United Kingdom
Attack Surface Management for UK Organisations
UK certification schemes and regulator guidance all begin with defining the boundary. You cannot scope what you have not found.
What drives attack surface management here
Cyber Essentials and Cyber Essentials Plus
Certification requires you to define the scope of your internet-facing infrastructure and then demonstrate the five technical controls across it. Scoping is where most assessments run into difficulty, because organisations routinely discover services they had forgotten during the assessment itself rather than before it.
NCSC guidance and the Cyber Assessment Framework
The National Cyber Security Centre places asset management at the foundation of the Cyber Assessment Framework, used across UK public sector and critical national infrastructure. Objective A of the CAF concerns managing security risk, and identifying assets is its starting point.
UK GDPR and the ICO
Article 32 requires security appropriate to the risk, and the Information Commissioner has repeatedly cited unpatched or forgotten internet-facing systems in enforcement action. An unknown asset cannot be patched, monitored or included in a risk assessment.
How EASMLens supports these obligations
- Boundary definition for Cyber Essentials scoping, established before the assessor arrives
- Continuous inventory supporting CAF Objective A asset management
- Detection of unpatched and end-of-life internet-facing services
- Certificate and TLS hygiene monitoring across every discovered endpoint
EASMLens supports these obligations with discovery, monitoring and evidence. It does not certify an organisation against any framework, and no product can.
Frequently asked questions
- Will this help us pass Cyber Essentials?
- It addresses the part most organisations get wrong, which is knowing the full scope of internet-facing infrastructure before certification. The technical controls themselves still need implementing, and the certificate is issued by your certification body.
- Do you support UK data residency?
- Tell us your specific requirement and we will confirm exactly what is available rather than answering in generalities.
- How is this different from an annual penetration test?
- A penetration test examines an agreed scope at one point in time. EASMLens continuously discovers what is in scope, including assets that appear between tests, which is where most surprises originate.