RESOURCES

Whitepapers, datasheets & materials.

Cybersecurity studies, technical specifications and in-depth material — written for security teams, not for a marketing funnel.

report

The Exploit Clock · 2026 edition

How long between a CVE being published and the code that exploits it, measured across the 928 CVEs ThreatSensor monitors. Open base, methodo…

report

State of Digital Exposure · 2026 Edition

CSURFACE annual report with the aggregated, anonymized panorama of observed digital exposure — attack-surface, supplier-chain and credential…

datasheet

Compliance matrix: controls and regulations

Seven CSURFACE controls mapped to clauses in nine frameworks: NIST CSF, ISO 27001, CIS v8, PCI DSS 4.0, NIS2, BACEN, LGPD and SOX.

datasheet

Built-in EASM or dedicated ASM: a comparison

Ten core capabilities compared side by side between a dedicated ASM platform and the EASM module built into vulnerability suites.

datasheet

CSURFACE platform architecture

A two-page datasheet: architecture, deployment, security posture and the platform's four capabilities.

whitepaper

CTEM: from the Gartner framework to an operational program

Independent technical guide to Continuous Threat Exposure Management: the Gartner framework, the five phases (Scoping, Discovery, Prioritiza…

whitepaper

The exposure window between the scheduled scan and remediation

Exposure Window: the acceleration of exploitation (Mandiant M-Trends), seven recent public cases (Log4Shell, Spring4Shell, Citrix Bleed, F5,…

whitepaper

Leaked credentials: the interval between exposure and discovery

Credential Leakage Monitor: why continuous monitoring of leaked credentials outperforms point-in-time audits, and how to shorten the interva…

whitepaper

Vulnerability prioritization beyond CVSS

Threat Intelligence and dynamic prioritization: how to get the remediation queue right by combining technical severity, observed active expl…

whitepaper

Digital supplier-chain risk: exposure inherited from third parties

Digital Supply Chain Risk: from the Polyfill.io case to subdomain takeover. Public cases (MageCart at British Airways, Ticketmaster/Inbenta,…

whitepaper

The real attack surface and what the official inventory does not record

Context-aware discovery with Machine Learning: why subdomain enumeration reveals only a fraction of the real attack surface — and how to ide…