Once an organisation accepts that it needs to watch its external attack surface, the next question is which product to use, and the market is crowded and loud. The National Cyber Security Centre has published a buyer’s guide precisely because the choice is hard to make well. What follows is a practical distillation: the things worth checking before you commit, grounded in that guidance and in what actually separates a useful tool from a noisy one.
Start with Your Objective, Not the Feature List
Before comparing products, be honest about what you are trying to achieve. An organisation that mainly needs an accurate inventory of what it exposes wants something different from one that already has good asset management and wants deep risk analysis. The NCSC’s first piece of advice is effectively to know your own objective, because every other decision follows from it. A tool that is excellent for a use case you do not have is the wrong tool.
What to Check
How it discovers. The quality of the whole product rests on discovery. Ask how it finds assets, how wide it casts, and how it handles confirming ownership. A tool that misses half your estate is worse than useless, because it gives false confidence.
How fresh the data is. Continuous is a spectrum. Find out how often the surface is re-checked. Daily is a reasonable baseline; anything measured in weeks struggles against a surface that changes daily.
How it prioritises. Detection is easy; ranking is hard. A good product tells you which handful of findings matter today and stays quiet about the rest. Ask to see how it scores risk, and whether you can tune that to your context.
What it covers beyond CVEs. Check that it looks at the issues that are not catalogued vulnerabilities: email security records like SPF, DKIM and DMARC, TLS certificate health, exposed services, DNS takeover risks, cloud misconfigurations. This breadth is where EASM earns its place.
Whether you need active assessment. Decide whether you want the add-on that actively tests for vulnerabilities rather than inferring them, and understand that it changes the risk and permission picture. Many organisations start passive and add this later.
How it fits your workflow. Findings that do not reach the people who fix them change nothing. Look at how it exports data, whether it integrates with your ticketing and SIEM, and whether multiple teams can be given appropriately scoped access.
Two Things the Guide Is Careful About
The NCSC is at pains to reassure on one point and to caution on another. The reassurance: adopting EASM does not increase your risk, because the internet-wide scanning it mirrors is happening to you anyway. The caution: the active vulnerability-assessment features, where offered, can interact with your systems in ways that need coordinating with your security team first. Passive discovery and monitoring are safe to run; active testing is a deliberate choice.
The Test That Cuts Through
If you can, run a trial against your own organisation and judge the output by two questions. Did it find assets you genuinely did not know about? And of the findings it ranked highest, were they the ones you would have picked yourself? A tool that surprises you with real assets and agrees with your judgement on what matters is doing its job. One that produces a long, flat list of everything, ranked by nothing, will end up ignored no matter how much it detects.
The Short Version
Choose an EASM product by starting from your own objective, then checking how it discovers assets, how fresh its data is, how well it prioritises, what it covers beyond catalogued vulnerabilities, whether you need active assessment, and how it fits your workflow. Remember that passive monitoring is safe to run but active testing needs coordination. And trial it against yourself: the right tool finds assets you did not know you had and agrees with you on what matters most.
