In today's dynamic threat landscape, organizations are shifting their approach to cybersecurity, moving from a reactive stance to a proactive strategy. This webinar will explore how ASM is becoming a cornerstone of that shift. You will learn what ASM is, why it is important, and how it addresses unique security challenges. We will also share key findings from our recent Leadership Compass, including market analysis and leaders, capabilities, and emerging trends. Please join us for our upcoming webinar and discover how leading organizations use ASM to reduce risk, enhance visibility, and stay ahead of sophisticated attacks.
Osman Celik, research analyst at KuppingerCole, will share insights from his latest Leadership Compass on ASM and its growing role in proactive cybersecurity strategies. He will discuss the core capabilities of ASM solutions, highlight innovative trends, and explain why organizations need ASM to stay ahead of emerging threats. The session will also provide an overview of leading vendors in different segments and their differentiators based on recent market research.
Martin Jartelius, CISO & Product Director at Outpost24, will contribute a practitioner’s perspective, sharing real-world insights from implementing ASM in complex enterprise environments. Drawing on his extensive experience in offensive and defensive security, Martin will highlight practical challenges, success factors, and lessons learned from the field. His input will offer attendees a grounded view of how ASM is applied in practice to reduce exposure, improve asset visibility, and strengthen overall cyber resilience.
Hello, everyone. Welcome to our webinar.
Today, our topic is Proactive Cybersecurity Strategies. Why ASM is a Cornerstone of your Modern Threat Management? My name is Osman Celik. I'm a Research Analyst at KuppingerCole. I've been working on ASM solutions in the last two or three years, actually. And today I'm joined by Martin Jartelius from Outpost24.
Welcome, Martin. How are we here? Perfect. So before we start with our webinar, let's do some housekeeping. So for our audience, you're all muted.
Actually, you don't have to control anything in your settings. And in the right hand side, you will see some buttons, apps, links, people, polls, questions, and chat. So you can interact with us there. So when we have the poll questions ready for you, you can use, for example, the polls tab and then try to answer the questions there. And whenever you have a question, you can raise your question there. You can send us. And then when we have the panel discussion part, we'll try to answer as much as possible. And for the slides and the recording, don't worry. We are recording the webinar.
And then the slide deck from my end will be available for you in the upcoming days. So this is today's agenda. And I will first begin with my findings and my insights from the ASM market. And then I will try to summarize with the key findings from the research. I think this is very important for you, especially for those who doesn't have that much time. And then later on, we will dive into our methodology of research. This is standard to every research we conduct here at Cofinger Call. And in the approximately last 30 minutes, we will have a panel discussion.
And then please prepare your questions. I highly encourage you to join our panel discussion with your questions. So let's begin out with our poll question number one. I give you approximately 10 seconds to answer it.
As I said, you will see the polls tab on the right-hand side to answer that. The question is, does your organization have an ASM solution in place today? Yes. Actively deployed. We are in evolution proof of concept phase or no. All right. So before we begin with the challenges part, I would like to tell how was my research actually. So we had 20 vendors participating to my leadership compass on attack surface management. And I have recently published a report. I think it was at the end of last month. Yeah. And we had very good feedback on the first report.
And this was the second edition we published. And the next one will be in 2026, hopefully.
So, but we're talking about ASM, but why don't we start with, why do we need ASM? It's because as the name of the webinar states, we need proactive security measures. And maybe so far in the last decade, we are used to reactive security measures that only addresses the threats after an incident occurred. And then this can result you in a significant downtime or remediation costs. And then ultimately what you end up is with data loss, operational disruption, and reputational harm in most cases. The next thing is that we have lots of interconnected devices nowadays.
You can name it like your cloud environment, your integrated tools, your IoT sensors, if you're in an industry that are using IoT or OT sensors, and other smart devices, you can name this list with more components. And then these are really not easy to be tracked or monitored with traditional or physical agents. And ASM provides a unified security overview, no matter which component you have in your IT environment. So this is a very good plus.
And the other thing is that your business is expanding, as long as you're doing a good job, and then you're hiring new people, that means more assets and more users to manage. So manually managing them, because actually impractical. So you need to have an automated tool. And ASM also comes into play in this case. And similar to your organizational growth, and then your IT systems is also growing. Every organization almost has some legacy systems that are combined with modern multi-cloud or hybrid cloud setups. So this means complexity to manage, and also this means layered infrastructure.
So you need to have a solution that are able to manage and address vulnerabilities, threats arising from this combination. The sophisticated attack vectors, this is a hot topic for everyone, I guess. And we all know that cybercriminals are leveraging AI and ML to orchestrate their sophisticated attacks. For instance, they are using AI or deepfake tools to automate phishing campaigns, for example. These are very deceiving, and I believe this is one of the hot topics of the cybersecurity as of today. This is my personal observation.
