Attack Surface Management (ASM) is a continuous process that involves identifying, assessing, and proactively securing an organization's assets to close security gaps before attackers can exploit them.
ASM includes four core areas: 1) External Attack Surface Management (EASM), which identifies internet-facing assets such as domains, IP addresses, and applications; 2) Cyber Asset Attack Surface Management (CAASM), which focuses on internal and external assets, as well as cloud resources and misconfigurations; 3) Third-Party Risk Management (TPRM), which examines supply chain risks inherited from vendors, partners, and subsidiaries; and 4) Digital Risk Protection (DRP), which tracks external threats, such as phishing domains, social media impersonation, leaked credentials, and brand abuse. Together, these capabilities provide security teams with an attacker's view of their environment and help them understand their vulnerabilities and prioritize issues proactively.
In 2025, ASM is no longer just about visibility. Organizations need solutions that provide context, prioritization, and remediation to stay ahead of emerging threats. This webinar explores why continuous, ownership-aware discovery is becoming a baseline requirement and how industry trends are pushing cybersecurity strategies toward risk-based, attacker-perspective approaches.
Osman, Research Analyst at KuppingerCole, will share key insights from the latest Leadership Compass on ASM. He will discuss how the market is evolving and what sets leaders in this field apart. Additionally, he will explain why risk mapping is becoming a key capability for vendors and how it contributes to effective remediation strategies.
Rob Gurzeev, Co-Founder and CEO at CyCognito, will share the company’s perspective as one of the leaders in the KuppingerCole Leadership Compass. He will outline how continuous, ownership-aware discovery helps close blind spots, why surface scans fall short, and how attacker-first strategies shape the future of ASM. He will also highlight why CyCognito is recognized as one of the most innovative vendors in the ASM market and demonstrate the capabilities that set it apart.
Hi everyone, my name is Osman Celik and I'm a Research Analyst at KuppingerCole. Today I'm joined by Rob Gurzeev from CyCognito. He is the Co-Founder and the CEO of CyCognito.
Hi Rob, how are you doing? Hey Osman, great to be here. Nice to see you. So today we are going to have the webinar around From Discovery to Remediation, the 2025 Landscape for Attack Surface Management. And now that we are reaching at the end of 2025, at the end of the webinar, we can also try to talk about what to expect in 2026. But before we start, let me do some housekeeping here for our audience. So you're centrally muted, so you don't have to control your audio. And throughout the webinar, we are going to have a couple of poll questions, to be exact, three poll questions.
We really encourage you to participate in those. Maybe if time allows us, maybe we are going to share the results and discuss them as well. So in order to do that, you will see in the right-hand side, a panel where you see apps, people, polls, and questions, and chat functionalities. So when we are asking you to answer the poll question, please use the poll tab to answer the questions. And whenever you have questions, please raise your questions in the chat button or the question button. All of them are fine for us. And we will discuss this at the end of our webinar.
For those of you who are not with us live today, we are recording the presentation, and also the slide decks will be shared with you, and you can download them as long as you wish to have them. So I briefly explained today's agenda. I recently worked on a leadership compass on a tax service management. I worked with 20 different vendors. I determined the leaders in different categories, and I made analysis for the market and also the vendors specifically. I determined what are the challenges, what are the required capabilities, how does ASM work, and then why do we need it.
And then I also briefly shared what is the status in the markets in terms of financial figures, acquisitions, and et cetera. And then at the end of this, at the end of my part, I will also share my key findings from the overall research, and I think that should be like the summary of my 100-page long report. So please stay tuned, and maybe if you have any questions about the key findings, you're more than welcome to ask me any questions. And then afterwards, Rob will start with his part, and then he's going to explain what Psycognito offers us.
And in the last 15 minutes approximately, we are going to have a Q&A session. Please ask your questions as I encouraged you in the beginning. Starting with our first poll question, does your organization have an ASM solution in place today? It's basically yes and no, and yeah, we are considering it in the evaluation proof of concept phase question. Take your time to answer it. So as I said, at the end of last May 2025, I released this Leadership Compassionate Tax Service Management. It was the second edition of this report.
As Coppinger call analysts, I've been working on this market since 2023, and it was nice to see what is changing in the second year and what vendors are offering differently than the first year when we did it back in 2023. Let's start with some challenges why organizations need ASM, what CISOs are dealing today, and one of the biggest issues for me is that many organizations are still relying on reactive cybersecurity measures, therefore the solutions.
So if we are going to address the threats only after an incident occurred, then it will definitely result in some significant downtimes or the remediation cost, and ultimately we'll either lose our data or our operations will be disrupted or our reputation will be harmed. So instead of being reactive, a tax service management tool is a starting point, I would say, to stay on the proactive side. Second thing is that the tax services are expanding. Now we are using a lot of IoT sensors, we are using lots of APIs in our programs, and so on.
