Attack Surface Management
Attack Surface Management vs Vulnerability Management: Differences
Attack surface management (ASM) discovers and monitors all assets, including unknown ones, from an attacker's perspective. Vulnerability management scans known assets for known vulnerabilities and tracks remediation. ASM answers "what can attackers see?" while VM answers "what's wrong with what we know about?" They're complementary: ASM finds the assets, VM secures them.

Andreas Johansson · Chief Executive Officer
Senior IT management leader with 25 years of experience in Cloud, Security, and Datacenter infrastructure.
Two Complementary Disciplines
Attack surface management and vulnerability management are frequently confused or treated as the same function. They serve different purposes, use different methodologies, and answer different questions — but together provide comprehensive security visibility.
Attack Surface Management
Focus
Discovering and monitoring ALL assets — known and unknown — from an external attacker's perspective.
Key Question
"What can attackers see and target?"
Methodology
- Outside-in discovery (attacker's perspective)
- Continuous asset enumeration across internet, cloud, and network
- Attribution (determining asset ownership)
- Exposure assessment (how accessible is the asset?)
- Shadow IT and unknown asset identification
Scope
- Internet-facing assets (subdomains, servers, APIs)
- Cloud resources across all accounts
- Third-party and vendor assets
- Shadow IT and unauthorized deployments
- DNS, certificates, and public infrastructure
Output
- Complete asset inventory (including previously unknown assets)
- Exposure risk scores
- New asset alerts
- Configuration change tracking
- Attack surface trend analysis
Vulnerability Management
Focus
Identifying and remediating known vulnerabilities in known assets.
Key Question
"What vulnerabilities exist in our systems, and how do we fix them?"
Methodology
- Inside-out scanning of known, inventoried assets
- Comparison against vulnerability databases (CVE, NVD)
- Risk scoring (CVSS, risk-based prioritization)
- Remediation tracking (patching, configuration, compensating controls)
Scope
- Operating system vulnerabilities
- Application vulnerabilities
- Configuration compliance (CIS benchmarks)
- Missing patches
- Weak cryptographic configurations
Output
- Vulnerability reports by severity, asset, and business unit
- Remediation progress tracking
- Compliance status against security benchmarks
- SLA monitoring for remediation timelines
- Risk trending over time
The Gap Between Them
What VM Misses Without ASM
Vulnerability management only covers assets in its scanning scope — typically assets registered in the CMDB or asset inventory. Without ASM, VM misses:
- Unknown assets. Internet-facing assets that aren't in the inventory. These assets are unscanned, unpatched, and represent the highest risk.
- Shadow IT. Cloud resources, SaaS applications, and departmental deployments outside IT's awareness.
- Configuration exposure. VM checks for vulnerabilities in software. ASM identifies exposure through configuration — public databases, open admin panels, and misconfigured access controls.
- Third-party risk. VM scans your assets. ASM can assess the external posture of your vendors and partners.
What ASM Misses Without VM
ASM discovers and assesses exposure from the outside. Without VM, ASM misses:
- Deep vulnerability assessment. ASM identifies that a server runs Apache 2.4.49; VM determines that this version is affected by CVE-2021-41773 and needs patching.
- Internal vulnerabilities. ASM focuses on external exposure; VM covers internal systems, applications, and configurations.
- Remediation tracking. ASM identifies exposure; VM tracks the remediation process through patching, verification, and compliance.
- Compliance benchmarking. VM maps asset configurations against compliance benchmarks (CIS, NIST, PCI DSS).
How They Work Together
The most effective approach integrates both:
- ASM discovers all assets — known and unknown
- Newly discovered assets are automatically added to the VM scanning scope
- VM scans all assets (ASM-discovered + already-known) for vulnerabilities
- ASM provides exposure context that enriches VM prioritization — a vulnerability on an internet-facing, unknown asset is higher priority than the same vulnerability on a documented internal server
- VM tracks remediation of findings from both disciplines
- ASM continuously monitors for new assets and exposure changes
- VM continuously scans for new vulnerabilities across all known assets
Choosing Between Them
- If you can only do one, start with VM for known assets — it addresses known risk with proven processes.
- Add ASM when:
- You suspect significant unknown assets (cloud environments, acquisitions, distributed teams)
- Enterprise customers or compliance requirements demand comprehensive asset awareness
- You've experienced incidents involving unknown or forgotten assets
- Your environment changes rapidly (cloud-native, DevOps, fast-growing)
- Ideally, implement both — ASM to find everything, VM to secure it.
How SeqOps fits
SeqOps covers the cloud and server part of your attack surface: it inventories resources in your connected cloud accounts and flags exposed services and misconfigurations. It doesn't scan the internet for assets you haven't connected.