Skip to main content
14 speakers. 7 enterprise risk teams. One day in Charlotte, Oct. 22.Save My Seat
BlackKite: Home
Menu
Back to Glossary

Attack Surface Management (ASM)

Attack Surface Management is the continuous discovery, classification, and monitoring of an organization's attack surface, covering internal systems as well as external-facing assets. In third-party cyber risk management, it is applied to vendors, identifying exposures in their external-facing infrastructure without requiring access to their internal systems. Black Kite performs outside-in Attack Surface Management across vendor portfolios on a continuous basis.

ASM exists because most organizations don’t actually know the full scope of what they’re exposing to the internet. A CMDB or asset inventory reflects what IT was told to track, not what actually got deployed. Development teams spin up infrastructure outside centralized control, acquisitions bring in systems nobody has reviewed, and legacy services linger years past their intended retirement. ASM is the practice of finding all of it, continuously, rather than trusting a spreadsheet that’s already out of date.

What Does Attack Surface Management Cover?

Attack Surface Management covers two halves of the same problem: the assets an organization can see from inside its own network, and the ones only visible from outside it.

  • Internal ASM: agent-based scanning and credentialed access, integrated with tools an organization already runs, like endpoint detection and vulnerability scanners.
  • External ASM: passive, outside-in discovery of internet-facing assets, requiring no credentials or cooperation from the asset’s owner.

Most vendors selling ASM tools actually sell one half or the other, not both, and the marketing rarely makes that as clear as the buyer needs it to be. A tool built around agents and internal integrations will never see a vendor’s environment, no matter how good it is at its own job. A tool built entirely on outside-in discovery will never see what’s happening behind an organization’s own firewall. Knowing which half a given ASM product actually covers is the first question worth asking before buying one.

How Is ASM Different From EASM?

External Attack Surface Management (EASM) is the external half of ASM, isolated and treated as its own discipline because it’s the only half that works without any cooperation from the organization being assessed.

That distinction matters enormously in a vendor context, since a vendor is never going to install an agent or hand over credentials to a company assessing it from the outside. 

Why Do Vendor Relationships Only Ever See the External Half?

A vendor relationship never grants agent access or credentials, so the internal half of ASM is structurally unavailable no matter how mature the relationship is.

That’s not a limitation specific to any one vendor’s cooperation level. It’s a structural fact of the relationship itself. An organization can be a model partner, respond to every questionnaire, and share every document it has, and the buying organization still won’t have internal network access. External ASM exists precisely because it doesn’t need that access to produce a usable picture, which is also why it’s the half that scales to an entire vendor inventory rather than one relationship at a time.

What Does an ASM Program Actually Do, Step by Step?

A mature ASM program runs three steps continuously: discovery, classification and prioritization, and ongoing monitoring.

Discovery Starts From a Single Domain

Discovery starts from a minimal seed, usually a single domain, and expands outward through DNS records, WHOIS data, and internet-wide scans to find every asset connected to it, including ones nobody remembers deploying. Black Kite Monitor runs this exact process continuously across a monitored portfolio, building each vendor’s digital footprint from nothing more than a top-level domain. The output is only as good as how far the discovery step is willing to look past the assets already on record.

Classification and Prioritization

Not every discovered asset carries equal risk. Black Kite’s 2026 Wholesale & Retail Cyber Exposure Report found that 54.96% of supply chain vendors in a mapped ecosystem were exposed to at least one CVSS 8-or-higher vulnerability, the kind of finding that determines whether a specific asset gets escalated immediately or logged for the next review cycle. Without this step, discovery just produces a longer list, not a more useful one.

Continuous Monitoring

An attack surface discovered once and never rechecked is already stale by the time the report is read. Continuous monitoring is what keeps the classification current as assets are added, removed, patched, or reconfigured, and it’s the step most point-in-time tools skip entirely.

Which Industries Feel ASM Gaps Most Acutely?

ASM gaps show up fastest in industries where the pace of new digital deployment outstrips the pace of formal IT governance, which in practice means retail, wholesale, and manufacturing more than most.

A manufacturing company connecting more operational technology to the internet every quarter is expanding its attack surface into territory its security team may never have owned before, often faster than governance processes built for corporate IT can absorb. Retail and wholesale organizations see the same dynamic through a different door: new point-of-sale integrations, seasonal microsites, and vendor-managed checkout tools that get added quickly and rarely get formally offboarded.

How Is External-Only ASM Applied to a Vendor Portfolio?

Running external ASM against one vendor is a scan. Running it against a portfolio of hundreds, on a schedule none of them agreed to, is the actual product problem.

Black Kite Monitor performs functionally the same discipline against every vendor in a monitored portfolio: continuous, outside-in discovery and tracking of each vendor’s externally visible footprint, with no credentials and no cooperation required. That’s a large part of what lets vendor risk monitoring run on a continuous basis instead of waiting for the next scheduled review, and a meaningful reason Black Kite positions itself as a leader in third-party risk intelligence rather than a general-purpose scanning tool.

What Are the Limits of ASM?

ASM tells an organization what’s exposed. It doesn’t tell them what’s actually exploitable, who’s currently trying to exploit it, or what it would cost if they succeeded.

A complete asset inventory with no vulnerability context is a map with no legend. An organization can know exactly how many subdomains a vendor runs and still have no idea whether any of them are actually dangerous. Pairing ASM’s discovery layer with a vulnerability assessment and current risk intelligence is what turns a list of exposed assets into a prioritized list of what to actually fix first, and in what order.

See also: 

Attack Surface 

External Attack Surface Management