Asset discovery
Domains, subdomains, IP ranges and cloud assets attributed to your organisation, including the ones registered on a corporate card by a team in another country.
Continuous Security
An annual penetration test is a photograph. Your attack surface is a video — subdomains appear, certificates expire, a developer exposes a staging environment on a Friday afternoon and it stays exposed for eleven months.
Consider the arithmetic. You test annually. The test takes a week. That leaves fifty-one weeks in which your perimeter changes and nobody checks. In that time your teams will register subdomains, spin up demonstration environments, deploy a new marketing site on a platform nobody told IT about, and let a certificate expire on something that turns out to be important.
Meanwhile the other side of the equation moves faster still. A vulnerability disclosed on Tuesday is being scanned for globally by Wednesday. The window between a critical flaw becoming public and it being exploited at scale is now measured in days, sometimes hours. Anything that depends on your next scheduled assessment to catch it is, functionally, not a control.
Attack surface management closes that gap. We continuously discover what belongs to you and what is reachable from the internet — including the assets that are not on any list you hold — and we watch for change. When something new appears, when something changes state, when a certificate is about to expire, or when a newly published vulnerability affects something you are running, you hear about it that day.
Coverage
Continuous, external, and non-intrusive by design — everything here is observation, not attack.
Domains, subdomains, IP ranges and cloud assets attributed to your organisation, including the ones registered on a corporate card by a team in another country.
Staging environments, demo instances, legacy hosts and services that outlived the project that created them.
Administrative panels, remote access, databases and management interfaces that have become reachable from the internet.
Newly published vulnerabilities matched against what you are actually running, escalated immediately when the flaw is on the known-exploited list.
Expiry, weak configuration, mismatches and certificates issued for names you do not recognise.
New hosts, new open ports, new technologies and altered configuration — reported as change, because change is the signal.
Dangling DNS records pointing at deprovisioned cloud resources that somebody else can claim.
Company credentials appearing in public breach data, and code repositories leaking keys and endpoints.
Approach
Set up once, then it runs. Findings arrive as alerts and as a live dashboard, not as a quarterly PDF.
We establish what actually belongs to you — starting from your known domains and expanding outward through the relationships that connect assets to an organisation.
You review the discovered inventory and confirm ownership. Anything ambiguous stays out until it is confirmed; we never test what is not yours.
A full assessment of the confirmed surface establishes the starting position, so subsequent alerts are genuine change rather than noise.
Continuous rediscovery and non-intrusive assessment, with vulnerability intelligence refreshed daily against everything found.
New exposure, new critical vulnerability or material change is raised the day it is detected, with context and a recommended action.
A monthly review with a human, covering what changed, what was closed, and what needs a decision rather than a fix.
Deliverables
The report is the product. If it cannot be acted on by a developer and understood by a director, we have not finished.
Everything internet-facing that belongs to you, kept current — usually 20–40% larger than the list clients start with.
Notification the day something appears, changes or becomes exposed, with the context needed to decide quickly.
Ranked by exploit probability and known-exploited status, so the queue reflects real risk rather than raw severity.
A conversation with a person about what changed and what it means, not an automated email.
Exposure over time — the chart that shows a board whether the programme is working.
Is this for you?
If none of them are, say so on the call and we will tell you honestly whether this is the right piece of work — or point you at the one that is.
Book a scoping callHow we work
The same engagement model applies to every piece of work we take on, so you always know what happens next.
A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.
Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.
Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.
One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.
A walkthrough call with your engineers. We answer questions on the fix, not just the finding.
A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.
Questions
The questions clients actually ask during scoping. If yours is not here, ask it directly.
A penetration test is deep, point-in-time and intrusive: a person actively attacks a defined scope and proves what is exploitable. Attack surface management is broad, continuous and non-intrusive: it observes what exists and what changes, every day, without attacking anything. They answer different questions and work best together — ASM tells you what to test and when something has changed, and the penetration test tells you how bad it is.
Monitoring is designed to be non-intrusive — it observes what is publicly visible rather than attacking it, and the traffic volume is negligible. Some security tooling will log the activity, so we provide our source addresses during onboarding, and you can allowlist them or leave them unlisted if you would rather see how your monitoring reacts.
We start from what you confirm — your domains and IP ranges — and expand outward through the public relationships that link assets to an organisation: certificate records, DNS relationships, registration data and cloud address attribution. Everything discovered is presented to you for confirmation before it enters scope. We never assess anything you have not confirmed as yours, both as a matter of law and because unattributed assets produce useless findings.
You are alerted the same day, with the affected asset, what the exposure is, whether it is on the known-exploited list, and what to do about it. For clients on a managed service we can also verify the finding manually before escalation, which removes the false-positive problem that makes most automated alerting easy to ignore.
Yes. Attack Surface Management is a live module in the Protect group of SemperWise One™, so it can be run as a platform subscription you operate yourself, or as a managed service where we monitor and triage on your behalf.
Next step
A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.