top of page
  • Home
  • Platform
  • U-ASM
  • Unified Attack Surface Management

    Attack Surface Management is the continuous process of discovering, classifying and monitoring every asset your organisation exposes to the internet — including the ones no inventory has ever recorded.

    That is where Attack Surface Management (ASM) comes in — a powerful tool that helps you identify, prioritise, and mitigate your external weaknesses, which can become a point of entry for attackers.

    U-ASM continuously discovers and monitors your digital assets for vulnerabilities and weaknesses, which helps you gain the attacker's point of view, resulting in a proactive and effective approach to security.

  • EASM EASM External Attack Surface Management Outside-in discovery and monitoring of everything an organisation exposes to the internet, including assets no inventory has recorded. Full glossary →
  • EPSS EPSS Exploit Prediction Scoring System A data-driven model, scored daily by FIRST, estimating the probability that a published CVE will be exploited in the wild within the next 30 days. Full glossary →
  • KEV KEV Known Exploited Vulnerabilities catalogue CISA's published record of vulnerabilities confirmed to be under active exploitation. Presence in KEV is evidence, not prediction. Full glossary →
  • CVSS CVSS Common Vulnerability Scoring System A severity score describing how bad a vulnerability would be if exploited. Its own specification treats the base score as a ceiling, not a measure of risk in your environment. Full glossary →
  • What U-ASM discovers

    Thirteen discovery and correlation capabilities, running continuously rather than on a schedule.

  • Domain and Subdomain discovery Enumeration outward from your registered names, including the subdomains nobody recorded and the ones an acquisition brought with it.
  • IP discovery The address space actually resolving to you today, rather than the range your inventory says you were allocated.
  • DNS Discovery Records, delegations and dangling entries — including the ones pointing at infrastructure you decommissioned.
  • TLS/SSL Certificate Discovery Certificates are public by design — every one issued for your brand is visible, including the ones you did not issue.
  • Open Port Discovery What is listening, on which host, and whether it was meant to be reachable from the internet at all.
  • Web Server Discovery The web servers and applications behind those ports, with the software and versions they advertise.
  • Asset Inventory A live external inventory built from what is observable, not from what somebody remembered to register.
  • Similar Domain Discovery Look-alike and typosquatted registrations, and the certificates issued for them — often the first visible signal of a phishing campaign being prepared.
  • Vulnerability Discovery Known weaknesses on the assets discovery actually found, including the ones no scan was ever pointed at.
  • Compromised Credential Discovery Leaked credentials tied to your domains, matched to the specific login surface they open.
  • Data correlation for better visibility Exposure, exploitability and credential findings joined into one picture, so priority reflects reachability rather than severity alone.
  • New Asset Detection A newly published service surfaces as a change event, not at the next scheduled cycle.
  • Configuration Change detection A newly opened port, a re-issued certificate or an altered DNS record is reported as it happens.
  • What actually happens to your telemetry

    Between a log line being written on one of your machines and someone telling you what to do about it, there are four stages and one store. This is all of them.

    Telemetry pipeline · illustrative

    Illustrative architecture diagram, not a live system view. Stage names describe the work; the specific components behind each one are scoped per engagement.

    Almost none of your exposure window is work

    Map the time between an exposure appearing and it being closed, and the fix is rarely what takes the time. Queue time is. Changing the cadence changes the queue.

    Quarterly scan cadence
  • 01 Exposure appears 0m work · 90d waiting A new service, a forgotten subdomain, an expired certificate. On a quarterly cadence it can sit unseen for a full cycle before anything looks at it.
  • 02 Discovery 2h work · 24h waiting The scan runs and the finding lands in a queue.
  • 03 Triage 3h work · 3d waiting Someone has to decide whether this one matters, against everything else in the queue.
  • 04 Remediation 4h work · 7d waiting The fix itself is usually quick. Getting it scheduled is not.
  • 05 Verification 1h work · 24h waiting Confirming the exposure is actually closed, not just ticketed.
  • Lead time
    102d
    Of which work
    10h
    Flow efficiency
    0.4%

    Structural illustration, not measured client results. The waiting figures follow from the cadence itself — a quarterly cycle means an exposure appearing just after a scan waits most of a quarter to be seen.

