ScanReview
Definition, scope, and first steps for EASM — written for founders and small teams.
Attack surface management (ASM) is the practice of continuously discovering, inventorying, and monitoring the systems an attacker could reach — especially those exposed to the internet — and detecting when that footprint changes. In small-business practice, people usually mean external attack surface management (EASM): outside-in visibility of domains, IPs, subdomains, ports, and services, plus alerts when something new appears.
Cloud accounts, SaaS apps, marketing sites, staging hosts, and vendor portals expand quietly. Many incidents start with something internet-facing that the team forgot about: an open admin port, an old subdomain, a test server left online. ASM/EASM is how you notice that drift without hiring a security team first.
What the public internet can see. Domains, certificates, open ports, public cloud assets, exposed services. This is the usual SMB starting point.
May include internal assets, identities, heavier prioritization workflows, and enterprise process. Useful later — often overkill as a first buy for a five-person team.
Think of EASM as continuous headlights on your exterior — necessary visibility, not the entire vehicle.
Solo founders, SaaS teams, and small businesses with any public website, API, or cloud workload. If you accept payments through Stripe/PayPal and do not store cards yourself, you may not need enterprise GRC software — you still benefit from knowing what is exposed and when it changes.
Independent paths after the definition — no enterprise theater required.