About EASMLens

Last updated 28 September 2026

EASMLens shows organisations what they expose to the internet, the way an attacker would see it, without touching their systems. It is built and operated by Security Solution Consultants, a cyber security and GRC advisory firm headquartered in Sydney, Australia, with a regional office in Auckland, New Zealand.

We built EASMLens because the same question kept coming up with our advisory clients across Australia, New Zealand, the Pacific, South East Asia and the Gulf: what do we actually have on the internet, and who is looking after it? Asset registers rarely answer it. Regulators increasingly ask it.

What EASMLens does

EASMLens discovers the domains, subdomains, IP addresses, certificates, cloud services and APIs attributed to an organisation, and assesses their exposure: known vulnerabilities on exposed services, end-of-life software, weak TLS, and email domain security across SPF, DKIM, DMARC, MTA-STS, TLS-RPT, DNSSEC and more. It refreshes that picture continuously and alerts when something new or risky appears.

How EASMLens looks at your estate

EASMLens works in two layers. Discovery is passive: it builds the picture of what you own from DNS, certificate transparency logs, internet-wide scan datasets and other public records. It then runs non-destructive active checks against the assets in your scope, such as service detection and web server checks, and grades email domain security. It never attempts to exploit a vulnerability, and it is not a penetration testing or managed SOC service. It makes sure those services are pointed at everything that is actually exposed.

Because active checks send ordinary network requests to your internet-facing systems, you should only include assets your organisation owns or is authorised to test. Tell us if a regulator or contract in your market sets rules on this, and we will work through scope with you.

Accuracy first

Security buyers are poorly served by vendor content that overstates regulation. Our country guides cite primary sources, say when something is a proposal rather than law, and correct claims that are widely repeated but wrong. Where a requirement cannot be verified from a public source, we say so.

Where we work

We work with organisations in Australia, New Zealand, Fiji, Tonga, Papua New Guinea, Indonesia, Malaysia, Singapore, the United Arab Emirates, Saudi Arabia, Oman, Bahrain, Kuwait, Qatar, Pakistan, Bangladesh and the United Kingdom, directly and through partners.

Part of a wider practice

Security Solution Consultants also builds GRCLens, a governance, risk and compliance platform used to run frameworks such as ISO/IEC 27001, NCA ECC and the Essential Eight. EASMLens evidence can feed those programmes directly.