    Continuous monitoring
  • 01 Exposure appears 0m work · 12h waiting Continuous discovery means the window is hours, not a quarter.
  • 02 Discovery 1h work · 1h waiting Found on the next pass and classified automatically.
  • 03 Triage 3h work · 8h waiting Prioritised against exploitability rather than raw severity, so the queue is short enough to work.
  • 04 Remediation 4h work · 2d waiting The same fix, scheduled against a much shorter list.
  • 05 Verification 1h work · 4h waiting Re-checked on the following pass rather than at the next cycle.
  • Lead time
    3d
    Of which work
    9h
    Flow efficiency
    11.0%

    Structural illustration, not measured client results. The waiting figures follow from the cadence itself — a quarterly cycle means an exposure appearing just after a scan waits most of a quarter to be seen.

    Why continuous monitoring beats a quarterly scan

    A scheduled vulnerability scan tells you about the assets you already knew about, on the day it ran. Here is what changes when discovery never stops.

    Capability Traditional Vulnerability Scanning CyberTI® U-ASM Asset discovery Limited to a supplied, manually maintained IP range Continuous discovery of unknown and forgotten assets Scan cadence Point-in-time, typically monthly or quarterly Continuous monitoring with change detection Attacker perspective Inside-out view of what you already know about Outside-in view of what an attacker can actually see Shadow IT and cloud sprawl Invisible until someone registers it Surfaced automatically as new assets appear Compromised credentials Not covered Monitored and correlated against your domains Typosquatting and brand abuse Not covered Similar-domain and certificate discovery — detection and speed, not prevention Certificate and DNS hygiene Partial, if in scope TLS/SSL certificate and DNS discovery included Prioritisation Raw CVSS severity Correlated by exposure, EPSS exploitation probability, CISA KEV status and business context Cost model Scales with the address space you scan Directed at live, reachable assets to reduce scan cost

    CyberTI’s characterisation of the two approaches, not an independent benchmark. "Traditional vulnerability scanning" means a scheduled, credentialed scan of a manually maintained IP range.

  • Asset discovery Traditional Vulnerability Scanning Limited to a supplied, manually maintained IP range CyberTI® U-ASM Continuous discovery of unknown and forgotten assets
  • Scan cadence Traditional Vulnerability Scanning Point-in-time, typically monthly or quarterly CyberTI® U-ASM Continuous monitoring with change detection
  • Attacker perspective Traditional Vulnerability Scanning Inside-out view of what you already know about CyberTI® U-ASM Outside-in view of what an attacker can actually see
  • Shadow IT and cloud sprawl Traditional Vulnerability Scanning Invisible until someone registers it CyberTI® U-ASM Surfaced automatically as new assets appear
  • Compromised credentials Traditional Vulnerability Scanning Not covered CyberTI® U-ASM Monitored and correlated against your domains
  • Typosquatting and brand abuse Traditional Vulnerability Scanning Not covered CyberTI® U-ASM Similar-domain and certificate discovery — detection and speed, not prevention
  • Certificate and DNS hygiene Traditional Vulnerability Scanning Partial, if in scope CyberTI® U-ASM TLS/SSL certificate and DNS discovery included
  • Prioritisation Traditional Vulnerability Scanning Raw CVSS severity CyberTI® U-ASM Correlated by exposure, EPSS exploitation probability, CISA KEV status and business context
  • Cost model Traditional Vulnerability Scanning Scales with the address space you scan CyberTI® U-ASM Directed at live, reachable assets to reduce scan cost
  • CyberTI’s characterisation of the two approaches, not an independent benchmark. "Traditional vulnerability scanning" means a scheduled, credentialed scan of a manually maintained IP range.

    What that gets you

    Increased Visibility

    See every internet-facing asset you own, including the ones nobody remembered to tell security about.

    Vulnerability assessment

    Continuously assess discovered assets for exploitable weaknesses rather than waiting for the next scheduled scan.

    Early detection

    Catch newly exposed services and certificates the moment they appear, before an attacker finds them.