In the modern businesses, we need some scalability and automation for our businesses. The number of users are changing depending on how well our organization is performing, and managing them manually is impractical. So we need some solutions that can be scaled and also can be automated as well. Our infrastructure is consisting of modern and legacy systems, especially in the bigger organizations we see this more often, so infrastructures are complex. So a single panel solution is more preferred today, and of course, switching to them also requires some digitalization process.
So ASM is also a solution that you should consider when you don't want to deal with this complexity. You can have a SaaS solution basically, and they can be easily deployed, and then they can be ready for performing in a couple of hours today. And one of the most important things for me here is, and also most of the CISOs would agree with me, that the attack vectors are being much more sophisticated than what they have been.
And a good detection tool, and also a good proactive tool, would really help us leverage some protection against that, and also some tools are also enabling us to use AI against AI, so that's a good thing. And the other three challenges I would say that is applying to any other cybersecurity solution out there. We have lots of business partners that force us to be careful about the third-party supply chain risks, and we don't want to have the legacy solutions that are barely helping us with the modern threats, and also most of us here are obliged to comply with the regulations.
And ASM solutions can help you overcome all of these hassles actually, in a nutshell. But how does ASM work, and why do you need it? To begin with, I would like to explain how I see the ASM markets.
For me, after working two years in this market, I have determined that there are mainly four subcategories in ASM market. The chasm, that is focusing on a unified, updated inventory of the cyber assets. These tools basically, most of the time, ingest data from the discovery tools, CMDBs, and vulnerability scanners, or endpoint agents. They operate both in on-premises and in cloud specifically. The second category is EASM.
These are the tools that are best for identifying internet-facing assets, more like external assets, such as your domains, your websites, your shadow IT, your cloud services, APIs, etc., and your subsidiaries as well. And the third category is digital risk protection. This is more on the brand protection side, and it also is a combination of threat intelligence plus brand protection.
So these solutions are designed to monitor dark deep web, social media, forum sites, and also some illegal marketplaces to see if your brand is mentioned, or your executive or employee accounts are mentioned there, if you have any leaked credentials, or an insider threat, or anything else around your brand or your organization.
Lastly, the third-party risk management, TPRM, tools are specifically designed for monitoring risk associated with your supply chain risk, your third-party risks, and these are the tools that are scanning your external vendors, your business partners, and service providers to see if they are at the risk of being targeted by cybercriminals, or if they have any vulnerabilities going on in their systems. So these tools are also part of a broader ASM landscape in our understanding. And what do they bring to the table?
Situational awareness, business context, when you are especially working with threat intelligence, then you know that it is relevant to your organization or not, should you be prioritizing this threat or not. And third-party risk mitigation, and your security posture enhancement, and also more really important, again, orchestration with other tools, because ASM is also a complementary tool from our, from my understanding, to your overall cybersecurity strategy. You can integrate with your ITSM or SOAR tools to make things orchestrating better.
And in the left-hand side, you see the newest six pillars, the last govern, the govern pillar has been recently added by NIST. So now it's not five, but six, six main pillars of a successful cybersecurity program by NIST. And similar to these six pillars, in my understanding, ASM works on these four pillars in terms of workflow, discovery, assessment, prioritization, and remediation. Sometimes this can change, some vendors say that, okay, we also do validation, we also do, let's say, recovery and respond differently.
But, you know, in a sense, these are the four pillars of the market. When I look at the, when I look at the vendors providing this ASM, an ASM solution. So discovery, assessment, prioritization, and remediation is what we expect from an ASM tool to conduct. And based on these four pillars, we determine core and innovative capabilities. And here you see the list of them.
So to mention a couple of them, so a must have capabilities we should list as the core capabilities, like asset discovery, misconfiguration discovery, shadow IT detection, or in the other side of the vulnerability identification, also risk scoring. Then the, once you find out what assets you have and discover all the known and unknown assets, then you also, you identify the vulnerabilities and more importantly, you map those in your attack surface, and then you try to contextualize them. And then where it begins, where you start prioritizing them.
And this is done by the help of risk score generation. Every vendor has its own unique way, in some cases, to generate this risk scoring. And this is something that also customers are also very interested into to get to know, because for us nowadays, one of the most important thing is to have less false positives, right? So they want to understand if the risks that are listed in the ASM solution is really relevant to them.
