CyberzSOC

Publication detail
← Back to advisories & guidance

External attack surface management (EASM) buyer's guide ↗ source

September 18, 2025 NCSC Guidance

Summary

External attack surface management (EASM) is the process of identifying, monitoring, and reducing vulnerabilities within assets that are accessible from the internet. This guidance will help system owners to choose an EASM product that is appropriate for their organisation. Vendors may also find this guidance useful when designing and developing EASM Attackers constantly scan organisations' IT systems (the hardware, software, services and cloud assets), looking for weaknesses they can use to gain access, or to steal data. The sum of potential access points is known as the ‘attack surface’, and attack surface management (ASM) is the process of identifying, monitoring, and reducing vulnerabilities across the entirety of an organisation's digital and physical assets. External attack surface management (EASM) is a subset of ASM, and focuses on protecting online assets that are accessible from the internet.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

No CVEs are referenced in this publication.

Vendors Named in This Publication

No KEV-catalogued vendors are named in this publication.