The Importance of Asset Context in Attack Surface Management.


This is the last of the four blogs (Help, I can’t see! A Primer for Attack Surface Management Blog Series, The Main Components of an Attack Surface Management (ASM) Strategy, and Understanding your Attack Surface: Different Approaches to Asset Discovery) covering the foundational elements of Attack Surface Management (ASM), and this topic covers one of the main drivers for ASM and why companies are investing in it, the context it delivers to inform better security decision making.

Read more…
Source: Rapid7


Sign up for our Newsletter


Related:

  • Patch Tuesday – September 2025

    September 10, 2025

    Microsoft is addressing 176 vulnerabilities today, which seems like a lot, and it is. Curiously, Microsoft’s own Security Update Guide (SUG) for September 2025 Patch Tuesday only lists 86 vulns, and that’s because the SUG doesn’t include a large number of open source software (OSS) fixes published today as part of updates for Azure Linux ...

  • Poland to receive new European Union’s SAFE loans programme to boost cyber defence among other capabilities

    September 9, 2025

    Poland will receive EUR 43.7 billion in low-interest loans from the European Union’s new SAFE programme to boost defence capabilities, Deputy Prime Minister and Defence Minister Władysław Kosiniak-Kamysz said on Tuesday, confirming earlier reports. Calling the decision “a historic success,” Kosiniak-Kamysz said the funds will guarantee continued investment in Poland’s security and defence, including air and ...

  • Germany: Cyber Security in Road Transport 2025

    September 8, 2025

    Information technology has been part of modern vehicles for a long time already: connected services, AI-based assistants and over-the-air updates are standard in many vehicle models – and with autonomous driving functions the complexity grows further. Cyber security is of essential importance for these technologies. The publication offers a compact overview of the main challenges and ...

  • An Earth-Shattering Kaboom: Bringing a Physical ICS Penetration Testing Environment to Life (Part 2)

    September 2, 2025

    This is the second in a three-part series on building and using a testing bench for Industrial Control Systems (ICS). In this series, Rapi7 researchers will build a physical test bench, review program logic to find flaws, perform manual exploitation of commonly used ICS protocols such as Modbus, then develop malware to automatically exploit the bench ...

  • WhatsApp fixes ‘zero-click’ bug used to hack Apple users with spyware

    August 29, 2025

    WhatsApp said on Friday that it fixed a security bug in its iOS and Mac apps that was being used to stealthily hack into the Apple devices of “specific targeted users.” The Meta-owned messaging app giant said in its security advisory that it fixed the vulnerability, known officially as CVE-2025-55177, which was used alongside a separate ...

  • Free webinar exploring the future of cyber security in critical industries

    August 28, 2025

    On 5 September 2025, cyber security professionals and industry leaders will gather online for a free, expert-led webinar: “Securing systems, data, and people: What are cyber security experts’ concerns for the future?”. This session serves as a precursor to the IET’s Cyber Security for Critical Industries Conference 2025, offering attendees a valuable glimpse into the ...