And lastly, of course, we have talked about the remediation, and it starts with alerting and reporting to the relevant stakeholders, and the ASM solution should at least provide some guidance and recommendation to the remediation. Some solutions out there also are now providing some automated remediation tools, and they look solid, and it's really promising. But I think that as of 2025, we cannot really expect an ASM solution to provide this. But maybe in the next years, it's going to change.
And last but not least, customers care about the remediation the most based on the research we conducted. So we could say that remediation is number one concern, and the second one is the risk score generation for end users. And the other side, we also have to mention a couple of innovative capabilities. These are the capabilities that not every vendor provides, but these are being offered by various vendors in the market. Not only the vendors I analyzed, but also the other big vendors out there that I mentioned in the vendors to watch list, which you can see in my report.
So these capabilities are now is, let's say, are not must to have, but it is nice to have, and once they are well integrated to ASM, then they are making you future proof. Some of them are like digital risk protection and TPRM. I already told you that these are the subcategories, but I do not expect every vendor to provide this. And on top of that, I expect at least a solution that is providing connectors to CTI, for example, that monitoring and so on. In this chart, you'll see this was a sample from a vendor.
Actually, this is a result from our leadership compass. We did not disclose the vendor's name, but here you see when we do the vendor analysis, we actually do the analysis around these eight main pillars, which we call them spider charts, and they are asset discovery and identification, vulnerability monitoring, cyber threat intelligence, digital risk management, risk prioritization, remediation, attack vector coverage, and architecture of the platform. So we try to score and rate vendors and analyze them around these eight pillars, and this could be what a vendor look like.
Actually, this is, as I said, a real result from the LC, but I'm not going to disclose the name of the vendor. And in this one, in this leadership compass, we determine the leaders, and our sponsoring, our supporting vendor today, Psycognito, was listed as the number one innovative leader vendor in the market. And this leadership matrix is based on the evaluation of innovative features that we discussed earlier, or the services on the technical approaches.
We discussed this in the required capability sections a minute ago, and based on this, Psycognito was the leader in the market in terms of innovation. And you can see the other vendors as well. So enough of vendors. I think that I would like to also share with you my findings from the market and also the overall findings from the ASM solution and vendors and the market altogether. So what are the market drivers? As we already discussed that the sophisticated cybertrust, the cyber criminals leveraging AI, puts us under a need of a modern solution.
So ASM is one of them, as I said, and it could be also complementary to your overall cybersecurity strategy. The attack surfaces are expanding, and then we are all subject to the regulatory compliances, especially if you are operating in the critical infrastructure verticals. And most importantly, I guess, as of 2025, we have no other choice than being proactive in cybersecurity. And some market highlights, I would like to read them because I think they're important.
So the market continues to move forward to a SaaS-based delivery because it was kind of mixed in 2023, but I see that more vendors are switching to SaaS-based now. And when we look at the vendor landscape, it is mostly dominated by the large cybersecurity vendors, and they incorporate ASM tools into their broader platform, and then they try to all these solutions together. And some smaller startups are preferring the modular structure. They have different models that are making up the ASM. Some startups are from Europe, especially we also analyze them in our report.
If you're curious to know, please read the report. And the primary buyers of ASM solutions operate in finance, healthcare, fine manufacturing, and the public sector. But on top of that, I could say that when I analyze the vendors, I could say that the industry coverage is very broad, not only limited to this. I just wanted to mention here the primary buyers. But if you're operating out of these sectors, I would really still encourage you to check what ASM is and how it can help you with So why is it important to mention the subcategories?
Because there is still no consensus on naming the attack surface markets, attack surface management markets. Some solutions call themselves exposure management. Some call themselves EASM. So I did not want people to get lost in this abbreviation world. So if you want to take a look at all the subcategories, you will see that they are actually serving for different purposes. But at the end of the day, ASM vendors or exposure management or threat landscape management tools, whatever their names, are offering either at least one of them or a combination of them or all of these four categories.
Yeah, again, the customers are most concerned with the remediation capabilities. And the second one, please don't forget risk score generation. And to draw a conclusion, you also need to expect that the ASM solutions must provide some third party integration, especially with ITSM scene and SOAR platforms.
All right, so these were the highlights from the market. So I would like to also share some key findings of my entire research. So the modern attack surface has expanded significantly due to cloud adoption and mobile devices, APIs, and IoT, like we discussed. And a proactive approach to cybersecurity is actually like a combination of asset management tools. If you have any solution around this, you will know what asset management tool is. You'll know what is the vulnerability management tool, or you'll also know what's threat intelligence platforms are.
So a combination of these three is actually a modern ASM. If you already have these three tools, then you can at least know what to expect from the ASM. So it's a combination of these three. Attack vectors, such as ransomware, phishing, malware, cloud misconfiguration, and zero-day vulnerabilities are growing in variety and volume. And most of the solutions out there are not going to help you mitigate those, but ASM is going to provide you an all-in-one solution, if you ask my opinion.