    Misconfigured Device detection

    Identify devices and services published with weak or default configuration and get them corrected.

    Brand Protection

    Look-alike and typosquatted domain discovery, and monitoring for misuse of your brand across the domains and certificates attackers register against you.

    Reduce Risk

    Shrink the attack surface deliberately by retiring exposure you no longer need.

    Automation

    Discovery, classification and monitoring run continuously without adding analyst headcount.

    Scan Cost reduction

    Direct paid scanning at the assets that actually matter instead of the whole address space.

    Australian compliance obligations U-ASM supports

    Three obligations each assume an accurate picture of what you expose.

    The SOCI Act requires responsible entities to maintain a written Critical Infrastructure Risk Management Program covering cyber, physical, personnel and supply chain hazards, with the Enhanced CIRMP Rules commencing 10 June 2026 and introducing more prescriptive expectations about how risks are identified and assessed. Ransomware payment reporting under the Cyber Security Act 2024 applies to businesses turning over more than $3 million, on a 72-hour clock. And the OAIC's Notifiable Data Breaches scheme requires assessment of a suspected eligible breach within 30 days, treating that as a maximum rather than a target.

    Continuous asset discovery is the evidentiary layer underneath all three. You cannot assess an incident's scope in 30 days if you are still working out which systems you own.

    What U-ASM does not do

    Three bounds, stated before you find them yourself.

  • 01 We cannot stop someone registering a look-alike domain. Nor can anyone else — domain registration is open. What U-ASM does is find them fast, along with the TLS certificates issued for them, which is often the earliest visible signal that a phishing campaign is being prepared.
  • 02 This is not a replacement for penetration testing. U-ASM tells you what exists and what is exposed, continuously and at breadth. A penetration test tells you what a skilled attacker can do with a specific piece of it, in depth. Standards such as PCI DSS v4.0.1 still expect annual-plus-significant-change testing regardless of what monitoring you run.
  • 03 This is an outside-in view, not an asset register. U-ASM sees what you expose to the internet. Internal asset management is a different category, and we do not claim to do it here.
  • Frequently asked questions

    Eleven questions, grouped, and sourced where a source exists.

    What it is

    What is Attack Surface Management?

    Attack Surface Management is the continuous process of discovering, classifying and monitoring every asset your organisation exposes to the internet — including the ones no inventory has ever recorded.

    It is deliberately an outside-in view: what an attacker can see and reach, rather than what your asset register says you own.

    Is this just a vulnerability scan with a different name?

    No, and the difference is the direction it looks from.

    A vulnerability scan is inside-out. You supply a range of IP addresses you already know about, and the scanner tells you what is wrong with them — point in time, typically monthly or quarterly.

    U-ASM is outside-in and continuous. It discovers what you expose without being told where to look, including assets no one documented, and it monitors for change rather than sampling. The gap that matters is the asset your scanner was never pointed at, because nobody knew it existed.

    There is a compliance dimension too: ASD's Essential Eight expects vulnerability scanning at least daily on internet-facing services. A quarterly scan of a hand-maintained IP list does not meet that, and cannot, because the list goes stale between cycles.

    Does attack surface management replace penetration testing?

    No. They answer different questions and most organisations need both.

    U-ASM tells you what exists and what is exposed, continuously and at breadth. A penetration test tells you what a skilled attacker can actually do with a specific piece of that exposure, in depth, at a point in time.

    They are also complementary in practice: U-ASM's discovery routinely finds assets that belong in the next test's scope and would otherwise have been left out. And the annual-plus-significant-change testing cadence that standards such as PCI DSS v4.0.1 require is unaffected by having continuous monitoring in place — continuous discovery is not a substitute for adversarial testing.

    What it finds

    How do you find assets we don't know we have?

    By working from the same public artefacts an attacker starts with — your domains and subdomains, DNS records, IP allocations, TLS certificates, open ports and the web servers behind them — and following the trail outward rather than reading your asset register inward.

    Shadow IT and cloud sprawl are found this way. A marketing team spins up a staging site, a developer exposes an API gateway, an acquired subsidiary brings its own domains. None appears in your CMDB. All appear from outside.

