Buyer's guide · United Kingdom
External Attack Surface Management: A UK Buyer's Guide for SMEs and MSPs
By Nathan Hill-Haimes · Published 24 September 2026 Updated
On this page
- What is external attack surface management?
- What is EASM not? (vulnerability scanning, DAST, CTEM)
- What does a UK SME or MSP actually need?
- How do you score an EASM vendor?
- What questions should you ask an EASM vendor?
- How is EASM priced, and which model suits you?
- What should a UK buyer check specifically?
- Which tools should a UK SME shortlist?
- How do you run a two-week evaluation?
Disclosure
This guide is published by SurfaceLoop, which sells an EASM product and therefore has a commercial interest in this market. The rubric below is capability-based, several of the vendors named score well against it, and competitor figures are limited to prices those vendors publish themselves, verified as of September 2026.
What is external attack surface management?
External attack surface management is the continuous discovery and monitoring of everything your organisation exposes to the public internet. Your attack surface is the set of points where an attacker can interact with you: apex domains and subdomains, IP addresses and the services listening on them, web applications and admin panels, TLS certificates, and the DNS records that govern your email. EASM builds that list and then keeps checking it.
The word doing the work is discovery. A tool that scans a list you typed in is a scanner. EASM is expected to start from your organisation's public identity -- a domain, a company name, a certificate footprint -- and work outwards to find the staging site nobody decommissioned, the marketing microsite a supplier set up, the router web interface exposed when a firewall rule was changed for a weekend and never changed back. For most UK SMEs the first discovery run is the single most valuable output of the whole exercise, because it is the first time anyone has seen the estate in full.
Everything is done from the outside. No agent on a server, no credentials, no firewall exception, no access to anything internal. That is a capability limit and also the reason EASM is deployable by a small team in an afternoon.
What is EASM not? (vulnerability scanning, DAST, CTEM)
Four adjacent categories get sold as EASM and one gets confused with it constantly. The useful distinction is not the feature list but the question each one answers, and what it needs from you before it can answer anything.
| Category | Question it answers | What it needs from you | What it will not tell you |
|---|---|---|---|
| EASM | What do we expose to the internet, and what is wrong with it? | An unknown estate. Discovery finds assets you did not list. | Anything not reachable from the public internet. |
| Vulnerability management | Which known vulnerabilities exist across our assets, and in what order do we fix them? | A known inventory, usually fed by agents or credentialed scans. | Assets nobody told it about, which is where most SME surprises live. |
| DAST | Can this specific web application be broken by attacking it while it runs? | A named application and often a test account. | Breadth. It goes deep on one app, not wide across an estate. |
| SAST | Does our source code contain insecure patterns? | A code repository. | Everything you did not write, and everything already deployed and forgotten. |
| CTEM | Across all of the above, which exposures actually matter to us this quarter? | A programme, not a tool. EASM is usually one input to it. | Nothing in principle, which is why it is rarely an SME starting point. |
Two practical consequences. First, EASM and vulnerability management are complements, not substitutes, and if you can only run one, run the one that builds its own inventory. Second, CTEM is a programme rather than a product. If a vendor answers "we are a CTEM platform" to the question "do you include discovery on this plan", you have not been answered.
What does a UK SME or MSP actually need?
Enterprise EASM requirement lists are written for organisations with a security team. A UK business of 20 to 200 people, or an MSP carrying thirty such businesses, has a different constraint: whoever operates this tool has another job. That narrows what matters to four things.
1. Discovery at the tier you will actually buy
Entry tiers are where discovery quietly goes missing. Check the plan you are being quoted, not the capability page. The test to apply during a trial: how many assets did it find that were not on your list? If the answer is zero, either your documentation is unusually good or the discovery is not working.
That figure is the argument for looking at all. It is not an argument for any particular vendor: any competent external scan across a cohort of UK SMEs would surface a similar picture, which is rather the point.
