BLOG
Cybersecurity insights.
Technical analysis of exposure management, written by the people who work on attack surface every day.
See all tags (53)
Filtered by #ASM · 9 articles Clear filter
EASM: discovering and classifying what you expose online
EASM continuously discovers exposed assets from the root domain, assigns an owner, and classifies exposures, with no agents to install.
Supply chain attacks doubled in 2025: how to react
Supply chain attacks doubled in 2025, and one in five incidents involved third parties. Understand what changed and how to reduce your exposure.
Stop spinning your wheels: the Gartner matrix and ASM
The Gartner prioritization matrix classifies attack surface management as a quick win: high impact and low effort, with results in weeks.
The CISO's guide to proving security ROI with OpenFAIR
How to use the OpenFAIR framework to quantify cyber risk in financial terms and hold up the business case for a security investment.
Real cases an ASM would have prevented
How Attack Surface Management (ASM) shows your infrastructure through an attacker's eyes, and what you can fix before someone exploits it.
Polyfill.io: what it is and the supply chain attack
How a supply chain attack compromised millions of websites through Polyfill.io, and what decides the time between compromise and discovery.
Reducing the attack surface to prevent incidents
How attack surface management (ASM) helps you find and reduce what your company exposes before an attacker gets there first.
How ASM reduces digital supply chain risk
Indirect exposure through suppliers and old dependencies became one of the biggest cybersecurity risks, and ASM goes straight at that part.
What external attack surface management (ASM) is
Seeing every asset your company exposes on the internet, why that became part of cybersecurity maturity, and where to start.