Yeah, regulatory compliance is always a thing for people who are located in the countries where they have obligatory regulatory compliance. So ASM helps you also ensure your compliance with many regulations, standards, and frameworks, which I will elaborate later on. But most ASM solutions are doing a good job. They can help you with GDPR, or if you're from the United States, HIPAA, or your PSIDSS, or any sort of regulation you can imagine, actually. But you have to keep in mind that you have to check the vendors' collaterals to see if they are matching with your expectations.
And the legacy solutions, as I mentioned earlier, they are still on the reactive level, so they are not proactive enough. And in most cases, they do not provide real-time monitoring of your assets and vulnerabilities.
And also, one more thing, it is sometimes very difficult to make them orchestrate with your other cybersecurity tools, like SOAR, for example. And last but not least, organizations rely on their supply chains, and then their third-party vendors, and then their business partnerships. And this is also nowadays, unfortunately, contributing to your risk exposure. So these were the challenges that I personally think that are leading organizations, or motivating them to acquire an ASM solution.
And before we really dive into what ASM is, I would like to make sure that everyone understands that ASM is not a label for all sorts of solutions that we can name as ASM. I know that this sounds a bit complicated, but in the market, especially from the vendor side, there is still no consensus on the naming of it. So some platforms name themselves EASM, for example.
Some, they say, we are doing exposure management. Some say that we are doing trend landscape management. But what we understand from ASM is, as long as you provide one or combination, or all of these four solutions listed on the left-hand side, which are Chasm, EASM, Digital Risk Protection, DRP, and Third-Party Risk Management, TPRM solutions, then you are working on the logic of ASM, which is actually very simple in a sense, because their workflows are always the same. You start with discovery, then you assess, and you prioritize, and then you remedy.
So each of these subcategories or subcomponents, however you name it, has the same approach to managing your assets and dealing with your vulnerabilities and proactively remediating them before you are already hit by the threats and vulnerabilities around there that might affect your business. So what is Chasm? This is a particular solution that could be, from my point of view, maybe where ASM started, because it is focusing on creating a unified and updated inventory of cyber assets.
And there are some still vendors, they still call themselves as asset management, but they are doing similar tasks to Chasm solutions. And what these two solutions do is, they ingest data from discovery tools, or they discover the assets, and then they can utilize the data from configuration management databases, or vulnerability scanners, or endpoint agents. And what is important about these solutions is that they can operate both on-premises and in the cloud. And if your organization is heavily focused on on-premises, then you should consider these solutions.
The second one is EASM, which is external attack surface management. And these solutions are basically focused on identifying your internet-facing assets, more like your digital assets. And then there are mostly SaaS solutions, SaaS-based solutions, and then they try to identify the assets in your website, in your domains, in your subdomains, shadow IT, or your cloud services, or APIs. The third ones are a bit going into the specific direction.
Actually, number three and number four, DRP and TPRM are more specific solutions, and they are mostly offered as part of Chasm or EASM. There are some also standalone DRP and TPRM solutions, but I noticed that it is always a good idea to combine these two with Chasm and EASM. So what DRP does is, they monitor your brand reputation. This is basically similar to brand protection.
What they do is, they scan dark and deep web, social media, instant messaging apps, forums, marketplaces, or any illegal activity for searching if your brand is exposed to an impersonation attack, or if your executives, your employees' credentials are leaked, or if you have any clone assets circling around the dark deep web level. TPRM tools is one of the things that we need the most nowadays, in my point of view, because they help you identify the risks coming from the external vendors and your service providers.
This is something that I will elaborate later on, but TPRM tools are a very good tool, a very helpful tool to secure your digital self-made chain. The whys, why do you need it, is because you need a situational awareness about your assets and then your users, like I told you already, and then you need to understand these assets and then the vulnerabilities that might arise from them in relation to your business context.
So you need to be able to relate them to your standing, where you stand in the market, in your industry, and then what you have to do, and then what you have to be careful the most. Third-party risk mitigation is again similar to the third-party risk management I already discussed, but your organization is not only the one that you are responsible nowadays, your assets, but you also have to secure your supply chain and then also the risk arising from there.
Overall, the ASM solution increases your security posture and then it is, ASM is not the only solution that you are probably using, so you have to make sure that it is orchestrating with your other tools such as ITSM or SOAR. So it is sometimes a complementary tool to your overall cybersecurity strategy, especially if you're a large organization. So as I said, the workflow of the ASM is pretty simple.
Discovery, assessment, prioritization, and remediation. So in the left-hand side, you'll see I listed the core capabilities in that order as well. So you have to discover your assets, you have to discover the misconfiguration in your cloud environments, you have to check if you're exposed to any shadow IT tracks, and in the dark deep web, for example, you can search if any of the credentials your company associated with is exposed, and you also have to identify if there are any vulnerabilities related to these assets you have.