AI, ML, and behavioral analytics enhance ASM platforms by empowering predictive modeling and automation. This is a critical part of the ASM engines, or let's say the ASMs, the brains. So if you have a solution utilizing AI, ML, and behavioral analytics, that is easier to correlate and also contextualize the threats, and then that's going to save up a lot of time, and you will have a functioning automated tool. Remediation capabilities are central to effective ASM, are consistently cited as a top customer priority.
Automated risk-scoring health organizations manage the high volume of false positives and focus attention on the vulnerabilities that can be exploited. Some vendors are now trying to integrate also a gen AI and also a gentic AI to their ASM solutions, but to be honest, they are still in development phase. I haven't seen any very, let's say, solid tool out there that is actually providing a gentic AI in an ASM, but I think that we should start expecting vendors providing such capabilities in the next report, hopefully at the end of 2026, where we will publish.
TPRM digital software supply chain security is still a challenge for many vendors. So these were the main findings of the report. I hope that you find them useful, and if you have any questions, please reach out to me, and then I can provide you more information, more insights if necessary. Before handing over to Rob, I would like to ask also my second poll question. How well is your Please answer to this question, as long as you have already an ASM platform in your organization. Very effective, works, but not very effective, and the last answer is doesn't work for us.
Please take your time to answer this, and here I hand it over to Rob. Thank you, Osman. Great discussion there, Osman, and feel free, by the way, to chime in on this piece where we double-click and zoom in on the number one innovator there on that graph, which is Psycognito in general, and then most of what we want to discuss here is what good looks like, or even what kind of KPIs in a vendor-agnostic way are useful to evaluate when you're wondering, hey, why is my program not working well enough? Maybe I'm seeing too many false positives. Maybe I'm still seeing too many blind spots.
Maybe I don't know what to focus on. So, the goal for the next few minutes is to talk about how to evaluate your own program and where you might want to go with it.
So, very briefly about Psycognito as a company, we help 20-something of the global 100 companies and many, many others, including small organizations, with specifically understanding how attackers see your external exposure and identifying the few critical exploitable attack paths from the outside in. To do that, to achieve that, we have three main capabilities. Number one, a very deep attack surface management capability, which is directly related, of course, to what we talked about.
Secondly, autonomous black box security testing, or pentesting, that includes vulnerability scanning, pentesting modules, and dynamic application security testing capabilities, and an exploit intelligence product and capabilities that contextualize each attack vector with which threat actors are exploiting this right now in the wild. Now, talking about the top challenges we see in attack surface management, and especially external attack surface management, which I would carefully say is the much more challenging part than aggregating internal IPs and standard simple IP assets.
Number one, lack of context and unified risk context. When you have many subsidiaries and networks and a diverse tech stack, it's becoming extremely hard to answer questions like, where is my PII exposure to the internet? Or across all of my subsidiaries and business units, do I have these Citrix net scaler or F5 big IP, whatever, that is now being attacked by China or Russia or this group?
Secondly, testing coverage is one of the most or least understood elements, I believe, in the industry right now. I think that's changing, and that's why we're talking about it too, where not enough organizations have been asking themselves, hey, how many of our applications, assets, what have you, are we actually pen testing? Or we have these wonderful security controls, what technology process, other things do we have in place to help us identify gaps in our CNAP, Zero Trust, whatever problems? We'll see some examples of such big critical gaps in a minute.
And then in cloud security, that's a big problem in general, and especially with regard to the two other areas of blind spots and areas that are not covered at all, and lack of testing within cloud environments. When talking about exposure management, we like to split it to two parts. Some don't. I actually believe it's incredibly important. You have the outside-in perspective that attackers have, and that should be unbiased and represent what attackers see.
And then you have the more common inside-out perspective, where you use integrations or API calls to enumerate what your security controls and other solutions like a ServiceNow see. Of course, everyone needs both perspectives. And I would say that now it's October 2025. In October 2025, the inside-out piece, I think, is well done by many enterprises. I don't know about most. The outside-in perspective, however, I think, is still a huge challenge for the vast majority of organizations.
Now, the question I love most in this regard is, okay, how do I measure success in this area? What are some KPIs we should consider?
So, number one, so these are four we developed with our customers. And as you can see, it's completely vendor-agnostic.
So, the number one KPI is, of course, what percentage of my assets do I even know about? One way to measure it is by inviting someone like Psycognito that has a seedless black box capability that will tell you what Psycognito sees, for example, and you would be able to compare that with what you have on your ServiceNow or Exonius or what your TPRM tells you. Another way that they also like is looking at the last 30 incidents that you had in the company and assessing what percentage of those last 30 incidents are related to unknown or even under-managed assets.
