications and their versions, cloud spaces and public repositories. And what belongs to others but carries your name: subsidiaries, contractors, agencies, the hosts of a past campaign.
The most dangerous part is the one nobody lists: the staging environment left open, the maintenance access left by an integrator, the acquired subsidiary whose inventory stops at the transaction document.
Why it drifts
An acquisition adds domains, a project opens a port, a contractor publishes a database, a certificate expires, a vulnerable version stays online because nobody owns it. The surface changes through legitimate routes, without a security decision, and the internal inventory follows weeks behind.
That is why the useful unit of measure is drift: what appears, changes or disappears from one observation to the next. A newly reachable service matters more than a frozen inventory of two hundred hosts.
What EASM does and does not do
EASM discovers and follows that surface from the outside: it enumerates what answers, dates every appearance and every change, ties known vulnerabilities to the advertised versions and ranks by severity and exposure. It exploits nothing and tests nothing: it is neither a penetration test nor an internal scanner.
Nor does it replace vulnerability management inside the systems; it gives it the list of what is genuinely reachable, hence what to fix first.
How to reduce it
Inventory from the outside, assign every asset to an owner, close what has no reason to be open, fix or isolate what must stay exposed, then watch the drift so the inventory never ages again. Prioritise by exposure and severity: a remote access without a second factor ranks above an up-to-date web server.
Declaring the perimeter and proving its ownership remains the first step: nobody should be able to have addresses monitored that are not theirs.
The link with credentials and exposure chains
A reachable service becomes critical when usable credentials circulate for it: that is the exposure chain with an “exposed service” origin, whose impact is direct access, VPN or mailbox, and whose playbook is hardening. Watching the surface without watching the leaks, or the reverse, leaves that combination invisible.
Frequently asked questions
EASM and a vulnerability scanner, what is the difference?
The scanner starts from what you give it and lists versions; EASM starts from your domains and addresses, discovers what answers, including what you did not give it, and tests nothing. One says what is vulnerable, the other what is reachable; you need both.
Do we have to declare all our IP addresses?
Declare your domains and your ranges; discovery brings up the subdomains and the hosts that answer. Ownership is verified before any observation, through a DNS record for a domain. A range held by a hosting provider on your behalf is declared with its justification.
How often should the surface be observed?
Regularly, at a frequency set at scoping according to the size of the perimeter; the drift between two observations is what matters, and an alert goes out at every new critical exposure. Certificate transparency logs, for their part, are followed continuously.
What does your surface answer from the internet?
A one-hour scoping call with an analyst says what already answers under your domains and ranges, with no intrusive test, and what is worth monitoring.
Bespoke offering: no public price, no packages.