And then what you do is you map them, and then you try to have a comprehensive view of your attack surface. And then you try to assess them doing a risk analysis. Try to understand what is most relevant to you and what is least relevant to you. Sometimes you end up having false positives, right? And then you try to understand what is important to your organization, maybe to your organizational culture, or maybe to industry standards. So also similar to your industry and also where you are coming from geographically, you also have to check if you are complying with regulations.
So once these are all checked, discovered, assessed, what you do is you prioritize. And then how you prioritize is mostly done by risk score generation. So we have EPSS, we have CVSS, or we have KIPP catalogs to help you, to help cybersecurity vendors to prioritize those risks.
However, in some cases, these are staying in the generic level, in my point of view. So some vendors are helping you with their propriety mechanisms, risk scoring mechanisms, to make those risks more relevant and more understanding for you. And then what happens next is very simple. You alert the relevant stakeholders, you prioritize your alerts again, and then you remediate. The remediation is the most important part of ASM tools nowadays because this is something that they are still trying to improve because they are not in the level of other remediation tools around there.
And I believe if ASM tools come to a certain threshold, and then if they provide a good level of recommendation, they can be an industry standard in all geolocations. Innovative capabilities, as I already discussed with the dark web monitoring, they help you actually enrich this workflow, discovery assessments, prioritization, and remediation. Let's take cyber threat intelligence, for example. This is probably one of the most important capabilities of ASM tools. Some does not really provide it out of the box.
Sometimes they provide connectors to the third-party feeds, and this helps you attribute the threats and enrich them with the contexts that are relevant to you. And the rest of the list is automation, the remediation, and also utilizing AI and ML to actually make this process faster and more secure. So when I was trying to observe the market, I also tried to understand what are the drivers, which are why organizations need ASM, and the market highlights what ASM vendors are offering in response to those needs. This can be also explained as what customers expect from these vendors.
So sophisticated cyber threats, as we discovered, because then you need to have a sophisticated solution to manage them. And your attack surface is expanding. You all have to deal with the regulatory compliance, and most organizations want to see a proactive cybersecurity mentality, and then they are searching for a vendor providing this. And ASM is most of the time your answer. And some highlights from the vendors. These are very objective highlights. These are the observations that I had when I was doing my research.
This highlight doesn't mean that this is the perfect ASM way to approach the ASM, or let's say what we have to really expect from vendors. But now this is what is available now in the market. So let me just go through them. So as I said, I did the research back in 2023, so there were more focus on on-premises, but this year I see a shift to our SaaS-based delivery. The landscape is being shaped by large cybersecurity vendors incorporating ASM into their broader platform offerings. IBM and Google did that recently. There are some ASM startups, particularly in Europe.
They are very solid solutions, but I would say that there is still a chance to enter this market. But I am not sure about the United States, but there might be still a chance for those who are operating in Europe, because the most startups I saw were located in Europe. The primary buyers of ASM are coming from finance, healthcare, manufacturing, and the public about regulatory compliance. The four subcategories of ASM is EASM, CASM, TPRM, and DRP. And vendors are offering either one of them, or a combination of them, or all of them.
And of course, vendors offering all of them doesn't mean they are the best, because then you also need to do your, as a vendor, you have to bring these capabilities in a certain level. Sometimes it just stays in the tech level, let's say. They just say that we deliver DRP, but they don't really do it. From customer point of view, they are most concerned with the remediation, and the second one is a good risk scoring mechanism.
And since they are most concerned with the remediation, and most ASM solutions does not really deliver good remediation, so you have to make sure that the ASM solution you're considering to acquire is integrating with ITSM, SIEM, or SOAR platforms, so that you don't worry about the remediation. So, this was my insights from the market.
Now, I'm going to quickly go through my key findings, so that you can kind of have my verdicts from the report. But before that, we have our second poll question. I give you 10 seconds to answer that. How has your organization's cybersecurity budget changed this year compared to last year? It grew significantly, grew slightly, and remained stable, decreased by more than 5%. All right.
So, if you'll let me, I'm going to read this section, because I think that it is important to understand every point discussed here. So, this is actually my ASM report in a nutshell.
So, the modern attack surface has expanded significantly due to cloud adoption, mobile devices, APIs, IoT and OT devices, and remote working practices. A proactive approach to cybersecurity that combines asset discovery, risk assessment, and threat intelligence is essential. And if you understand, actually, this tree is the unification of asset management, vulnerability management, and threat intelligence platforms, which means a modern ASM, actually.
So, if you're familiar with these three tools, then you understand that ASM is trying to unify these three solutions in short. Ad-hoc vectors such as ransomware, phishing, malware, cloud misconfiguration, and especially zero-day vulnerabilities are growing in variety and volume.
AI, ML, and behavioral analytics enhance ASM platforms by empowering automation. And one of the most important findings is remediation capabilities are central to effective ASM and are consistently cited as a top customer priority.