So, that can give you that answer quickly and effectively. The next two elements, as I mentioned, are, I believe, we need to discuss the more as an industry, put it that way, and it relates to penetration testing and dynamic application security testing, meaning how do we test in production the stuff that our company actually runs on? And we have coverage and cadence.
So, if we have 10,000 websites or 1,000 websites exposed to the internet, including DevOps and everything there is, what percentage of that is actually being tested at all? And what most folks figure out when they ask this question, they learn that, oh, we're actually testing just 10%, 20%, 30% of our FQDNs and websites. Which is the great tool that we all love, but we're really covering just 10% of that, our pen testing service. And they would say, oh, and our pen test is really annual, and we run dynamic application security testing, for the most part, every quarter or once a year.
So, now you could easily argue, hey, our mean time to detect is 12 months or three months. And that brings us to the last KPI, which is, in a sense, the most important, which is the end-to-end mean time to remediate and how long the dwell time is from the moment the issue is created, brought to the world, and until it's remediated. It's not very meaningful to measure that based on, for example, geotickets only, because what if this issue has been dwelling for a year, right?
So, that's where you want that to be in the days for critical issues, ideally hours, and you need that whole stack to work well. So, these are the KPIs I would recommend every organization to look at with regard to exposure management. Features are cool, but this is what truly matters. And now we'll talk about a few perspectives and critical capabilities in our view that can take you there and can help you assess how close or far away you are from that. A couple of examples from the psychognitive side, very, very quickly.
Number one, if we take the cloud exposure and cloud visibility perspective, for example, we want to know how, you know, if we have these 100 subsidiaries and business units, which ones are exposing the most cloud assets to the internet, and who are the two or three or five business units out of the 100 that are generating most of the cloud risk. We also want to compare the cloud exposure with what our WIS or CSPM or CNAP are showing us. And that's the visibility portion. On the testing side, this is an example of how we want to test every single asset.
For example, it's not very meaningful in our view to simply enumerate open ports. It's popular, done since the 90s, but just not very effective and valuable. What you probably want to do, if you can, is to test actively every single asset, every single day, or at least week, to tell not just, hey, we have 1,000 open SSH ports to the internet, but to say, hey, here is the one that is using weak credentials that any even unsophisticated attacker, you know, would be allowed here to become an admin in our network. That's where the value really is.
And you want probably a technology to do that for you, not manual pen testing on one or 10 or 20% of the assets once in a while. We were talking about mean time to remediation and how do we cut MTTR for critical risks to just hours or days. When we're being asked about that question, some people think about, oh, automated remediation is probably the way to go. That's probably the future. And I agree it's the medium long-term future. And in cloud, for example, that's way easier than in some other contexts.
However, the number one element that hinders organizations from cutting their MTTR significantly seems to be based off our research and our customers is prioritization. Most vulnerability management tools, I will not mention any names because it doesn't matter. It's pretty hundreds and hundreds of thousands of critical issues in the enterprise. When I have 1,000 critical issues as a CEO in whatever area, unfortunately, I'm unaware of such things, but there isn't much you can do about 1,000 problems, especially if you can remediate maybe 50 per month effectively and quickly.
So we believe it's all about prioritization and, of course, evidence and the backing of it. But you can see some examples here of how even some of the most biggest organizations in terms of attack surface in pharmaceutical manufacturing and media, Fortune 100 companies, how when you prioritize attack vectors and issues based on is it discoverable by attackers? Is it attractive to attackers? Is it an important asset based on heuristics? And is it exploitable? You validate it and you say, is it exploitable?
So with that approach and technology, you can get to just a single digit number of criticals, even if you're a Fortune 100 company. So that was not possible until a couple of years ago. For some organizations, this still looks like science fiction, but it's completely doable today. That's what I believe we should all strive for and something that our team will be happy to discuss with folks who care about it, which is hopefully everyone.
Next, another topic that is near and dear to my heart, and I also believe there's a lot of around that in general, is what does asset discovery mean? Myself and many of our team members have spent years in intelligence agencies where targets of intelligence agencies can be organizations like ISIS or Boko Haram. And when your target is Boko Haram, for example, as an intelligence agency, you can simply ask them, hey, would you mind sharing with us your IP ranges and FQDNs, and why don't you actually deploy these agents in your whatever too?
