
As someone who has been working in IT security for a long time and who regularly both attacks infrastructures and assists companies that have been attacked, there is one thing we encounter time and time again: the underestimation of one’s own attack surface. It is not uncommon for companies to lack a complete Overview of which exposed systems they actually operate and how these appear to attackers. This is precisely where Attack Surface Management (ASM) comes into play.
Viewing your own infrastructure through the eyes of an attacker
ASM forces organisations to view their systems from an attacker’s perspective. When you see yourself through an attacker’s eyes, you ask entirely different questions:
Public accessibility
Which domains, subdomains or Cloud services are publicly accessible, and should they be at all?
Shadow IT
Are there any forgotten servers, shadow IT or old test instances that nobody is aware of anymore?
Exposed services
Which services are listening on ports publicly, which APIs are inadequately protected, and which Cloud resources are misconfigured?
Companies are often aware of their own lack of knowledge, but this perspective is uncomfortable. Uncomfortable, but necessary: an attacker isn’t looking for the most elegant way in, but for the one that works. ASM is therefore not just ‘nice to have’.
What is Attack Surface Management?
ASM is a continuous process in which all of a company’s IT assets, whether known or hidden, are systematically identified, monitored and assessed. The aim is to make all potential points of entry or attack visible. This involves looking beyond just known and documented systems: Forgotten or sold equipment, Cloud instances, APIs, old domains, shadow IT or misconfigured SaaS services can all cause damage. Anything that is accessible from the public or semi-public network, or is connected in any way to the corporate network, can form part of the attack surface.
ASM deliberately sets itself apart from traditional vulnerability management, which often focuses on known assets and works through CVEs. ASM starts earlier: it aims first and foremost to make all assets visible, so that it is clear what needs to be protected in the first place.
An overview of tools and providers
The field of ASM is now well-established and professional. There are specialised platforms that automatically discover assets, monitor them continuously and prioritise risks based on what an attacker might do.
- Mandiant Attack Surface Management: Cloud-based; detects web assets, subdomains and cloud resources, and assesses risks.
- Tenable One: Helps to identify all assets and establish visibility across both internal and external resources.
- Rapid7 Attack Surface Management: Automates detection and monitoring and complements traditional vulnerability analysis.
- Microsoft Defender External Attack Surface Management: Particularly suitable for cloud-based and internet-exposed services, including the detection of shadow IT.
Important considerations when choosing: A good ASM solution should offer comprehensive asset discovery, continuous monitoring, risk prioritisation and, where possible, automation. Cloud infrastructures, SaaS services, hybrid working and third-party integrations mean that an organisation’s digital attack surface is constantly growing and evolving. What seemed secure yesterday may have been forgotten or misconfigured today. Organisations with changing infrastructures, Cloud environments or external services stand to benefit enormously, as ASM helps to eliminate ‘blind spots’ and provide a true picture of the entire attack surface.
Recommendations for security teams
Take your digital footprint seriously
Start with an ASM solution that offers automated asset discovery, even if you think you have an overview of everything. We find assets that nobody had on their radar with surprising frequency.
Establish continuous Monitoring
ASM should run continuously so that new assets or changes are detected immediately.
Prioritise risks
Not every problem is equally critical. The aim is to identify realistic entry points and address those posing the greatest risk first.
Integrating ASM, Vulnerability Management and Pentesting
ASM identifies what exists. Traditional Pentests and vulnerability analyses show where and how you could be attacked. Together, they provide a robust defence strategy.
Mint Secure GmbH
How Mint Secure supports you
We help organisations visualise their actual attack surface and secure it in a targeted manner.
Attack Surface Assessment
We identify publicly accessible assets, shadow IT and forgotten systems from an attacker’s perspective.
penetration test
We carry out targeted testing of the identified entry points to determine whether they can be exploited in practice.
consulting
We assist with the selection and integration of ASM solutions into your security processes.
Conclusion
Attack Surface Management forces organisations to view their own infrastructure from the uncomfortable but necessary perspective of an attacker.
If you do not continuously map your digital attack surface, you leave attackers with precisely those blind spots that are sufficient for a successful attack.
Mint Secure helps you understand your attack surface and protect it effectively. Talk to us.

