Attack surface management: you can't protect what you can't see
The way into a network is rarely the spectacular zero-day. More often it is the forgotten asset nobody had on their radar anymore. isidaten makes the attack surface continuously visible from outside and inside, and matches it automatically against current vendor advisories.
The way into a network is rarely the spectacular zero-day. More often it is the forgotten subdomain, the expired certificate, the test server that quietly went online. The pattern behind it is always the same: defenders work from last quarter's asset list, attackers scan today. That gap is the attack surface, and it cannot be closed with a spreadsheet.
Asset blindness is the real problem
Most incidents begin not with missing technology but with missing visibility. What is not inventoried does not get patched. What nobody knows is exposed shows up in no risk assessment. An attack surface captured by hand once a quarter is blind exactly between those points, and that is where the attacker finds the way in.
Outside view and inside view in one platform
Many tools see only one side: either the externally reachable attack surface (External Attack Surface Management, EASM) or the internal systems (Internal Attack Surface Management, IASM). isidaten covers both. The same platform checks what is reachable from the outside via the cloud or an agent, and what sits on the internal network. What matters is the where: not in a separate scanner silo, but where the risk register, measures and evidence also live. Specialized exposure management suites offer both viewing directions, but they sit next to the compliance world. Integrated into an ISMS platform, this combination is rare.
What continuous visibility means
The attack surface management module in isidaten answers the question of what a company is actually exposing, continuously instead of occasionally:
- Freely defined scan targets: as domain, IP range or CIDR, each individually activatable.
- Discovery instead of upkeep: assets are found automatically, with last scan time and number of systems discovered, instead of being maintained by hand in a list.
- Certificates including expiry: discovered TLS certificates are tracked with validity, days to expiry and a status up to expired. The certificate nobody was tracking surfaces before it becomes an incident.
- Findings with severity: every finding carries severity, category, CVE reference, CVSS score and a clear handling status.
The real lever is the match
Visibility alone only produces a longer list. The difference appears when discovered assets are matched automatically against current vulnerabilities. isidaten ingests vendor security advisories in CSAF format into a central catalog and links them to your own asset base by name, version or CPE. Instead of reading an advisory and asking manually whether it affects you, the answer is already there: which system, which software, at what CVSS score, whether an exploit is available and whether the flaw is remotely exploitable. Exactly those facts decide what gets handled first.
One object base: finding, risk, evidence
The decisive point is where the finding goes next. In isidaten a discovered asset is the same object as in asset management and in the risk register. A finding therefore does not stay a line in a scanner report but moves through a traceable status into risk treatment, with a documented decision between remediation, compensation and acceptance. A pure scan becomes a provable state that an auditor can follow.
The link to NIS2
For entities in scope of NIS2 this is more than convenience. Anyone who has to treat risks systematically and prove their effectiveness needs the link between exposed asset, known vulnerability and decision taken in one place, not spread across several tools. See how attack surface management works in isidaten on our solutions page, or book a demo.
Questions about this update?
Talk to us – we are happy to show you this feature in a demo.