So, this is my finding for the ASM vendors who are maybe interested in hearing the feedback from their customer. So, some solutions, as I said, for customers, their number one priority is the remediation, but some solutions have strong mechanisms and algorithms for risk scoring.
So, this is actually the second most important concerns of customers, because it is very essential for them to reduce the false positive, because then you don't want to deal with the alert fatigue, and then you don't want to deal with what is not really relevant to you. Vendors are integrating Gen-AI into their ASM solutions to support tasks such as building queries, generating remediation suggestions, and automating risk assessment.
But I have to be honest that the use of Gen-AI is still in the early stages, and I have seen very limited use of agentic AI in the ASM market, just to keep in mind. Last but not least, TPRM and digital software supply chain security remain a challenge for many vendors.
Yeah, many solutions are still lacking TPRM capabilities, and then they have, let's say, they should have a better focus on TPRM, because I see that this is something that needs to be addressed in the market from the vendor's point of view. So, now that I'm done with the key findings, I would like to briefly highlight how we do a research at Coppinger Cole, and as I said, this is standard to every research we do at Coppinger Cole, not limited to ASM.
So, but again, before we start, we have another poll question. I always forget our poll questions. What is the biggest challenge when implementing cybersecurity?
Budget, skills shortage, wrong tool choice, and stakeholder management? Please take your time to answer. All right.
So, what do we do as analysts is that we try to identify vendors first when we begin with the reports, like for example, for ASM report, I try to see which vendors are eligible, they are qualified, they bring, they deliver the certain core capabilities, and then I make a list of them, and then we reach out to them, and then once we have their consent, then we send them our questionnaires. These are very detailed questionnaires, sometimes around 300 to 600 questions, including standard and margin is noting.
Apparently, he was the one answering my questions, and I'm really bored, but this is one of the, let's say, most solid source we use as a company to analyze vendors, and on top of that, we do the briefings where we also have the live demo of the product, and of course, we use documentations that are available on vendor's website, and then we analyze all the information we have, and we write the first draft of the report, and we send it to all the participating vendors.
In this, when in this report, we had 20 vendors, so I received all of their feedback in the fact-check period, and for example, if they have any updates, or if I, if there's any challenge I list for them, and in this, in this, from the research time to fact-check period, if they address any of these challenges I listed, for example, then they can come and tell me that, Osman, we have now patched this, or we no longer have this, this problem as a challenge, so could you please remove it, or could you please take a look at our press release?
So this is, this is the fact-check period, and this is around like two, three weeks period, and then I receive the final feedback from them in this, in this period, and I consolidate them with the first draft, and finally, we publish the report. So this four-stage process is taking around six months to complete, so you should keep in mind that this is a very long process, and we are spending a lot of hours as a research challenge company, and also vendors are also putting lots of effort to provide as much information to us, and then we try to be as accurate as possible.
This is, for example, a simple, a sample spider chart that we used in ASM market. This is not standard to every LC we are using. You'll see in the left-hand side, we have eight evaluation criteria, and these are specific to ASM market, and you'll see that they are all related to what I covered so far, maybe excluding architecture, because that is more about the platform capabilities, not ASM itself only. So you see that asset discovery and identification, vulnerability monitoring, CTI, digital risk management, risk prioritization, remediation, and attack factor coverage.
So these were my eight evaluation criteria that I mapped the questionnaire towards when I received the answers. And based on these eight criteria, we also mapped them against security, functionality, deployment, interoperability, usability, innovation, market, and ecosystem, and financial strength. I'm going to skip this part very quickly because this was the last report that I used these dimensions. We are no longer going to elaborate on these dimensions, but we used to do this. So you see that the security is mostly related to the platform security, not the security ASM is providing.
Functionality is purely the subject of, related to the subject of the research, which is ASM, and the other things are pretty easy to understand, I believe. And in this page, we have more like the corporate information about a vendor, where they stand in the market, their financial strength, and then their partners, and then their system integrators, and then their overall partner ecosystem. And in this page, you see the vendors that are rated in the LC-ASM.
We had advanced cyber defense systems, Armistice, BishopFox, BitSight, CrowdStrike, Psycognito, Dedectify, 4Seeds, 14Net, Adrian, Ionix, Ivanti, JupyterOne, Kela, LionGuard, Outpost24, Qualys, Rapid7, ThreatNG, and VidSecure. So these vendors are from the different places of the world, from Europe, from Asia, from United States, and they all are eligible to be rated in my report. That means that they are all good solutions, but of course, there is a difference between them, and then their also focuses are different. So please check out their website if you're interested in any of them.
And if possible, please read our report or license it to see the deeper insights from each of these vendors. And these are the vendors that we contacted, but did not really do a deeper analysis. So if you're interested, please check this slide deck later on once it's available offline, so you can also consider these solutions as well. So in our leadership compasses, we have four different kinds of leadership, and product leadership, market leadership, innovation leadership, and a combination of these three overall leadership.