2. Output a generalist can act on
A finding that reads "CVE-2023-48795, CVSS 5.9, see advisory" is a research task. A finding that reads "this SSH service accepts a vulnerable key-exchange configuration; update OpenSSH to 9.6 or later, or disable the affected ciphers in sshd_config" is a change request. Same underlying detection, entirely different cost to your Tuesday. Ask to see real findings during the demo and read the remediation field, not the severity badge.
3. No agents, no credentials, no project
External-only scanning should mean you prove you own a domain (usually with a DNS TXT record) and results start arriving. Anything that requires software on servers, a credentialed scanner inside the network, or a paid onboarding engagement has a deployment cost that small teams routinely underestimate and then never finish paying.
4. A price you can put in next year's budget
This is the requirement most often left off the list, and the one that most often ends an EASM subscription in month nine. If the bill is metered by discovered assets, doing the thing you bought the tool for makes the tool more expensive. That is a structural conflict, not a criticism of any particular vendor -- but you should know which model you are signing up to. See the four pricing models below.
And for MSPs specifically
Add three requirements: separate tenants per client under one login, per-client reporting you can send without editing, and a commercial arrangement that lets you include the service in a managed offering rather than reselling a licence at cost. An EASM tool that cannot separate clients is an EASM tool you will operate in spreadsheets.
How do you score an EASM vendor?
Score each criterion 1 to 5 from what you observe in a trial, not from what you are told in a call. Multiply each score by the weight, add them up, and divide by 5 for a mark out of 100. The weights below are tuned for a UK SME or MSP buying its first external monitoring; adjust them and say so in your notes rather than pretending a rubric is objective. If you are an MSP, raise multi-tenancy from 5 to 15 and drop "output a non-specialist can act on" from 15 to 5: your engineers can read a CVE reference, and your clients cannot.
| Criterion | Weight | Scores 5 when | Scores 1 or 2 when |
|---|---|---|---|
| Discovery included at the tier you will actually buy | 20 | Subdomain, certificate-log and DNS-based discovery runs on the entry plan, and newly found assets are scanned without you adding them by hand. | Discovery is an add-on, an enterprise-tier feature, or a one-off onboarding exercise; you type in the hosts you already know. |
| Cost predictability over 12 months | 15 | You can state next year's invoice today. The bill does not move when discovery finds 40 more assets under a domain you already pay for. | Price depends on a metered count you cannot forecast, or the published figure is a base fee with per-target licences bolted on top. |
| Output a non-specialist can act on | 15 | Each finding says what it is, why it matters here, and the specific change to make. A competent generalist fixes it without a translator. | A CVE identifier, a CVSS score and a link to an advisory. Severity without remediation is a to-do list, not a fix. |
| Signal quality and false-positive handling | 15 | Findings are verified before they are raised, duplicates are collapsed, and you can mark a false positive so it stays suppressed on that asset. | Version-banner guesswork raised as confirmed vulnerabilities, and no way to dismiss one permanently. |
| Deployment friction | 10 | External-only. No agents, no credentials, no firewall changes. Ownership is proven with a DNS record and can be revoked. | Agents on servers, a credentialed scanner inside the network, or a professional-services engagement before first results. |
| Coverage breadth across the external surface | 10 | Ports and services, web admin panels, TLS and certificates, HTTP security headers, known CVEs, and DNS and email spoofing controls (SPF, DKIM, DMARC). | Ports only, or web only. Email authentication in particular is often absent and is one of the most commonly misconfigured surfaces. |
| Change tracking and alerting | 5 | The tool tells you what is new, changed or fixed since the last scan, and alerts on new exposure rather than emailing the whole list again. | A fresh full report each time, leaving you to diff it yourself. |
| Evidence you can hand to someone else | 5 | Exportable reports suitable for an insurer, an auditor, a client or a Cyber Essentials assessor, with dates and asset scope on them. | A dashboard with no export, or a PDF that reads as marketing rather than evidence. |
| Multi-tenancy and MSP fit | 5 | Separate client tenants under one login, per-client reporting and billing, and a commercial route to resell or include it in a managed service. | One tenant per subscription, so five clients means five logins and five invoices. |
| Total | 100 | Weighted score = sum of (score × weight) ÷ 5, out of 100. | |
Discovery carries the heaviest weight because it is the capability that distinguishes the category, and because the exposures SMEs are most often surprised by are on assets that were never on an inventory.
