BLOG

Cybersecurity insights.

Technical analysis of exposure management, written by the people who work on attack surface every day.

See all tags (53)

Filtered by #ASM · 9 articles Clear filter

#EASM#ASM

EASM: discovering and classifying what you expose online

EASM continuously discovers exposed assets from the root domain, assigns an owner, and classifies exposures, with no agents to install.

#supply chain#supply chain attack

Supply chain attacks doubled in 2025: how to react

Supply chain attacks doubled in 2025, and one in five incidents involved third parties. Understand what changed and how to reduce your exposure.

#ASM#Attack Surface Management

Stop spinning your wheels: the Gartner matrix and ASM

The Gartner prioritization matrix classifies attack surface management as a quick win: high impact and low effort, with results in weeks.

#OpenFAIR#ROI

The CISO's guide to proving security ROI with OpenFAIR

How to use the OpenFAIR framework to quantify cyber risk in financial terms and hold up the business case for a security investment.

#ASM#Attack Surface Management

Real cases an ASM would have prevented

How Attack Surface Management (ASM) shows your infrastructure through an attacker's eyes, and what you can fix before someone exploits it.

#Supply Chain#Cybersecurity

Polyfill.io: what it is and the supply chain attack

How a supply chain attack compromised millions of websites through Polyfill.io, and what decides the time between compromise and discovery.

#ASM#Cybersecurity

Reducing the attack surface to prevent incidents

How attack surface management (ASM) helps you find and reduce what your company exposes before an attacker gets there first.

#Digital Supply Chain#ASM

How ASM reduces digital supply chain risk

Indirect exposure through suppliers and old dependencies became one of the biggest cybersecurity risks, and ASM goes straight at that part.

#Attack Surface Management#ASM

What external attack surface management (ASM) is

Seeing every asset your company exposes on the internet, why that became part of cybersecurity maturity, and where to start.