So you have to do real reconnaissance to find that path of least resistance that is so, so valuable. The problem is that when you're building an attack surface management or external attack surface management technology, it's so much easier on every level to simply tell your customers and security teams, hey, why don't you give us your IP ranges? That's how it's been done since the 90s. What can go wrong? And the problem is most tough to find and important blind spots are not, especially in 2025, are not in the known IP ranges.
They're in the edges, they're coming from acquisitions, they're coming from third party assets that store your data and that attackers can actually find. And you all know that. So the difference between real discovery that starts with no prior knowledge and assumptions and still discovers the full attack surface is the only way we know to find those tough to find and important blind spots. And one should be very careful with the lazy approach that is extremely common, yet extremely dangerous.
Now, if you're looking at how can I tell and what difference does it make? So number one, one area of difference is do you even understand the organization structure of the company as the correlate each asset to its owner and not based on what's on ServiceNow or a tool like that, because they don't have that knowledge for many assets. But can you use real technology to map the organization structure and find these complex discovery paths? In some cases, we're talking about 15 different hops between corporate, the big company, and these random web applications and cloud resources, etc, etc.
Here, and we just saw what this looks like on Cyclognito. Below on this slide, we can we can see what a common attack surface management tool looks like in this regard, where one you have to feed it with your own assets. And then if you're looking at some random IP, for example, you can absolutely not tell how it's related to your company. In so many cases, if not almost all of them. A couple of other angles on this very quickly. And then I see that we got some questions from our crowd here. So we'll get to these in a couple of minutes.
One more example or important angle on how they manage my exposure is validating that the security controls even work that they're even deploying the capability. For example, we built validates tests and challenges all of your applications for web application firewalls to help you identify where you have applications that are production applications that impact your revenue, but are not protected by your web. And just like everything else we do, by the way, we don't need any input deployment configuration inclusion listing nothing to do it just like real attackers, which is the whole point.
For example, we will tell you this portion is not protected at all. And here are the technologies you do have in place and some changes you want might want to make.
Here, the same concept with zero trust, extremely important. And again, requires one deep discovery and number two, active testing of all assets to identify and identify things like this leading some would say, well, let's keep it that leading network security, huge vendor was sort of protecting this fortune 100 company, but five out of the 71 sassy egress points were actually vulnerable and attackers could access internal assets and IoT services through the egress point. So you're paying so many millions of dollars on a security solution that actually creates risk.
Problem is, if you're not pen testing, or discovering and pen testing all of these external exposures all the time, how are you going to find this by applying basic logic? Okay, next, moving to some of the biggest challenges folks have an exposure management, which is dynamic IPs moving around a huge problem, especially on cloud and modern assets. That's where number one, you want deep fingerprinting of the assets. And then another thing we've recently built, and we're I think it's in alpha right now, but will be soon released is dynamic IPs anchoring.
If now, maybe the number one challenge in this area for folks is false positives that are a result of not being able to anchor dynamic assets, it is really hard and it requires heuristics. Port scanning and port scanning data modeling is not close to being enough. So that's one of the biggest pen points many folks have and a critical area and a critical capability to track this. A couple of other critical elements you want to consider, how much context do I have on the assets that I am seeing? As I mentioned earlier, do I know where the PII is within all of these assets?
Can I tell where my APIs are? And again, I want a technology that can tell me that not just rely on existing knowledge that I don't have or not completely have. We talked about autonomous pen testing a little bit. This expands on it some more. I will quickly say, so we have time for Q&A, that if the testing capability requires either deployment configuration or a lot of inclusion listing, like standard vulnerability scanners, the end result is testing just 30 to 80% of the assets, depending on the security control or the scanner. And then risk simply accumulates where you're not looking.
So many folks now shift more and more dollars from standard legacy pen testing and bug bounty programs to autonomous pen testing that can cover all assets and test them every day or every week, which just logically is, I believe, where the industry should be. DAST is a specific use case here for that. And jumping to the very last piece here, I just wanted to share a couple of very exciting things we're working on.
Number one, AI exposure management, meaning new capabilities to identify AI resources and assets and MCPs and data sets and things like that that are exposed across your full enterprise. Also completely black box, huge concern for so many organizations these days. The second area that is related, although very different in nature, is AI insights, like where's my attack surface going? Why is this subsidiary having its attack surface grown by 80%? Is that an acquisition they made? Is that something else they did? I'm excited about this webinar and thank you, Osman, for putting this together.
And since we have some questions from the crowd here, happy to move there. Yeah, it was actually interesting to see, especially for me, the last part of it really aligned with how I also predict the future.
Yeah, we covered 2025 landscape, but also if time allows, maybe we can also talk about the 2026, what to expect from it. And then maybe you would also like to share a couple of opinions there. Before we move on to questions, I asked the last poll question of today. What is the biggest challenge in your ASM program today? False positives, lack of risk prioritization, and lack of integrations.