Two notes on using the rubric honestly. Anything scoring below 3 on discovery or on cost predictability should be a shortlist exit rather than a deduction, because both are structural and neither improves after purchase. And a total in the 70s is a good outcome: this rubric is written so that several products in this market can reach it, and a vendor scoring 95 against a rubric is usually evidence that the rubric was written by that vendor's marketing team.
What questions should you ask an EASM vendor?
Take these to a demo call and write the answers down. The third column is the useful one: it is not that a bad answer disqualifies a vendor, it is that a bad answer tells you which follow-up question to ask next.
| Question | Why it matters | A bad answer sounds like |
|---|---|---|
| Is asset discovery included on the plan you are quoting me, or is it an upgrade? | Discovery is the whole point of the category. Without it you have bought a scanner for the assets you already knew about. | "Discovery is available on our higher tiers" or "we will run discovery as part of onboarding". |
| What exactly do you count for billing, and what happens the month that count goes up? | Per-asset and per-target models can double an SME bill when discovery does its job, which creates an incentive not to look. | "It depends on your environment" with no unit named, or a refusal to state the overage price. |
| Show me a real finding as my team would receive it. | It is the fastest test of whether output is actionable. Ask for a live example, not a slide. | A screenshot of a severity chart, or a finding whose remediation field is a link to a vendor advisory. |
| How do you verify a finding before raising it, and how do I permanently dismiss a false positive? | Unverified banner-grabbing produces noise, and noise trains a small team to ignore the tool. | "Our scanner is very accurate." No verification step described, no suppression mechanism. |
| How often is an asset rescanned on my plan, and is that a floor or a target? | "Continuous" is used for anything from hourly to monthly. Monthly scanning on a free or entry tier is a real constraint, not a detail. | "Continuously" with no interval attached when pressed. |
| What do you check on DNS and email authentication? | SPF, DKIM and DMARC gaps are cheap to fix, invisible in daily use, and very common. A tool that ignores them misses easy wins. | "That is more of an email security product." |
| Where is my scan data stored and processed, and who is your sub-processor list? | UK buyers with public-sector or regulated clients get asked this in their own supplier questionnaires and need a written answer. | A verbal "it is all in the cloud, it is fine", or no sub-processor list available. |
| How do you authorise scanning, and how do I revoke it? | You are asking a third party to probe your infrastructure. Authorisation should be explicit, scoped and reversible by you. | "Just give us the domains." No ownership verification, no self-service revocation. |
| Can I export findings as evidence, and in what format? | The report often has a second audience: an insurer, a client, an assessor or a board paper. | Screenshots only, or an export available on request from support. |
| What is the full trial, and does it run on my own domains without a card? | A trial on a sandbox domain tells you nothing about your estate. A card-gated trial tells you about their funnel, not their product. | A guided demo described as a trial, or a trial that degrades to a limited free tier mid-evaluation without saying so. |
| What is the contract term, the notice period, and how am I invoiced? | Annual commitments and card-only billing are both fine, but they should be known before the pilot, not after. | Term and notice period not stated until the order form arrives. |
How is EASM priced, and which model suits you?
