RESOURCES
Whitepapers, datasheets & materials.
Cybersecurity studies, technical specifications and in-depth material — written for security teams, not for a marketing funnel.
report
The Exploit Clock · 2026 edition
How long between a CVE being published and the code that exploits it, measured across the 928 CVEs ThreatSensor monitors. Open base, methodo…
report
State of Digital Exposure · 2026 Edition
CSURFACE annual report with the aggregated, anonymized panorama of observed digital exposure — attack-surface, supplier-chain and credential…
datasheet
Compliance matrix: controls and regulations
Seven CSURFACE controls mapped to clauses in nine frameworks: NIST CSF, ISO 27001, CIS v8, PCI DSS 4.0, NIS2, BACEN, LGPD and SOX.
datasheet
Built-in EASM or dedicated ASM: a comparison
Ten core capabilities compared side by side between a dedicated ASM platform and the EASM module built into vulnerability suites.
datasheet
CSURFACE platform architecture
A two-page datasheet: architecture, deployment, security posture and the platform's four capabilities.
whitepaper
CTEM: from the Gartner framework to an operational program
Independent technical guide to Continuous Threat Exposure Management: the Gartner framework, the five phases (Scoping, Discovery, Prioritiza…
whitepaper
The exposure window between the scheduled scan and remediation
Exposure Window: the acceleration of exploitation (Mandiant M-Trends), seven recent public cases (Log4Shell, Spring4Shell, Citrix Bleed, F5,…
whitepaper
Leaked credentials: the interval between exposure and discovery
Credential Leakage Monitor: why continuous monitoring of leaked credentials outperforms point-in-time audits, and how to shorten the interva…
whitepaper
Vulnerability prioritization beyond CVSS
Threat Intelligence and dynamic prioritization: how to get the remediation queue right by combining technical severity, observed active expl…
whitepaper
Digital supplier-chain risk: exposure inherited from third parties
Digital Supply Chain Risk: from the Polyfill.io case to subdomain takeover. Public cases (MageCart at British Airways, Ticketmaster/Inbenta,…
whitepaper
The real attack surface and what the official inventory does not record
Context-aware discovery with Machine Learning: why subdomain enumeration reveals only a fraction of the real attack surface — and how to ide…