So, Rob, I think that you deserve the glass of water. And then let's see what our audience is saying. Maybe we can already start with the polls.
So, let's see what our audience said today. So, the first question was, if your organization have an ASM solution in place today? And half of our audience didn't have one.
It's good, because then I think that we had from beginner to advanced level information for everyone joining today, for those who need to get familiar with ASM as well. And 30% is actively deploying it. The second question was, if they are happy with their ASM platform, if it's performing well or not? 75% of them said that it works, but not very effective. No one said that it's very effective. 25% said that it doesn't work for us. Interesting results. And the biggest challenge, the last question we just asked.
So, the biggest challenge of the ASM program today is lack of risk prioritization and the lack of integration. They both got 50% of the votes. No one really complained about false positives. I don't know if it's the case really, but would you like to say anything around it? Especially, I'm curious what you would like to say.
Almost 75, no one is happy with their ASM program today. At least 75% of the people participating today said that it works for us, but it's not really very effective. Would you like to say anything about this, Rob?
Yeah, that doesn't surprise me. I think that exposure management is very challenging to succeed with. And I think that there are so many popular ways to attack the problem that, for example, integrate really well, look very nice, blah, blah, blah. But when you look at the KPIs I shared earlier, which are, again, completely vendor agnostic, you're seeing that you're still in the orange. Versus the green. If I don't have active security testing of all assets, I will not be able to prioritize very well.
If false positives is a big problem, and on average, customers tell us that they wasted 10 hours per single net new asset just to understand what is it, who owns it, what is this thing, then it simply cannot work. And I think we're still early as an industry in our understanding of such KPIs or agreeing on what these KPIs should be. But I'm a huge believer in that and in the approach of challenging the existing vendors and set up and evaluating solutions this way versus looking at shiny objects and single specific examples of a single finding. Yeah.
Yeah, I also agree with what you just said. And I would like to also contribute to it with a couple of points I remember from my research.
So yeah, I think that our audience today did not really elaborate on the false positives, but I think it's a major thing. And this is one of the main drivers of the automated tools today. And we don't want to really analyze everything one by one. We don't have the human resources. We all the time talk about cybersecurity skills gap. And we need to have some tools that are addressing, that are showing us the right direction without putting, making us detours, right? So we need to have some tools that are intelligent enough to contextualize the threats.
We are not expecting something that is not warning us based on some assumptions, but we would like to see the alerts there, but we would like to see them highlighted when it's really relevant to us. Because then at the end of the day, we would like to have things under control. I think this is a human instinct. We don't want to yet let AI to control everything and decide, yes, this is irrelevant to you or this is not. But I think that we would like to be informed, but we would like to be alerted. This is a different word than informed.
Alerted when it's very necessary to be alerted and then informed about. So the other things I can also say a couple of words.
Yeah, the risk prioritization. If you remember in the report, in my report, it was the number two, the second most concerned topic for the end users. I'm not surprised. And lack of integrations is also very important because I think that we want something orchestrating with the rest of our cybersecurity tools stack. Especially if you are a larger enterprise, we have on-premises, we have SaaS, and we have also subsidiaries that we have spread across the different geopolitical regions. And then we have lots of infrastructure to make sure that they orchestrate all together.
Therefore, we rely on very different tools. And also, I think that some tools are also custom-made or internal tools that we also need to make sure that we have the right tools, right integration material, right APIs to integrate and also not to also mess up with our IT infrastructure. So ASM should not be a hassle in this point. ASM should be one of the contributing factors to integrations and they should work with your must to have other security tools, I think.
Yeah, so we have a couple of more questions. I think we covered enough the poll questions, but I think the last one was really important if you ask my opinion as well. So what are some country-intuitive things security teams learn only after a while of deploying their ASM program? It's an interesting question. What would you like to say about this?
Yeah, happy to start and curious about your thoughts, Osman. I think that many organizations start their journey in attack surface management thinking, if I have a solution in place and it's well integrated with the other solutions, I'll probably be able to solve 80 to 90 percent of the problem or a big chunk of the problem.
And I think that many, many security teams are surprised by, number one, how much false positives they're seeing and how much of their time is burned on fighting these false positives coming from everywhere on the one hand and on the one hand continuing to miss critical assets that lead to incidents eventually despite having a tool in place. And so I think the counter-intuitive thing is in cyber security you're hoping that good enough is good enough in many areas because folks already use dozens of tools in an enterprise.