There are four pricing models in this market. Knowing which one you are being quoted matters more than the number attached to it, because the model determines whether the number is stable. All figures below are prices the vendors publish themselves, as of September 2026, and prices change.
| Model | How the bill moves | Published examples (September 2026) | What to check |
|---|---|---|---|
| Per asset | Scales with the number of assets the tool discovers, usually in banded tiers. | Attaxion: $129/mo Starter, $349/mo Plus, $949/mo Business by asset count, plus a free Community Edition (monthly scans, half the findings visible) and a 30-day trial. Microsoft Defender EASM: billed per billable asset on Azure, with a 30-day trial. | Good discovery raises your bill. Ask what counts as an asset, where the tier boundaries sit, and what happens when you cross one mid-term. |
| Per target, on top of a base fee | A platform or base fee, then a licence for each target you want scanned. | Intruder: a base fee plus per-target licences, with Cloud around $299/mo and Pro around $499/mo, and a free plan limited to weekly checks on ports 80 and 443. | The headline figure is not the invoice. Price the base fee and the target licences together for the estate you expect after discovery, not the one you can list today. |
| Platform fee plus usage | An annual platform fee for the tier, then usage charges per domain or target. | Detectify: platform fees from €2,500, €5,000 or €15,000 per year depending on tier, plus per-domain or per-target usage, with a free Starter option. | Annual commitment on the platform fee makes this the least forgiving model to get wrong. Model two years, not one. |
| Flat or band-based subscription | One price for an agreed scope, either genuinely flat or banded by company size rather than by asset count. | UpGuard Breach Risk: $250 to $2,000/mo scaling by employee count. SurfaceLoop: £149/mo flat with discovery included and a 14-day trial with no card, invoiced by AMVIA. | Check what "agreed scope" means in the contract, and whether a band change (headcount growth, an acquisition) moves you up a tier mid-term. |
Free tiers, and what they cost you instead
Several vendors offer a permanent free tier, and each pays for it with a specific limitation worth understanding before you build a process on one. As of September 2026: Intruder's free plan checks weekly and only on ports 80 and 443; Attaxion's Community Edition scans monthly and shows half of its findings; Detectify offers a free Starter option. Free tiers are a reasonable way to see a product's interface. They are a poor basis for a monitoring commitment you would describe to a client or an insurer, because the scan interval is the part that was cut.
Price the estate you will have, not the one you can list
In metered models, quote after discovery, never before. Run the trial, let discovery finish, count what it found, then ask for the price at that count and at 50% above it. A firm that listed nine assets and discovered thirty-four is not unusual, and on a per-asset tier that can be the difference between two price bands.
What should a UK buyer check specifically?
Data residency and processing
Scan output is a map of your weaknesses, so treat it as sensitive whether or not it contains personal data. Ask where findings are stored and processed, what the transfer mechanism is if that is outside the UK or EEA, and for the sub-processor list. Under UK GDPR you need a lawful basis for transfers and a data processing agreement with anyone handling data on your behalf; if you serve public-sector or regulated clients, their own supplier questionnaires will ask you these questions and you will need the vendor's written answers, not your recollection of a sales call.
Cyber Essentials and Cyber Essentials Plus
Cyber Essentials, the UK government-backed scheme administered by IASME, is a self-assessment covering five control areas, with Cyber Essentials Plus adding independent technical verification. Several of those controls are about exactly what an external scan sees: services exposed to the internet that need not be, software reachable from the internet that is unsupported or unpatched, and default or weak configuration on public-facing systems. Running an external scan before you submit means you find those things before an assessor does, and a dated export gives you something to attach to the remediation you did.
Be clear about the limits. No EASM vendor certifies anyone -- certification comes from an IASME-appointed certification body -- and the scheme's scope includes things an external scan cannot see, such as user access control and malware protection on endpoints. Treat EASM as evidence-gathering and gap-finding for the external half. Our Cyber Essentials preparation page goes through which controls an external view can and cannot help with.
NIS2 and the UK NIS Regulations
Most UK SMEs are not directly in scope of either, and you should establish which side of that line you are on before letting a vendor use the acronyms as a closing argument. The UK NIS Regulations apply to operators of essential services and relevant digital service providers under UK competent authorities; the EU's NIS2 Directive applies to in-scope entities in EU member states, which can reach a UK company through an EU establishment or, more commonly, in practice through a customer's supply-chain requirements flowing down to you. Both frameworks expect risk management measures and vulnerability handling, so a documented external monitoring process is genuinely useful when you are in scope or being asked about it. Neither makes a specific tool mandatory, and any vendor saying otherwise is telling you something about their sales training.
