Skip to main content

EASM buyer's guide now available

How to choose an external attack surface management (EASM) tool that’s right for your organisation.

ArtemisDiana by Getty Images

Earlier this year we published an account of what we learned from the Active Cyber Defence 2.0 experiment in attack surface management (ASM).

One of the findings from that experiment highlighted an absence of independent advice on how organisations could select an effective external attack surface management (EASM) product. Today, the NCSC are publishing an External Attack Surface Management (EASM) buyer's guide to do just that.

EASM products identify and scan your internet-accessible assets to identify any misconfigurations, exposures, or vulnerabilities that could be exploited by an attacker to gain access to your data and services. EASM products contribute to maintaining the 'defender’s edge' by ensuring you have the same – or better – visibility of your online systems as potential attackers.
 

Using an EASM product is the real-world equivalent of having a security guard check outside your offices every day to make sure you’ve not left any windows or doors open. And if they find any that are, they quickly let you know so you can take appropriate action. Even if you think ‘Why would a criminal be interested in my organisation?’ you should still consider using EASM products; rather than target specific organisations, cyber criminals can indiscriminately probe millions of online assets with next to no effort.   

During our ACD 2.0 research, we found that many organisations do not have a complete record of their entire online digital estate. Using the above analogy, this is akin to having no idea how many doors and windows you have, where they are located, and how you lock them. EASM products use automated discovery techniques to quickly give you visibility of all your online assets, something many of our experiment participants found both eye-opening and valuable.

Our ACD 2.0 research (the full version is available from here) identified a strong and diverse market, offering EASM products with a range of features at a range of price points, suitable for many different organisations. If your organisation is responsible for maintaining internet-accessible services, especially where any disruption to those services would impact your business or customers, you should consider how an EASM product can improve your cyber security.

This new guidance will help you identify if using an EASM product is right for you and your organisation, and if so how to pick one. It outlines the features you can expect in EASM products, and provides you with a set of questions to consider to help tailor your requirements. There is no one-size-fits-all for EASM. This will help you prepare to discuss with EASM providers how their products will support your specific needs, and for you to make the best choice.

We specified when we announced ACD2.0 that it would run as a partnership, including with industry suppliers. Once again, we’d like to thank all the cyber security companies and customer organisations that helped us to shape this guidance.

Ricky L

Technical Director for ACD 2.0


Written by

Ricky L Technical Director for ACD 2.0

Published

Part of blog