External attack surface management (EASM) is the continuous identification, monitoring and assessment of the digital assets an attacker can find from the internet without your credentials: domains, certificates, cloud services, APIs, forgotten subdomains, and the suppliers attached to them.
It exists because the asset register is always incomplete. Cloud accounts get opened outside procurement. Subdomains outlive the app they pointed at. A vendor’s staging host still resolves. None of those objects appear in the CMDB on the day they become reachable, which is the day they matter.
Panop’s discovery starts here — from a company name, outside-in — then continues inside the network. This article is the vocabulary for the first half.
What EASM is for
An attacker does not start from your inventory. They start from your company name, your DNS, your certificates, your cloud-provider metadata and the leak sites that already have a subset of your staff’s passwords. EASM is the discipline of doing that reconnaissance on a schedule, attributing what it finds to you, and watching it change.
Done well, the output is not a larger spreadsheet. It is a current map of what is reachable from an untrusted network, with owners attached, so the next stage — deciding which of those objects is actually exploitable — has something true to work on.
Done badly, it is another scanner: banners collected, CVEs looked up, a weekly PDF. That is vulnerability management performed on a partial perimeter. It is not attack surface management.
EASM, ASM, CAASM and CTEM are not synonyms
The four acronyms get used as if they were product editions. They are not.
| Term | What it names | What it does not do |
|---|---|---|
| EASM | Technology for discovering and monitoring internet-facing assets | See inside the network, or prove exploitability on its own |
| ASM | Broader attack-surface management, sometimes including internal and OT | A settled standard; vendors stretch it |
| CAASM | Cyber asset attack surface management: unifying inventories via integrations | Find assets that never entered those integrations |
| CTEM | Gartner’s operating loop: scope, discover, prioritise, validate, mobilise | A product you can switch on |
CTEM is the programme. EASM is one of the inputs to the discover stage. Without it, discovery has a hole the size of everything you never listed. With only it, you have a perimeter map and still no proof that any given finding is reachable in your configuration, and no view of the supplier or the cluster that is not public.
That is why Panop treats EASM as the start of exposure management, not the product. Exposure management vs vulnerability management is the companion piece on what happens after the map exists.
Why the register is always late
Three structural reasons, none of them a diligence failure.
Cloud is faster than procurement. A sandbox in a personal account, a forgotten region, a storage bucket created for a migration and never torn down: all of these are reachable before they are owned.
The perimeter is now a graph of other people’s perimeters. Verizon’s 2026 DBIR put confirmed breaches involving a third party at 48%. A supplier questionnaire cannot see a host the supplier stood up on Tuesday. EASM that does not include connected vendors is EASM of a company that no longer exists.
AI assets did not go through the same gate. Models, agents and MCP servers get deployed from a laptop. They are internet-facing more often than the team that owns IAM expects. AI asset discovery is EASM applied to a class of object the last generation of ASM tools was not built to name.
What a useful EASM programme actually produces
A buyer evaluating EASM tools or Panop should ask for artefacts, not category labels.
- A map that started without a seed file, or an honest account of what had to be uploaded for the map to be complete.
- Change, not a snapshot. New, changed and gone assets, on a cadence that matches how often DNS and cloud actually move.
- Attribution you can argue with. A confidence score and a reason the asset was tied to you, so the false-positive fight happens before validation spend.
- A hand-off into validation. The point of the map is to know what to test. If the EASM tool stops at “here is a CVE on this banner,” you have bought a scanner with better marketing.
Panop’s answers to those four: discovery starts from a company name; it re-runs continuously; ownership is enriched from the systems you already run; validation is an autonomous pentest against the services actually fingerprinted.
Panop’s discovery product is the EASM-shaped start of that loop: seedless discovery, then autonomous pentest.
EASM is necessary. It is not sufficient.
If the only question you have is “what of ours is on the internet that we do not know about?”, a specialist EASM product will spend years on that question and may beat a broader platform on subsidiary attribution or dark-web add-ons. That is a legitimate shortlist.
If the question is “what is reachable, including through a supplier and including the model a developer shipped last week, and which of those paths should we close today?”, EASM is step one of a CTEM loop. Buy the map. Then buy, or already have, the test and the ranked queue. Panop is built as that loop. EASM is where it starts.