But I think it's counter-intuitive how in this area because of the combination of false positives, blind spots that are really hard to find, and then prioritization that is broken in general in vulnerability management unless you are validating the risks and have heuristics that tell you what's important because no, again, other solution like ServiceNow has that knowledge on assets, unfortunately. So it's counter-intuitive how big of a problem that is and you're only starting to feel it when you operationalize the program.
You're starting to report on it and someone wants to know, hey, are we reducing our MTTR significantly? And why are we still seeing these random incidents on these DevOps tools and some SaaS platforms and things we didn't know about? Wasn't that supposed to be solved? And why does our tool have zero data about these things?
So yeah, I think that's very counter-intuitive to folks who are building the program for the first time, trying to operationalize it for the first time. Yeah, I think that I agree with you and I would like to also add one more thing. I think one of the, I think if I think about the counter-intuitive things, I would say that the shadow IT discovery is something very important for most of the customers out there, ASM customers. I think that ASM is one of the tools that are allowing you to also scan and also relate your assets to the vulnerabilities and also potential threats.
So it's not only limited to asset management tools, like it's not only scanning your assets, but also it's also making sure that you are actually aware of what might hit you later on. So these are these two things I would say, the shadow IT and also potential threats that might hit you in short and long-term are the counter-intuitive things that security things learn after deploying ASM, I would say. The second question is how do successful ASM programs help with other programs such as EPSAC, cloud security and pentesting? That's another good one.
I would say that a solid attack surface management program can be the foundation or a critical infrastructure to almost everything else in cyber security. So if you think about, for example, we mentioned cloud security, you need this angle to make sure that the CNAP of choice is properly deployed everywhere. And by definition, deployment-based solutions cannot see what they are not covering by definition.
If you're thinking about EPSAC and pentesting and red theming, that's a huge area of value because today's and for 20 years, pentesters and red teamers, they were doing some port scanning, then picking a few assets they would spend a lot of time on. But the way to more and more teams want to do it is use great data on, hey, what's actually every day or every week and focus on those things versus, oh, there's this new completely random engineering project. So this big boss wants us to test it or something.
Okay, but is that where really most of the risk is right now versus we acquired this company two years ago and they have this VPN or update server or something else exposed and exploitable and connected to these internal crown jewels, that is the path of least resistance. That's where I really want to learn that, solve that quickly and guide the organization on what we can learn from it versus we built a new whatever IoT device in the company and now the next couple of years, we should only test that. So it can really guide so many other programs once you can trust this problem.
Well, a couple of points I would like to also elaborate on this. So I think that ASM program could be related to cloud security because we already discussed about misconfigurations and then ASM is one of the tool out there that lets you understand if you have any misconfiguration in the systems. But I would like to also talk about pentesting a bit. I think back in 2023, when I started writing the report, I already knew what's vulnerability management, what is pentesting, what is red teaming, blue teaming, purple teaming, etc.
But what I noticed that people were complaining, okay, we have this pentesting, but it's only running on demand. And sometimes it's scripted and you don't know if cyber criminals will follow the exact path that an ethical hacker will follow. So I actually tend to think that also ASM is kind of like next-gen pentesting. I know pentesting is not a tool, but if you're going to make something next-gen out of something, then it will be pentesting actually. And then I see lots of companies now putting more and more focus on automated pentesting. And I think that this is progress I see.
And then this is maybe also due to the success of ASM exposure management tools. Yeah, I could not agree more, Osman. And customers who experience it see a huge upside from it. And really, why would you want to spend these $200,000 of an annual pentest budget on a once-a-year project that covers 10% of your staff versus splitting it differently so you have a continuous capability that identifies what attackers are most likely to your point to find.
So that's, I think, exactly right. Any final thoughts before we wrap up?
Yeah, I would say it was a great session. I think extremely important session that so many folks out there I know are trying to learn more about the topic.
Hey, why is this not working for us? Where should we aim? How do we measure success in this area?
So, great session. And as always, of course, we would love to talk to folks who want to learn more about SiteCommitter.
Yes, please reach out to Rob or to me if you have any questions. And I think that if I want to wrap up quickly, the most important thing I think in 2025 is finally understanding the importance of proactive mindset, if you ask my opinion. And ASM is one of the tools. Exposure management is one of the tools out there that helps you start with the journey at least. Because then I am sure the most cybersecurity tools out there will adapt this mentality and they won't be reactive anymore.
And I think this is something also that we should expect from 2026 as well to see more and more tools switching to their mindset and being proactive and also trying to understand the cyber criminals mindset because now they have the advantage of using AI but we also have the advantage of country using AI against them. But yes, thank you very much for joining us today. I think it was a great session too and I'm looking forward to see you in the next webinar. Have a good day and evening. Bye-bye.
See All Locations
See All Locations