Seeing what attackers see

Christo Coetzer, Director & CEO BlueVision, sets out the key steps to deploying cyber attack surface management (ASM) to defend your business.

In an age of sprawling hybrid infrastructures and accelerating digital transformation, Attack Surface Management (ASM) has become essential to maintaining a strong cyber defence posture. Effective ASM isn’t just about asset discovery — it’s about seeing the enterprise the way an adversary does. By continuously mapping external and internal exposures, correlating vulnerabilities with live threat intelligence, and prioritising risks based on business impact, security teams can transform visibility into proactive control and ensure resilience against modern attack vectors.

Know your environment

Knowing your environment in the context of ASM is about achieving visibility into all assets that could be exposed to potential attackers. This includes everything from servers, applications and cloud services to forgotten subdomains, misconfigured APIs or even employee credentials leaked on the dark web. It’s not just about cataloguing what’s out there; it’s about understanding how an adversary might see and exploit these assets.

From my perspective, knowing your environment means maintaining a dynamic inventory of your internet-facing infrastructure and services, enriched with context about their purpose, configuration and vulnerabilities. This involves leveraging reconnaissance techniques (similar to those used by attackers) combined with threat intelligence to identify risks, such as unpatched systems or exposed databases. Without this clarity, organisations are essentially navigating a minefield blindfolded, unable to prioritise or mitigate risks effectively.

Next – deployment of ASM

Deploying ASM effectively requires a structured yet adaptable approach. Based on my experience, the following steps are critical to building a robust ASM program:

  • Start by identifying all external facing assets, including domains, subdomains, IP ranges, cloud services and third-party integrations. Automated tools can help, but manual validation is often necessary to uncover shadow IT or forgotten assets.
  • Once assets are mapped, assess them for vulnerabilities and misconfigurations. This isn’t just about running a scanner, it’s about prioritising findings based on exploitability and business impact.
  • Incorporate threat intelligence, such as OSINT, to identify exposed credentials, leaked data or emerging threats targeting similar organisations. This adds context to your findings and helps focus remediation efforts.
  • The attack surface isn’t static. New assets, configurations or vulnerabilities can appear overnight. Continuous monitoring ensures you’re not caught off guard by changes in your environment.
  • Not all risks are equal. Use a risk-based approach to prioritise fixes, focusing on high-impact vulnerabilities or assets critical to business operations.
  • ASM isn’t just a technical exercise, it requires alignment between security teams, IT and business units to ensure remediation is practical and sustainable.

Regular iteration of these steps ensures your ASM programme evolves with your organisation’s infrastructure and the broader threat landscape.

Can ASM tools keep pace with the speed and sprawl of modern infrastructure?

The short answer is yes, they can but only if chosen and implemented thoughtfully. Modern infrastructure, spanning hybrid clouds, containerised environments and sprawling SaaS ecosystems, moves at a breakneck pace. ASM tools must be agile enough to keep up with this sprawl while providing actionable insights.

From my observations, the best ASM tools combine automation with intelligence. Automation is crucial for discovering assets and vulnerabilities at scale, particularly in dynamic environments where new instances are constantly being created. However, automation alone can generate noise, including false positives or low-priority alerts, that can overwhelm teams. The most effective tools integrate contextual analysis, such as correlating vulnerabilities with active exploits in the wild or prioritising assets based on their business criticality. That said, no tool is a silver bullet. Organisations must complement ASM tools with skilled analysts who can interpret findings, validate results and adapt to new attack vectors. The rapid adoption of cloud-native technologies and ephemeral infrastructure, such as serverless functions, pushes ASM tools to their limits; however, those built with flexibility and real-time capabilities are proving they can keep pace, if paired with a proactive security culture.

What’s the difference between internal and external ASM?

Although both are interconnected they are at the same time distinctively different. External ASM focuses on assets exposed to the public internet, such as web servers, APIs or cloud storage buckets, accessible from outside your network. It’s about seeing your organisation through an attacker’s eyes, identifying entry points they could exploit during reconnaissance or initial compromise. External ASM often leverages offensive security techniques, like scanning for open ports or misconfigured services, and integrates OSINT to uncover risks like exposed credentials or leaked data.

Internal ASM, on the other hand, deals with assets and vulnerabilities within your network perimeter. This includes internal servers, employee devices, or misconfigured databases that may not be internet-facing but could be exploited by an attacker who has gained a foothold, such as through phishing or a compromised endpoint. Internal ASM requires deep integration with endpoint detection, network monitoring and identity management to map and secure the internal attack surface.

In my view, the key difference lies in scope and perspective. External ASM is about preventing initial access; internal ASM is about limiting lateral movement and damage after a breach. Both are essential, as a single weak link, whether a public-facing misconfiguration or an internal unpatched system, can compromise the entire organisation. A mature ASM programme bridges these two, ensuring comprehensive visibility and defence across the entire attack surface.

Be prepared. Always

ASM is not just a technical process; it’s a mindset. It requires organisations to think like attackers, anticipate risks and act decisively to reduce exposure. By knowing your environment, deploying a structured ASM approach, leveraging capable tools and addressing both internal and external risks, organisations can stay one step ahead in today’s relentless threat landscape. From my vantage point, the key to success lies in combining technology with human expertise and a commitment to continuous improvement, because in cyber security, standing still is not an option.

Tags:
No Comments

Sorry, the comment form is closed at this time.

1