Attack surface management: what is visible outside your perimeter
Attack surface management (ASM) is the continuous discovery, classification and assessment of every internet-facing asset an organisation exposes. The goal is to find exposed systems, forgotten subdomains, vulnerable services and leaked credentials before attackers exploit them. ASM complements vulnerability management (known assets, deep scanning) with the outside-in view: what attackers learn about you when they start from a blank page.
How this compares to neighbouring topics
ASM reduces what attackers can see in the first place. Threat hunting looks for attackers that got in anyway. Penetration testing probes selected systems deeply and at a point in time. Red team assessments simulate a realistic attack path. These disciplines require ASM as a prerequisite and remain necessary. Without a clear outside-in view, the pentest targets the wrong perimeter.
ASM vs vulnerability management
| Dimension | Vulnerability management (classic) | Attack surface management |
|---|---|---|
| Starting point | Known asset inventory (CMDB, IP ranges). | Publicly visible outside-in view, no assumptions. |
| Depth | Authenticated, deep, many details per asset. | Unauthenticated, broad, attacker perspective. |
| Blind spots | Everything not in inventory (shadow IT, forgotten domains). | Internal systems with no internet exposure. |
| Output | CVSS list, patchable. | Exposed services, misconfigurations, leaked credentials, shadow domains. |
| Complement | Needs ASM to become complete. | Needs VM for depth per confirmed asset. |
What ASM typically finds in Swiss environments
- Forgotten subdomains from old campaigns or sub-brands pointing to inactive cloud buckets (subdomain takeover risk).
- Legacy remote access: RDP, SMB, exposed legacy VPN concentrators, often without MFA.
- Misconfigured S3, Azure Blob or GCS buckets with readable objects.
- Exposed admin interfaces (Jenkins, GitLab, Prometheus, Grafana, database web shells).
- Unmaintained public test environments left over from projects or acquisitions.
- Leaked credentials in paste sites, code repositories or combo lists with Swiss domains.
- OT or ICS assets with unintended internet exposure in manufacturing environments.
- TLS certificates with mismatched common names revealing undocumented systems.
Every previously unknown but confirmed asset either belongs in log ingestion or must be decommissioned. ASM must feed findings into detection coverage to improve security beyond producing reports. If an undetected exposed system is compromised, that can trigger an ISG notification duty. See [SOC and ISG reporting](/en/soc/soc-isg-24h-reporting).
Prioritisation: not everything red matters
A raw ASM result can produce thousands of findings. The craft is prioritising by real exploitability. Three axes matter:
- Exposure: is the service reachable from the internet, or is there a firewall in between that only happened to be closed during the scan?
- Exploitability: is there a known exploit, is the vulnerability actively used in the wild (CISA KEV, EPSS score)?
- Business value: does the asset serve a crown-jewel process, or is it an isolated marketing landing page?
ASM as a process, not a project
- Run discovery continuously, at least weekly, because annual scans are insufficient. Attack surfaces change with every deployment.
- Trigger-based rescanning on M&A, domain changes, new sub-brands or cloud migrations.
- Link into change and CMDB processes: every confirmed asset is either recorded or decommissioned.
- Handover to the SOC: new assets go into log coverage, leaked credentials into detection and reset workflows.
ASM and Swiss regulation
ASM directly addresses several control expectations. ISO 27001 and SOC requires A.8.8 (technical vulnerability management) and A.5.9 (inventory of information and assets). DORA requirements for the SOC requires continuous risk monitoring of ICT assets. NIS2 Swiss subsidiaries mandates vulnerability and exposure management. For manufacturing, the Cyber Resilience Act also becomes relevant, since exposed OT interfaces turn into regulatory risk.
Placement in SOC operations
SOC as a Service Switzerland describes how ASM fits into ongoing SOC operations. For coordination with pentesting, see Penetration testing Switzerland. For active searches for attackers, see Threat hunting in Switzerland.
Frequently asked questions
Is ASM the same as an external vulnerability scan?
An external VA scan checks known IPs and hosts for known vulnerabilities. ASM starts without an asset list and first finds what exists at all (discovery) before assessing it. The biggest findings are usually forgotten systems that never appear in the VA scope.
Does ASM replace a pentest?
No, it makes the pentest more targeted. ASM delivers the full outside-in view; the pentest goes deep on selected targets. Without ASM, a pentest often covers only what is in the CMDB and misses the most relevant shadow assets. See [Penetration testing Switzerland](/en/services/penetration-testing-switzerland).
How often should ASM run?
Run discovery at least weekly, with additional scans triggered by M&A, new domains, cloud migrations and major releases. Quarterly snapshot reports are a governance complement, not a substitute for continuous monitoring.
Who should run ASM, internal IT or the SOC provider?
Discovery can run in either model. Value only appears when findings flow into detection coverage, change processes and incident response. A managed-SOC model with ASM integration closes that feedback by design. For evaluation, see [SOC provider comparison](/en/soc/soc-provider-comparison-checklist).
How does ASM identify leaked credentials?
ASM monitors paste sites, code repositories, combo lists and dark-web marketplaces for patterns linked to Swiss domains and company aliases. Confirmed hits trigger a password reset, a session invalidation and a targeted threat hunt. See also [Token theft and session hijacking](/en/soc/token-theft-session-hijacking).
Related terms
- Vulnerability Management Vulnerability management is the ongoing process of finding weaknesses, assessing them by risk, and verifying their remediation.
- CVE CVE is the global directory of publicly known security vulnerabilities where each vulnerability receives its own identifier.
- Shadow IT Shadow IT refers to software, cloud services, and devices that employees use without the IT department's approval.
- CTI Cyber Threat Intelligence (CTI) provides processed information about attackers, their tools, and their objectives.