EASM Checklist for Small Businesses (12 Steps)
What are the 12 steps of the EASM checklist?
Work through each step in order. Every item is one action.
- List every domain you own — include marketing microsites, retired brands, and regional variants.
- Discover all subdomains — enumerate subdomains for each domain to surface forgotten services.
- Find shadow IT and cloud services — identify internet-facing assets no central list captured; see shadow IT.
- Map exposed services and open ports — record which TCP ports and services are reachable from the internet.
- Check for exposed admin panels — flag any login or admin panel that should not be publicly reachable.
- Validate TLS certificates — check for expired, self-signed, or weak certificates on every host.
- Review HTTP security headers — confirm HSTS, CSP, and X-Frame-Options are present where they should be.
- Verify email authentication — check SPF, DKIM, and DMARC to prevent domain spoofing.
- Scan for known CVEs — test discovered services against known vulnerabilities.
- Check for breached credentials — look for exposed employee credentials tied to your domains.
- Set up continuous monitoring — schedule at least monthly (ideally weekly or continuous) rescans so new exposures surface fast.
- Assign remediation ownership — give every finding a named owner and a deadline so issues actually get fixed.
How do you action this checklist without a security team?
Of the 12 steps, only two genuinely need human judgement — listing domains (step 1) and assigning ownership (step 12). The rest are technical checks that automation handles well. The UK National Cyber Security Centre (NCSC) recommends that smaller organisations lean on automated, well-supported tooling rather than trying to build deep in-house expertise, which is exactly the model this checklist assumes.
The payoff of automating step 11 in particular: with continuous external monitoring, a new exposure — a certificate about to expire, an admin panel that appeared after a deploy — surfaces within days, whereas a business relying on an annual review can leave the same exposure open for months.
How SurfaceLoop handles this
SurfaceLoop automates the discovery and scanning steps of this checklist from a single root domain — discovering subdomains and shadow IT, then checking everything it finds across seven scan categories including open ports, admin panels, TLS, security headers, email authentication, and known CVEs, with continuous monitoring and plain-English findings. Start a 14-day free trial on your own domains — no card, no sales call.
See External Attack Surface Management feature →For the full discipline behind the checklist, see the pillar on external attack surface management, and for tailored guidance read EASM for small business.
Frequently asked questions
- What should be on an EASM checklist for a small business? +
- A small business EASM checklist should cover: listing all domains, discovering subdomains, finding shadow IT and cloud services, checking open ports, reviewing exposed admin panels, validating TLS certificates, checking security headers, verifying SPF/DKIM/DMARC, scanning for known CVEs, checking for breached credentials, setting up continuous monitoring, and assigning ownership for remediation.
- How often should a small business run an EASM scan? +
- A small business should run a full external attack surface scan at least monthly, and ideally weekly or continuously, because internet-facing assets change constantly as services are added and certificates expire. Continuous monitoring is preferable to periodic scans because it catches new exposures -- such as a newly exposed admin panel -- within days rather than months.
- Can a small business do EASM without a security team? +
- Yes. A small business can perform EASM without a dedicated security team by using a self-service EASM platform that automates discovery and testing and explains findings in plain language. The checklist steps that require manual effort -- listing domains and assigning remediation ownership -- are within reach of any small team, and the technical scanning is automated.
- What is the first step in EASM for a small business? +
- The first step in EASM for a small business is to list every domain the organisation owns, including marketing microsites, old brands, and regional variants. Discovery of subdomains and services builds on that domain list, so an incomplete list of root domains leaves blind spots that later scanning cannot cover.
Get SurfaceLoop security briefings
No spam, just findings that matter. Fortnightly.