So today, I'm going to share our all leadership chart for the LC-ASM. You see that we have the leaders, challengers, and followers. I will only name the oral leaders for the sake of time.
Qualys, Armys, CrowdStrike, Psycognito, Fortinet, Rapid7, BitSight, Outpost24, and Kela were rated as the overall leaders in ASM market in 2025. So yeah, if you're interested, we will also share the link of the report and also a buyer's compass that we provide for the customers who are interested in learning more about ASM and how to procure it, and then what to be careful in the procurement process.
So yeah, this was it from my side. Martin, sorry for making you wait for 30 minutes, but I think it's always a good idea to give an overall view of the market, and then maybe some of our audience does not really understand everything about ASM, which is completely normal, and maybe they don't have an ASM tool in the place yet. So maybe you can all start introducing yourself and then maybe tell us, if they don't have any ASM tool, why they should consider Outpost24 instead of other solutions.
All right, thank you for the presentation and introduction. Much like when we look to briefings and market reviews, there is a difference. As you mentioned, you use 300 questions to evaluate the different stakeholders. I've been working with which some of them use as low as 40 when they do their evaluation. So essentially, what you take into things, they differ. If we look to Outpost24, we come from a background on vulnerability management. That's our roots, and as you mentioned, that's one of the pillars going into what forms ASM today in many of the offerings.
In the case of Outpost24, we come from a background where we did vulnerability management, and we could see that customers, they would struggle to fix all the issues identified. So we moved from talking about vulnerabilities to solutions to their problems, like these are the things you need to go out and fix. We come from the European markets. There was no real legislation driving vulnerability management yet. So we had to be very useful compared to many of the US vendors, where if you're on the stock market, you need to do vulnerability management. So there you had to pick an option.
Here we were competing with no action or using us. For these customers, they started working with like, you need to go to this version of a web server, for example, for having all the vulnerabilities. That helped them for a period of time, but there's so many attacks that are growing, the amount of IT assets is growing, and it became a problem again.
That's where we started in our end, implementing threat intelligence into the prioritizations, because if we know that Russian or Middle Eastern hackers are targeting a vulnerability in an organization, that means that's the first thing you need to fix. So we came from that end, and for years, that worked quite nicely for our customers, but then we could see again that there were customers who struggled with security, who suffered breaches, and they weren't suffering these breaches due to ignoring results in most cases.
Some did, of course, but in most cases, it was because there is a natural shortcoming in vulnerability management as a base philosophy, and that's that you tell the scanner what you own, and it will tell you what's wrong with it. But in the modern organization, most organizations are not aware what they own, what they host, and what they expose anymore, and that meant we had a challenge we had to tackle.
So that's why we entered into the ASM space, because we need our customers to remain secure, and the way we're doing that is helping them find out what they need to be auditing and what they need to be fixing, and the EASM is a very core element in that. Could you maybe remind me your story from starting from the SweepHatic site, because I remember when I did the report in 2023, I worked with SweepHatic. It's a company, by the way, Alpha24 acquired in the last years, and it was like a media core solution, and now when you put your strengths together, you've become a market leader.
Maybe would you like to elaborate why that happened, and then how did you actually unify your strengths together? So the place we come from is, we've been a pure play moment management vendor. We picked up a pure play threat intelligence vendor, a pure play cloud security posture management, and a pure play EASM platform, SweepHatic, and that means that when we look to the different products within our portfolio, each of them are very strong in a limited area.
We haven't tried to be very wide and shallow, so today we have, I mean, we've been able to move from being able to fingerprint some thousand vulnerabilities in the SweepHatic platform to supporting more than 270,000 vulnerabilities when we look to that.
We've gone from, depending on the CISA CEVs list, from priority to having our own threat intelligence team, which infiltrate Russian hacker groups on the dark web, to have our own threat intelligence on what they're targeting, what vulnerabilities they're discussing, and what exports they're trading, and this, of course, makes an immense difference.
I mean, just things like protocol support, being able to bring in a vulnerability scanner that's been around since 2001, and bringing that knowledge into the EASM space, of course, meant that they had access to a completely different set of base technology to marry with the discovery features and prioritization features they already had. I think that it's really good that you mentioned about your threat intelligence team.
Maybe, could you maybe also maybe give us some information how they operate? Because in the market, as far as I noticed, there are three ways to approach cyber threat intelligence when integrating them into your EASM solutions. The number one is you have a small group, a small internal group of people that are maybe ethical hackers located in different places on earth, and then they help you identify what's going on, and they provide you threat intelligence.
The second one is that you are actually trying to come up with your own threat intelligence platform, again, backed up by some team, of course, but then you have a deeper focus, and then you, for example, scan the dark deep web, and then you provide connectors to, for example, Interpol, Europol, so you are actually collaborating with other big threat intelligence platforms, like, for example, Recorded Feature. And then the third option is that you have none of them, and then you're just providing connectors, so like a chance for your users to utilize CTI.
