EASM
The continuous discovery and assessment of internet-visible assets and services from an external perspective.
Knowledge centre
The continuous discovery and assessment of internet-visible assets and services from an external perspective.
A continuous programme for scoping, discovering, prioritising, validating and mobilising action around material exposure.
A decision-tree approach that maps vulnerability evidence and stakeholder context to an action outcome.
A structured naming scheme used to identify hardware, operating systems and applications.
Turn scanning, ownership, risk decisions and remediation into one repeatable operating system.
Build treatment expectations around evidence and exposure instead of severity alone.
Why ever-growing queues obscure risk and how to restore a manageable flow of decisions.
A repeatable workflow for reducing a large vulnerability population to a defensible and actionable priority list.
Move reporting away from raw finding counts and towards coverage, ageing, ownership and verified exposure reduction.
Critical counts are easy to report and easy to misunderstand. Without coverage, exposure and age, they say very little about risk.