# Attack Surface Management Program

> From $7.5K / mo · Offensive Security · https://cisomarketplace.services/services/attack-surface-management-program

Continuous discovery, monitoring, and assessment of your organization's external attack surface and digital footprint. Our ongoing service provides real-time visibility into internet-exposed assets, shadow IT, misconfigurations, and newly emerging vulnerabilities, enabling proactive risk reduction before attackers can exploit these weaknesses.

## In scope

- External asset discovery and inventory
- Continuous vulnerability scanning
- Cloud resource monitoring
- Domain and subdomain tracking
- Certificate management
- Shadow IT discovery
- Exposed credentials monitoring
- API security monitoring
- Third-party connection tracking
- Priority alert notifications

## Deliverables

- Real-time attack surface dashboard
- Monthly vulnerability trend reports
- Critical exposure notifications
- Remediation guidance and verification
- Executive risk summaries
- Shadow IT alerts
- Quarterly attack surface reduction plans
- Risk prioritization framework
- Continuous improvement recommendations

## Tiers

### Standard Attack Surface Monitoring: $7.5K / month

Continuous external discovery and vulnerability scanning for up to 5 root domains, up to 250 external IPs and up to 3 cloud accounts. Standard alert rules, critical exposure notifications and one monthly trend report.

Limits: domains 5, external ips 250, cloud accounts 3

Includes:
- Asset discovery and inventory with subdomain tracking
- Continuous external vulnerability scanning
- Certificate and exposed-credential monitoring
- Critical exposure notifications
- Monthly vulnerability trend report

Excludes:
- Custom alert rules and risk scoring
- Analyst-validated findings and remediation verification
- Quarterly attack surface reduction plan
- Penetration testing or exploitation of findings

### Advanced Attack Surface Management: $12.5K / month

Continuous monitoring for up to 15 root domains, up to 1,000 external IPs and up to 10 cloud accounts. Analysts validate findings, rank them by risk, verify fixes, tune custom alerts and deliver a quarterly attack surface reduction plan.

Limits: domains 15, external ips 1000, cloud accounts 10

Includes:
- Everything in Standard at the larger footprint
- Analyst validation and risk-ranked findings
- Remediation guidance and fix verification
- Custom alert rules
- Shadow IT and exposed API monitoring
- Quarterly attack surface reduction plan

Excludes:
- Threat intelligence integration
- Custom risk scoring model
- Named dedicated analyst
- Penetration testing or exploitation of findings

### Enterprise Attack Surface Intelligence: $20K / month

No fixed cap on domains, IPs or cloud accounts; footprint is scoped at onboarding, including subsidiaries and third-party connections. Adds threat intelligence integration, a custom risk scoring model, a named analyst and monthly executive risk summaries.

Includes:
- Footprint scoped at onboarding, no fixed cap
- Subsidiary and third-party connection tracking
- Threat intelligence integration
- Custom risk scoring model
- Named analyst
- Monthly executive risk summary

Excludes:
- Penetration testing or exploitation of findings
- Hands-on remediation in client systems
- Internal network vulnerability scanning

## Terms

Starting price shown is the lowest published tier. A written proposal fixes scope, tier and price before anything is signed. Timeline is set in the SOW.

Scope this engagement: https://cisomarketplace.services/scope?service=attack-surface-management-program