So what is your approach to CTI, and then how do you help your customers with that, make them utilize it? So we live in the second option in this case. We come from a background where we were working heavily focused on threat intelligence. We had malware analysis, and we're working close with some national security services that fledged into a platform where we needed to stop monitoring their presence on the dark web, the different groups we were tracking. So we built an extensive platform which monitors several hundreds of different sources by automation.
On top of that is a team of reverse engineers and infiltrators who work close to these groups. They are also the ones who analyze the data, so we can look on data on when something was discussed and how probable it is that this will result in exploitation.
So it's, you know, that there is an EPSS scoring. We have something we call farsight scoring, which is similar in base philosophy, but it's based on threat intelligence data as well as vendor prior scoring and EPSS weighting in here. But we have our own platform and our own team, and we generate our own threat intelligence. We used to integrate another organization, Threat Intelligence, but there were shortcomings. When you do not control the roadmaps, that means that the threat intelligence you produce isn't really applicable to your core customer base.
So a pure threat intel company will not be focusing just on the bits that fits in an ASM solution. So we know that we focus a lot on, for example, breached passwords. We monitor stealer networks where we can see as credentials get stolen by these groups or when they are trading them, when they're and then take this information and apply it to the attack surface information we have. So we would know, for example, if any credentials related to your main domain is getting included here, but we will also see if, for example, your customers who's on your platform.
So if you're running an e-commerce platform, we would see as these groups are stealing the passwords and usernames of your customers, and that's a possibility of moving in and getting rid of these problems before you're subject to fraud, for example. All right, so I was actually wondering, also, if you looked at my slide, that this subcategories of ASM is a concept that I came up with after working on it like three years. Do you agree with me on this approach? And if you agree, what sub-components does Outposts24 provides? And then maybe you can tell us what areas you still need to improve.
So the sub-components, that is... Let me remind you, CASM, EASM, TPRM and DRP solutions, third-party risk management and digital protection.
Exactly, and I agree on almost all of them, apart from that, and with all respect, I have very low respect for third-party risk management, mainly because it's looking on something from the outside. It's the best you can do, and you should always do the best you can do, but this is still judging your business partners based on the front of their office buildings. If you do third-party risk management where you scan somebody from the internet without them being involved, it's going to be very shallow.
When you move into it, like specialist vendors do, where you do reviews of their policies and so on, then it starts to have an effect, and it's more efficient than having every organization run their own audits, it's one or two audits is the thing. It's very interesting here, actually, because some vendors are claiming that they do third-party scanning, so it's beyond fourth-fifth party. Yes. So what's your take on this? Just marketing?
My main problem there is that having used these solutions myself, both prior in my career, but now also as representing a vendor, I know that I can adjust my scoring very, very easily on these platforms by adjusting the things I'm aware that they are looking at, and that do not correspond to being secure, no more than having a range of security certificate. It says it has a base hygiene, but beyond that, it's not a very in-depth element.
It's still, if it's the best you can do, it's the best you can do, but for your critical vendors, you need to look closer when using these platforms and solutions. And most of the time, the third-party risk, it doesn't come in the form like they have a bad website, and therefore, it's a problem for me. It's they have someone who's really lazy as an engineer, and they use remote management to get to my networks, and they deploy systems there with passwords.
We've seen this when we've been helping our clients where one of them had white-labeled VPN endpoints for more than 70 of their different office sites, and they're all just rebranded other organizations' VPN devices, which were unmaintained. It was immediate group access to these networks for us, and that, of course, matters, but you want to see these things because that's not on their networks. They're on your networks, and they're an effect of their malpractice in these cases.
So, using third-party risk management, it's effective when they go not for the scanning, but for the actual auditing and provide an accurate view and results. So, platforms where you will push out, forcing somebody to go through their security processes, and that is good for the business, for anybody in the industry, because that allows you to not have to have any auditing of everybody you trust.
I mean, as an online organization, you will have hundreds of vendors. If you could go to a company which provides third-party risk management, and they've done audits over them, that saves a lot of time, but you really need to have a good solution there, and third-party risk management by an EASM perspective, like external scanning, that's way too shallow for what we need. All right.
So, I was actually also wondering one more thing that you mentioned that you are a European vendor, and you are located in Sweden, right, if I'm not wrong? Correct. Yeah.
So, and then the Spearbatic was from Belgium. So, you have a very European focus on the EASM. Do you think that this is an advantage for you? And considering the adoption rates of solutions, which are always ending up North America being number one, what could you offer them as a European company? The North Americans? Yeah. Quality. I'm going to be rude and state that. The problem on the US market at the moment is it's oversaturated with organizations compared to the workforce. If you look to things like the amount of security engineers available on that market, it's a huge shortage.
