EASM
External Attack Surface Management
Continuous discovery, inventory, and monitoring of an organization’s internet-facing assets and exposure signals from an outside-in perspective.
External Attack Surface Management (EASM) is the practice of continuously discovering, inventorying, and monitoring every asset and signal an organization exposes to the public internet — domains, subdomains, IP ranges, cloud storage, exposed services, credentials in breach data, DMARC/SPF posture, code-repository leakage, and third-party dependency exposure. EASM tools operate from an outside-in perspective (no agents, no internal access) and are typically used by security teams to reduce dwell time on internet-facing vulnerabilities and by procurement to assess vendor security posture. Category leaders include CyCognito, Palo Alto Cortex Xpanse, and Randori. LeakTrace overlaps with EASM on the discovery layer but extends further into the response layer: analyst desk verification, chain-of-custody evidence packaging, and coordinated remediation. Where EASM tells you what is exposed, LeakTrace tells you what it means and coordinates the fix.
For businesses, EASM is often the starting point of a cyber posture conversation with a partner or insurance carrier. LeakTrace Business Audit ($697) delivers the EASM layer as a bounded 72-hour engagement rather than a per-seat annual SaaS contract. For family offices, EASM against the principal and every advisor tenant is a required precursor to any meaningful wire-fraud prevention program.