    What does "compromised credential discovery" mean?

    It means monitoring for credentials tied to your domains appearing in breach corpora and criminal marketplaces, and correlating those against the assets you actually expose — so a leaked credential is matched to the specific login surface it opens.

    Credential-based intrusion remains one of the two dominant breach patterns, and a person — phished, tricked or simply reusing a password — is involved in the majority of them. Traditional vulnerability scanning covers none of this — it is outside the category's definition.

    Can you stop someone registering a domain that looks like ours?

    No — and nor can anyone else. Domain registration is open, and no security vendor can prevent a third party buying a look-alike name.

    What U-ASM does is find them fast. Similar-domain discovery monitors for typosquatted and look-alike registrations against your brand, along with the TLS certificates issued for them, which is often the earliest visible signal that someone is preparing a phishing campaign against your customers or staff. From there the response is yours to run — takedown requests, registrar complaints, pre-emptive user warnings.

    Detection and speed, not prevention. Any vendor claiming to prevent typosquatting is describing something that does not exist.

    Do we just get a list of CVSS scores?

    No. Findings are ordered by whether they are actually reachable, whether they are actually being exploited, and what the affected asset is worth to you.

    CVSS gives severity, and its own specification treats the base score as a ceiling rather than a live risk measure. On top of it we use EPSS, which estimates the probability that a given CVE will be exploited in the wild within the next 30 days, and CISA's Known Exploited Vulnerabilities catalogue, which records confirmed active exploitation. Combined with exposure context from discovery, that produces a remediation order rather than a severity histogram.

    How quickly does attack surface monitoring notice a change?

    Discovery, classification and monitoring run continuously rather than on a scheduled sweep, so a newly published service, a newly issued certificate or a newly opened port surfaces as a change event rather than waiting for the next cycle.

    The benchmark to compare against is ASD's Essential Eight expectation of at least daily vulnerability scanning on internet-facing services. A monthly or quarterly scan cannot meet that. Continuous change detection is the only way to close the window between exposure appearing and exposure being known.

    How it fits

    Why is ASM essential?

    Emerging technologies keep expanding what an organisation exposes to the internet, and traditional inventory processes cannot keep pace.

    IT environments have grown more complex, threats have grown more sophisticated, and remote work has pushed the perimeter well beyond the office.

    In Australia the regulatory case is now specific rather than general. Critical infrastructure entities must maintain a written Critical Infrastructure Risk Management Program under the SOCI Act, and the Enhanced CIRMP Rules that commenced on 10 June 2026 replaced principles-based expectations with prescriptive ones. Businesses turning over more than $3 million must report ransomware payments within 72 hours. And any organisation holding personal information must assess a suspected eligible data breach within 30 days under the OAIC's Notifiable Data Breaches scheme. Each of those obligations assumes you know what you expose.

    How does U-ASM help with our Australian compliance obligations?

    Three obligations each assume an accurate picture of what you expose.

    The SOCI Act requires responsible entities to maintain a written Critical Infrastructure Risk Management Program covering cyber, physical, personnel and supply chain hazards, with the Enhanced CIRMP Rules commencing 10 June 2026 and introducing more prescriptive expectations about how risks are identified and assessed. Ransomware payment reporting under the Cyber Security Act 2024 applies to businesses turning over more than $3 million, on a 72-hour clock. And the OAIC's Notifiable Data Breaches scheme requires assessment of a suspected eligible breach within 30 days, treating that as a maximum rather than a target.

    Continuous asset discovery is the evidentiary layer underneath all three. You cannot assess an incident's scope in 30 days if you are still working out which systems you own.

    What are the primary use cases?

    Asset discovery — finding the internet-facing systems nobody has documented.

    Vulnerability reduction — cutting exploitable exposure before it is used against you.

    Credential monitoring — detecting compromised credentials tied to your domains.

    Application security — tracking the web applications and APIs you publish.

    Attack surface reduction — deliberately retiring exposure you no longer need.

    See what CyberTI® can find on your perimeter

    We can run a discovery pass against your external footprint and walk you through what turns up.

    Both forms deliver to info@cyberti.com.au.

    bottom of page