It's why getting services from an organization like EU is a managed service key by the function and not by the product in many cases, because there won't be enough security engineers everywhere. It's a shared resource, just like the third-party risk management is dependent on an auditor auditing many, many organizations and others benefiting from that. It's the same thing when you look to a solution provider that provides, for example, managed penetration testing or managed services for a platform there.
And if we look to that market, just comparing something that's easy for me to compare, you would look on the cost levels for doing a penetration test. That's a few years back. You have the pen testing as a service, right?
Yeah, we do. Now, we've been doing that since 2015 for web applications.
So, in those cases, we move in with a... Today, you would start with the ASM scan and you find things you prioritize and based on what's most critical to your organization, the most critical ones, you transition into our team to configure the scanning, the alerting, but also move in and do recurrent penetration testing.
So, you have human-level testing and then you can just interact throughout the ASM platform and toolings we have. And your team can talk to our team and get feedback when you do patching.
And so, you can just ask them, did my patch in pre-production fix issues? And they can go through that and interact. It's the same thing here with a shared staff pool, essentially.
So, you get access to an extremely skilled application security team without having them in your team, but through the tools, you can just interact with them as if they were on a different floor in your building, which works out nicely. Now, the reason this impacts America negatively is that somewhere you have a pain point where you won't be able to spend more on a penetration test and that's happened. And what we can see is when you start comparing the offers between a European organization and American organization are often quite similar on the euros or dollars.
But when you look under the hood and the work descriptions, we're now in a point where the US organizations to remain competitive, they've started to tune down the amount of days they're usually spending on a test when they're involving humans. So, when you look for a European solution, most of the time, we come with a background where automation is key. We don't have huge security teams.
So, the tools must be efficient. And the tools we build are from my experience, I've been a customer of Outpost and other before I joined 13 years back. It's essentially very much focused on automations and driving process. There's no point in selling somebody a tool where they need to hire four people to make it work for you, because most European organizations would not. They are happy to bring in a tool which makes the guys in the security team more efficient or the IT department more efficient, but they wouldn't be thrilled to stop trying to build a new security team. All right.
So, let's imagine that as a customer, we are considering investing in an ASM solution. This is more like a general question for you. What key factors do you think that I should keep in mind during the procurement process? And then I want like, what should be aware of? And then why should I be careful? And what should I focus after the deployments? Yeah.
So, if we start with the first one, what you should be looking out for, it's that you pick the tool you need. That might sound very natural, but if you would be thinking about something else, it would make perfect sense if we're talking about the hardware tool that needs to be fit for its purpose. And as you said prior, the definition of an ASM tool today is relatively loose. And you need, for most who are trying to do ASM for increased security, you need something that has good product coverage. It should have good automations.
So, when you configured it, it should just keep working. It should find new things, it should categorize them, it should alert you if strange things happen. It should have a low overall level of false positives, because you can't spend too much time neither on finding strange domains that aren't yours. Along with my statement, this was like the number second concern of customers. Yeah. And I can imagine that one of the things, the first thing actually, we spent effort on building AI and machine learning into the platforms for, that were to give a probability rating of ownership.
So, we can see, for example, you're sharing names of structures or anything that gives us a correlation, shows us a technology, anything that gives a stronger correlation that drives a probability of ownership, we can push them to the top. When you attempt to watch something, it should always be the most likely things that belongs to you that you can confirm and shift over, because that gives a substantially better signal-to-noise ratio. That's important, especially with a tool like an ASM solution. Anybody can make an ASM solution that finds anything, but that will just be...
Sorry, we have somebody in the chat trying to connect. I got distracted by the message there. But the main thing is that it must be running quite frequently as well, because we can look on traditional providers, especially those who came from third-party risk management and shift into ASM or EASM. Some of these ones, the lapse from when something is found in the platform until a change you make in infrastructure is picked up is up to 90 days.
That does not work if you're trying to do this to drive identification of new risk and change in your if you're trying to find out the exposure of your organization. If you have to wait 90 days before that's known, that's way beyond the average time for exposing something vulnerable to exploitation.
So, the most critical things would be run near real-time and other elements. Depending on how invasive they are, like full port scans, where you need to spend a lot of effort and put quite a bit of load, those run less frequently, of course, because you can't push an organization over to find out what they're using either. But is it really realistic to think that ASM can do this all by itself? For example, you were talking about real-time scannings and everything, and also an automated remediation, for example, which is very difficult. It's really hard to find in a vendor.
So, my question would be, what integrations do we need to get a full visibility of our tech surface? Because, again, even if you have an ASM solution, then maybe it might not be delivering all those sub-components I listed. And you need to have some native integrations, and maybe you can already mention what are the most important integrations for Outposts 24, for example.
I mean, for us, it's the most deployment-to-date hybrid, and it's a quick new thing, and that's the cloud integrations. Instead of looking for what you have running in the cloud, which you, of course, also do, you're just giving us access to pull that information and getting very accurate data immediately.
