๐Ÿ“Š Dashboard ๐ŸŸข Pulse โœ‰ Inbox Shield ๐Ÿ“ก Vendor Watch ๐Ÿ“‹ Compliance ๐Ÿ›ก๏ธ BrandGuard

What Is Attack Surface Management? (And How to Do It for Free)

Enterprise ASM tools cost $30,000+/year and are built for security teams with 10 people. But the underlying concept โ€” continuously knowing what you expose and whether it's secure โ€” is something any small team can implement for close to nothing.

What attack surface management actually means

Your attack surface is everything an attacker can see and interact with from the outside: your websites, APIs, subdomains, email configuration, open ports, SSL certificates, and any exposed admin panels or cloud storage. Attack surface management (ASM) is the practice of continuously discovering, monitoring, and reducing this exposure.

The key word is continuously. A one-time penetration test is a point-in-time snapshot. Your attack surface changes every time you add a subdomain, renew an SSL certificate, change a DNS record, or deploy a new service. ASM is about staying current โ€” knowing what you have and whether it's configured securely.

What your attack surface includes

๐ŸŒ
Web properties
Your main domain, subdomains, staging environments, and any forgotten microsites
๐Ÿ“œ
SSL/TLS
Certificate validity, expiry dates, weak cipher suites, and HSTS configuration
๐Ÿ”’
HTTP security headers
CSP, X-Frame-Options, Referrer-Policy, Permissions-Policy โ€” each a defence layer
๐Ÿ“ง
Email security
SPF, DKIM, DMARC configuration and enforcement policy
๐Ÿ”
DNS records
Zone transfers, dangling CNAME records, MX configuration
๐Ÿšช
Open ports
Exposed databases, admin panels, dev tools, or SSH/RDP accessible from the internet

Why small teams ignore it (and why that's a mistake)

Most small teams do a one-time security audit when something goes wrong, then go months or years without checking. In that time:

None of these show up until an attacker finds them โ€” or until a customer complains their browser is showing a certificate error. The cost of monitoring is near zero. The cost of a breach is not.

The free ASM stack for small teams

1. External scan: SSL, headers, DNS, ports

The EdgeIQ Dashboard runs a free scan against your domain that checks SSL grade and expiry, all major HTTP security headers, SPF/DMARC/MX records, and exposed ports. It's free and takes 30 seconds. Run it monthly at minimum โ€” or set up automated weekly monitoring with Pulse.

2. Subdomain discovery

Most teams don't know all their subdomains. Certificate Transparency logs record every SSL certificate ever issued for your domain โ€” searching them via crt.sh gives you a near-complete list of subdomains that have ever had a certificate. Do this quarterly.

3. Email authentication

Check your SPF, DKIM, and DMARC records with Inbox Shield. An Aโ€“F grade on each component tells you instantly whether your email domain is spoofable. This is a 2-minute check that most teams have never done.

4. Brand monitoring

Your external attack surface also includes what attackers build about you. Lookalike domains โ€” typosquatted or homoglyph registrations of your domain โ€” are used to phish your customers while looking like they come from you. BrandGuard monitors for these daily.

5. Compliance posture

If you're targeting SOC 2, HIPAA, or PCI compliance, the Compliance dashboard maps your external scan results to the relevant control framework โ€” so you know which findings are compliance-relevant and which to prioritise.

How often should you scan? Weekly automated scans for anything customer-facing. Monthly manual check of subdomain inventory. Quarterly review of DNS records and third-party integrations.

What enterprise ASM tools give you that free tools don't

Enterprise tools like Censys, Runzero, and Axonius give you deeper internal network visibility, asset inventory for thousands of IPs, integration with SIEM/SOAR platforms, and dedicated analysts. If you have a SOC and more than a few hundred externally-facing assets, they're worth it.

For a team of under 50 people with a handful of domains and a standard SaaS stack, a free external scan tool + weekly automated monitoring covers 80% of what matters at 2% of the cost.

๐Ÿ“ฌ Weekly attack surface digest

Security monitoring tips, new threat techniques, and product updates. No spam โ€” unsubscribe anytime.

โœ… You're in. Check your inbox.

Run a free attack surface scan right now

The EdgeIQ Dashboard scans your domain for SSL issues, security header gaps, DNS misconfigurations, and open ports in under 30 seconds. Free, no account required.

Scan Your Domain Free โ†’

No account required ยท results in 30 seconds