About

EASM News is a site about one discipline: External Attack Surface Management. It covers the news, the techniques and the practical detail of understanding what your organisation exposes to the internet, watching it change, and closing the gaps before someone else maps them. It is written for the people who have to do that work, and for the people who have to decide whether to buy a tool to help.

The premise is simple. Most organisations cannot confidently answer the question an attacker answers first: what of ours is reachable from the internet, and what is wrong with it? EASM is the practice of answering that question continuously, from the outside, the way an attacker would. This site exists to explain how it works and to report on how it is changing.

What EASM Is, in One Paragraph

The National Cyber Security Centre defines External Attack Surface Management as the process of identifying, monitoring and reducing vulnerabilities in the assets that are reachable from the internet. In practice that means five things: discovering the domains, subdomains and addresses you own; working out what each asset is; flagging what looks wrong; repeating all of it on a schedule because the surface changes daily; and reporting the result so someone can act. It maps and assesses. It does not break in, and it does not make you more of a target, because the internet is already scanning you regardless.

The five EASM operations: discovery, information gathering, risk identification, monitoring and reporting.
The five operations of EASM, run continuously.

Why It Deserves Its Own Site

The external attack surface is the part of security that grows on its own. Every campaign site, test server, acquired company and third-party integration adds to it, usually without anyone updating a register. The assets nobody remembers are the ones left unpatched and unwatched, and they are exactly the ones an attacker finds first. A discipline built to see them continuously is worth understanding well.

It is also a field full of noise. Products promise to find every vulnerability with a scan, vendors blur the line between mapping and testing, and the genuinely useful ideas get lost in the marketing. Part of the job here is to separate what EASM really does from what it is sold as, plainly enough that a reader can act on the difference.

A timeline contrasting an annual assessment, with a gap where exposure sits unnoticed, against continuous monitoring.
A yearly scan leaves a gap; continuous monitoring catches change the day it appears.

What You Will Find Here

Explainers. How EASM works and where it fits, in plain language, with diagrams you can put in front of people who are not specialists.

Discovery and inventory. How assets are found, why shadow IT and the forgotten estate matter, and how to turn a discovery scan into an inventory you can trust.

Exposures. The issues EASM surfaces that are not catalogued vulnerabilities: subdomain takeover, weak email security, exposed services, certificate and DNS problems.

Monitoring. Why continuous beats point-in-time, and how to keep the signal from drowning in noise.

Tooling and guidance. The products and open-source tools that do this work, and how to choose between them against standards like the NCSC’s buyer guidance.

How This Site Works

A few principles shape what is published here. The site is independent and has nothing to sell; where it discusses tools, it describes what works and why, and leaves the choice to the reader. It favours the practical over the theoretical, so the test of any article is whether a working practitioner can do something with it. And claims are checked against primary sources rather than repeated from press releases. The writing is deliberately unattributed, because the subject matters more than the byline.