Continuous Security

Your perimeter changed this week.

An annual penetration test is a photograph. Your attack surface is a video — subdomains appear, certificates expire, a developer exposes a staging environment on a Friday afternoon and it stays exposed for eleven months.

New host exposed today MonWedFri Assets reachable from the internet
24/7Continuous discovery
13,532Active test templates
DailyIntelligence refresh
AlertOn change, not on schedule

The gap between tests is where you get breached

Consider the arithmetic. You test annually. The test takes a week. That leaves fifty-one weeks in which your perimeter changes and nobody checks. In that time your teams will register subdomains, spin up demonstration environments, deploy a new marketing site on a platform nobody told IT about, and let a certificate expire on something that turns out to be important.

Meanwhile the other side of the equation moves faster still. A vulnerability disclosed on Tuesday is being scanned for globally by Wednesday. The window between a critical flaw becoming public and it being exploited at scale is now measured in days, sometimes hours. Anything that depends on your next scheduled assessment to catch it is, functionally, not a control.

Attack surface management closes that gap. We continuously discover what belongs to you and what is reachable from the internet — including the assets that are not on any list you hold — and we watch for change. When something new appears, when something changes state, when a certificate is about to expire, or when a newly published vulnerability affects something you are running, you hear about it that day.

Coverage

What we monitor

Continuous, external, and non-intrusive by design — everything here is observation, not attack.

Asset discovery

Domains, subdomains, IP ranges and cloud assets attributed to your organisation, including the ones registered on a corporate card by a team in another country.

Shadow IT and forgotten infrastructure

Staging environments, demo instances, legacy hosts and services that outlived the project that created them.

Exposed services and interfaces

Administrative panels, remote access, databases and management interfaces that have become reachable from the internet.

New vulnerability exposure

Newly published vulnerabilities matched against what you are actually running, escalated immediately when the flaw is on the known-exploited list.

Certificate and domain hygiene

Expiry, weak configuration, mismatches and certificates issued for names you do not recognise.

Change detection

New hosts, new open ports, new technologies and altered configuration — reported as change, because change is the signal.

Subdomain takeover risk

Dangling DNS records pointing at deprovisioned cloud resources that somebody else can claim.

Credential and data exposure

Company credentials appearing in public breach data, and code repositories leaking keys and endpoints.

Approach

How it works

Set up once, then it runs. Findings arrive as alerts and as a live dashboard, not as a quarterly PDF.

  1. 01 · Attribute

    We establish what actually belongs to you — starting from your known domains and expanding outward through the relationships that connect assets to an organisation.

  2. 02 · Confirm

    You review the discovered inventory and confirm ownership. Anything ambiguous stays out until it is confirmed; we never test what is not yours.

  3. 03 · Baseline

    A full assessment of the confirmed surface establishes the starting position, so subsequent alerts are genuine change rather than noise.

  4. 04 · Monitor

    Continuous rediscovery and non-intrusive assessment, with vulnerability intelligence refreshed daily against everything found.

  5. 05 · Alert

    New exposure, new critical vulnerability or material change is raised the day it is detected, with context and a recommended action.

  6. 06 · Review

    A monthly review with a human, covering what changed, what was closed, and what needs a decision rather than a fix.

Run against recognised standards

  • CISA KEVKnown-exploited escalation
  • EPSSExploit probability scoring
  • ISO 27001 Annex AAsset management control evidence

Deliverables

What you actually receive.

The report is the product. If it cannot be acted on by a developer and understood by a director, we have not finished.

Live asset inventory

Everything internet-facing that belongs to you, kept current — usually 20–40% larger than the list clients start with.

Change alerts

Notification the day something appears, changes or becomes exposed, with the context needed to decide quickly.

Prioritised exposure queue

Ranked by exploit probability and known-exploited status, so the queue reflects real risk rather than raw severity.

Monthly review

A conversation with a person about what changed and what it means, not an automated email.

Trend reporting

Exposure over time — the chart that shows a board whether the programme is working.

Is this for you?

Talk to us if any of these are true.

If none of them are, say so on the call and we will tell you honestly whether this is the right piece of work — or point you at the one that is.

Book a scoping call
  • You cannot produce a confident list of everything your organisation has on the internet.
  • You have multiple business units, brands or countries registering their own assets.
  • You test annually and know that is not enough between tests.
  • You have acquired companies and inherited unknown infrastructure.
  • Your development teams can deploy publicly without going through IT.

How we work

Six steps, and no surprises.

The same engagement model applies to every piece of work we take on, so you always know what happens next.

01

Scope

A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.

02

Authorise

Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.

03

Test

Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.

04

Report

One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.

05

Remediate

A walkthrough call with your engineers. We answer questions on the fix, not just the finding.

06

Retest

A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.

Questions

Attack Surface Management — answered.

The questions clients actually ask during scoping. If yours is not here, ask it directly.

How is attack surface management different from a penetration test?

A penetration test is deep, point-in-time and intrusive: a person actively attacks a defined scope and proves what is exploitable. Attack surface management is broad, continuous and non-intrusive: it observes what exists and what changes, every day, without attacking anything. They answer different questions and work best together — ASM tells you what to test and when something has changed, and the penetration test tells you how bad it is.

Will monitoring affect our systems or trigger our own alerts?

Monitoring is designed to be non-intrusive — it observes what is publicly visible rather than attacking it, and the traffic volume is negligible. Some security tooling will log the activity, so we provide our source addresses during onboarding, and you can allowlist them or leave them unlisted if you would rather see how your monitoring reacts.

How do you know which assets belong to us?

We start from what you confirm — your domains and IP ranges — and expand outward through the public relationships that link assets to an organisation: certificate records, DNS relationships, registration data and cloud address attribution. Everything discovered is presented to you for confirmation before it enters scope. We never assess anything you have not confirmed as yours, both as a matter of law and because unattributed assets produce useless findings.

What happens when you find something critical?

You are alerted the same day, with the affected asset, what the exposure is, whether it is on the known-exploited list, and what to do about it. For clients on a managed service we can also verify the finding manually before escalation, which removes the false-positive problem that makes most automated alerting easy to ignore.

Is this included in the SemperWise One platform?

Yes. Attack Surface Management is a live module in the Protect group of SemperWise One™, so it can be run as a platform subscription you operate yourself, or as a managed service where we monitor and triage on your behalf.

Next step

Get a written scope and a fixed price.

A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.