It's, of course, more efficient. The same thing, but the main thing is integrations with ticketing and ITSM tools.
So, ServiceNow, for example, JIRA, anything like that, because you can't have a system that is dependent on a user logging in and reading the recommendations for things to happen. They should, the security analysts, to ask the questions, the data can help them answer or find questions by looking on the data that they're interested in, but the day-to-day work that needs to function through the integrations.
Otherwise, it won't ever work out. And this is kind of, when you mentioned what you should focus on when you're doing the implementation, this is also one of these central things. If there's something you need to do, big or small, get it done or don't start at all.
I mean, it's a saying, and this holds very true here. And if you just start the tool, do discovery, and then you start working with the results, you're not done and you will not be successful. You should do the deployment, you should do the filtering, you should do the events and the alerting, regardless of what product you choose, because the product must feed into your existing processes in the organization. Preferably, it shouldn't force you to make new processes, it should function with what you have.
So, relatively open integrations and set it up to drive the things that needs to happen when something is detected and picked up on that platform. If you don't drive it all that way, you will never be successful in using the solutions.
Yeah, and similar to integration, I think the orchestration of the tools are also very important. The ones that are already existing and were coming from a single vendor.
So, when we think about Outposts24, what other additional capabilities or services do you provide, other than ASM, maybe to provide a better protection for the attack surfaces and also overall cybersecurity strategies? Yeah, so the main tool suites, not the former eASM solution, now the ASM solution, that one integrates into our existing vulnerability management suites. You can push things there to get scanning started, you can pull results, you can pull assets back from them, and those are, of course, important to go more in-depth.
eASM is predominantly a discovery tooling, whilst the vulnerability management comes with the web application scannings. We're also a DAST provider and manage DAST or also using a hybrid delivery with people involved as well. We have the threat intelligence solution.
They come from what used to be the organization BlueLib, seated down in Spain, and these solutions have boiled over and are now the social monitoring, so we can, for example, track a CEO, so there is not popping up false profiles of them on LinkedIn or other social media platforms, mentions on X or anything else that's relevant there. And same thing with orchestrating dark web monitoring directly from within the eASM solution, so you can start tracking your brand or domains or specific technologies you're using.
Data loss prevention, same thing here, not as in prevention, but data loss detection, so we can see if it's on sharing sites, if it's created on the dark web, if it's on file sharing sites, if there's uploads on different platforms we support.
But I think for the audience here, the most unexpected bit from our end is that we work quite heavily in more active directory connected security as well, and that's not deeply integrated into the eASM suites, but we have within our group a spec of software which specializes in things like ensuring that the day you hire someone, they can be provided their username and password, they can do an initial password setup without having to go to an office using multi-factor authentication needs, and we can block them from using known bad passwords, but also pick up when hackers are starting to use passwords in their password spraying attacks, and that's going into the product there which is called seem to be breached passwords.
So we have a range of solutions in this space, especially the resets solutions which allows users to self-service multi-factor authenticate to provide a password reset for their domain, that can be anything down to your manager authenticated and confirming you are the one performing this. So that comes from a different side of the business, but it covers from our bit, we went after all the aspects of cloud application infrastructure network and users data. So the data loss detection and the darkroom, that's tied to the data track, and this is for us the user track.
They are not one yet, but they're moving in that direction of course. That's a very extensive set of capabilities and other services I would say. So because we have only one minute left, so I would like to ask one last question if you could maybe summarize it. So out of this huge list of additional capabilities on top of ASM, if someone is interested in the managed service, which areas or of these capabilities you can actually provide? Like which capabilities can be provided as managed service? If you can just summarize it quickly.
So as managed service, you can pick up either application security programs, which will run through the Stafford prioritization categorization, setting up the scanning and doing the reporting with your teams. You can get the managed EASM with configuration alerting, all the things you just instead of doing the deployment, we just do it for you. Same thing for vulnerability management, we can either do deployment or just sell it as function instead. That's perfect. I think this is also an opportunity for those who are considering to acquire ASM as a managed service. But thank you so much Martin.
It was a lot of information and I'm happy to discuss all this with you. I think that you have a very solid solution. You're a leader in the market and I would also like to thank Outpost 24 for making this webinar possible. Would you like to say any final words? I would say thank you for having us. And as mentioned, it's a pleasure being ranked a leader and not just a leader, but a leader in so far the most thorough review we had from the many analysts.
Yeah, likewise here. We appreciate that. And from our end, the webinar is finally coming to an end. But ASM is gonna be on our agenda for the upcoming months and years. We will have two events coming up soon. One of them is in Munich and then another one is in Frankfurt. I will probably have a section around ASM in Frankfurt November 6th. So please sign up and join us there if you can, or you can just virtually join us. And stay tuned for more updates from Covinger Call and Outpost 24 if you're interested in ASM. Thank you so much for joining today and have a good day and evening. Bye-bye.
Thank you all.
See All Locations
See All Locations