Attack surface management: what is visible outside your perimeter

Attack surface management (ASM) is the continuous discovery, classification and assessment of every internet-facing asset an organisation exposes. The goal is to find exposed systems, forgotten subdomains, vulnerable services and leaked credentials before attackers exploit them. ASM complements vulnerability management (known assets, deep scanning) with the outside-in view: what attackers learn about you when they start from a blank page.

All

How this compares to neighbouring topics

ASM reduces what attackers can see in the first place. Threat hunting looks for attackers that got in anyway. Penetration testing probes selected systems deeply and at a point in time. Red team assessments simulate a realistic attack path. These disciplines require ASM as a prerequisite and remain necessary. Without a clear outside-in view, the pentest targets the wrong perimeter.

ASM vs vulnerability management

DimensionVulnerability management (classic)Attack surface management
Starting pointKnown asset inventory (CMDB, IP ranges).Publicly visible outside-in view, no assumptions.
DepthAuthenticated, deep, many details per asset.Unauthenticated, broad, attacker perspective.
Blind spotsEverything not in inventory (shadow IT, forgotten domains).Internal systems with no internet exposure.
OutputCVSS list, patchable.Exposed services, misconfigurations, leaked credentials, shadow domains.
ComplementNeeds ASM to become complete.Needs VM for depth per confirmed asset.

What ASM typically finds in Swiss environments

  • Forgotten subdomains from old campaigns or sub-brands pointing to inactive cloud buckets (subdomain takeover risk).
  • Legacy remote access: RDP, SMB, exposed legacy VPN concentrators, often without MFA.
  • Misconfigured S3, Azure Blob or GCS buckets with readable objects.
  • Exposed admin interfaces (Jenkins, GitLab, Prometheus, Grafana, database web shells).
  • Unmaintained public test environments left over from projects or acquisitions.
  • Leaked credentials in paste sites, code repositories or combo lists with Swiss domains.
  • OT or ICS assets with unintended internet exposure in manufacturing environments.
  • TLS certificates with mismatched common names revealing undocumented systems.
What this means for the SOC

Every previously unknown but confirmed asset either belongs in log ingestion or must be decommissioned. ASM must feed findings into detection coverage to improve security beyond producing reports. If an undetected exposed system is compromised, that can trigger an ISG notification duty. See [SOC and ISG reporting](/en/soc/soc-isg-24h-reporting).

Prioritisation: not everything red matters

A raw ASM result can produce thousands of findings. The craft is prioritising by real exploitability. Three axes matter:

  1. Exposure: is the service reachable from the internet, or is there a firewall in between that only happened to be closed during the scan?
  2. Exploitability: is there a known exploit, is the vulnerability actively used in the wild (CISA KEV, EPSS score)?
  3. Business value: does the asset serve a crown-jewel process, or is it an isolated marketing landing page?

ASM as a process, not a project

  • Run discovery continuously, at least weekly, because annual scans are insufficient. Attack surfaces change with every deployment.
  • Trigger-based rescanning on M&A, domain changes, new sub-brands or cloud migrations.
  • Link into change and CMDB processes: every confirmed asset is either recorded or decommissioned.
  • Handover to the SOC: new assets go into log coverage, leaked credentials into detection and reset workflows.

ASM and Swiss regulation

ASM directly addresses several control expectations. ISO 27001 and SOC requires A.8.8 (technical vulnerability management) and A.5.9 (inventory of information and assets). DORA requirements for the SOC requires continuous risk monitoring of ICT assets. NIS2 Swiss subsidiaries mandates vulnerability and exposure management. For manufacturing, the Cyber Resilience Act also becomes relevant, since exposed OT interfaces turn into regulatory risk.

Frequently asked questions

Is ASM the same as an external vulnerability scan?

An external VA scan checks known IPs and hosts for known vulnerabilities. ASM starts without an asset list and first finds what exists at all (discovery) before assessing it. The biggest findings are usually forgotten systems that never appear in the VA scope.

Does ASM replace a pentest?

No, it makes the pentest more targeted. ASM delivers the full outside-in view; the pentest goes deep on selected targets. Without ASM, a pentest often covers only what is in the CMDB and misses the most relevant shadow assets. See [Penetration testing Switzerland](/en/services/penetration-testing-switzerland).

How often should ASM run?

Run discovery at least weekly, with additional scans triggered by M&A, new domains, cloud migrations and major releases. Quarterly snapshot reports are a governance complement, not a substitute for continuous monitoring.

Who should run ASM, internal IT or the SOC provider?

Discovery can run in either model. Value only appears when findings flow into detection coverage, change processes and incident response. A managed-SOC model with ASM integration closes that feedback by design. For evaluation, see [SOC provider comparison](/en/soc/soc-provider-comparison-checklist).

How does ASM identify leaked credentials?

ASM monitors paste sites, code repositories, combo lists and dark-web marketplaces for patterns linked to Swiss domains and company aliases. Confirmed hits trigger a password reset, a session invalidation and a targeted threat hunt. See also [Token theft and session hijacking](/en/soc/token-theft-session-hijacking).

Continue reading in this cluster
Threat hunting in Switzerland: when detection rules stop being enough
Threat hunting is the hypothesis-driven search for adversaries that slip past existing detection rules. It complements SIEM and EDR alerts, it does not replace them. The goal is to structurally reduce how long adversaries stay undetected; Mandiant M-Trends 2026 reports a median of 14 days. Analysts actively search for tactics, techniques and procedures (TTPs) before an alert fires.
Penetration testing Switzerland: find attack surfaces before attackers do
A penetration test is a targeted attack simulation against defined systems, carried out by Swiss testers using a documented methodology. The test produces an auditable report with prioritised findings and recommendations that fit your environment. The report provides evidence for regulators and insurers. ANOMAL tests web, cloud, Active Directory, APIs and internal networks.
Red team assessment: detection and response under realistic load
A red team assessment is a goal-based, multi-week attack simulation against the entire detection and response chain, not against a narrow scope. The output is not a vulnerability list but an evidence-backed statement about what SOC, EDR, identity and cloud controls stop together. ANOMAL runs red team engagements using MITRE ATT&CK with a methodology based on TIBER-EU. For systemically important institutions, FINMA considers red-teaming exercises a required part of cyber exercises (supervisory notice 03/2024) and names frameworks such as TIBER-EU and CBEST.
Comparing SOC providers: the neutral selection checklist
Comparing SOC providers works via verifiable criteria, not logos: data scope, response authority inside the customer tenant, evidence artefacts, response times and contract wording. This page lists the questions used to line offers up side by side. Deliberately without vendor names, so the checklist holds up even when ANOMAL is not on the shortlist.
SOC as a Service in Switzerland: The Complete Guide
SOC as a Service is an externally operated Security Operations Center that monitors your environment around the clock, detects attacks and triggers the response. According to Mandiant M-Trends 2026, attackers went undetected for a median of 14 days in 2025. With a SOC that detects and assesses around the clock, typical detection time becomes much shorter.