Cymulate is a recognized platform in the category of Breach and Attack Simulation. Its proposal is to safely and controlledly execute attack scenarios against the security controls of the organization, to verify if firewalls, endpoint detection and response systems respond as expected. For teams that want to continuously validate the effectiveness of their controls and exercise defensive postures without relying solely on sporadic tests, it is a solid tool.
It's important to recognize what this category does well. Attack simulation answers a legitimate and relevant question: are the existing controls working? This is a valuable defensive validation exercise, and Cymulate is a reference in this space.
CSURFACE answers a different question. Before validating if the controls work, it's necessary to know what exists to be protected. CSURFACE discovers the external attack surface — including unmanaged assets, shadow IT, and the digital supply chain of suppliers —, assigns each asset to the organization, and prioritizes based on what is actually exploitable. It's not breach and attack simulation: it's discovery and prioritization of real exposure.