Procurement through an MSP
For many UK SMEs the right answer is not to buy an EASM licence at all, but to require the outcome from the IT provider they already pay. An MSP running one platform across its client base has both the volume economics and, crucially, someone who will actually read the findings. If you go that way, get four things in the service schedule: which platform, the scan frequency, a written monthly report to you, and who is accountable for remediating what is found. If you are the MSP, the questions in the vendor table apply with multi-tenancy and per-client reporting weighted far higher, and our MSP page sets out how we handle that side.
Which tools should a UK SME shortlist?
Three or four is the right shortlist length, chosen to span pricing models rather than to collect logos. The products below are the ones UK small businesses and MSPs most often encounter, described neutrally; each link goes to a detailed comparison, and the roundup of EASM tools for small businesses covers a wider field.
- Intruder -- an established UK-founded platform with a well-regarded interface and a genuinely useful free plan for a first look. Pricing is a base fee plus per-target licences, so model the target count carefully.
- Attaxion -- discovery-first, with clearly published per-asset tiers and a 30-day full trial. Strong on the capability that matters most; the trade-off is that the bill tracks the asset count.
- Detectify -- deep application-layer testing built on crowdsourced research, and the strongest option here if your primary risk is a web application you build yourself. Annual platform fees plus usage put it above most SME budgets.
- UpGuard -- external security ratings with substantial third-party and vendor-risk monitoring attached. Worth shortlisting if you need to assess your suppliers as well as yourself.
- Microsoft Defender EASM -- the natural candidate if you are already committed to Azure and have someone comfortable there. Billed per billable asset through Azure, with a 30-day trial, and it expects more security familiarity than the others.
- SurfaceLoop -- our own product, included here for completeness: one flat £149/mo with discovery included, plain-English remediation, a 14-day trial with no card, invoiced by AMVIA. It is aimed squarely at the flat-price, small-team case and does less than the enterprise platforms above by design.
How do you run a two-week evaluation?
- Before you start, write your list. Every domain and public IP you believe you own, from memory and from your registrar. This is the baseline the trial is measured against, and it must be written down before discovery runs.
- Set the weights. Take the rubric above, adjust the weights for your situation, and agree them with whoever signs the invoice. Doing this after the demos is how shortlists get rationalised backwards.
- Run two or three trials in parallel on the same domains. Parallel, not sequential: the comparison is only meaningful against the same estate in the same fortnight.
- Count the delta. How many assets did each tool find that were not on your list, and did it find any the others missed? This is the single most informative number in the exercise.
- Fix three findings using only the tool's own words. One header or DNS issue, one certificate or service issue, one software or version issue. If you had to search elsewhere to understand what to do, score the output criterion accordingly.
- Get the quote at the discovered count. Then ask for the same quote at 50% more assets, and for the renewal price. Metered models deserve both figures in writing.
- Score, then decide. Fill in the rubric from observed evidence, note where you overrode a score and why, and keep the sheet. It is the document that makes the renewal conversation straightforward in a year.
Questions, answered
Something else? Email hello@surfaceloop.com and a person replies.
What is external attack surface management?
External attack surface management (EASM) is the continuous discovery and monitoring of every internet-facing asset an organisation owns -- domains, subdomains, IP addresses, web applications, exposed services and certificates -- from the outside, without agents or credentials. It answers two questions: what do we expose, and what is wrong with it. Discovery is what separates EASM from a scanner: the tool is expected to find assets you did not know to list.
How is EASM different from vulnerability scanning?
Vulnerability management starts from an inventory you supply and goes deep on known vulnerabilities across it, usually with agents or credentialed scans. EASM starts from your organisation's public identity and works outwards to build the inventory itself, then checks what it finds from an attacker's viewpoint. For a small business the practical difference is that vulnerability management tells you about the servers you remembered, and EASM tells you about the ones you forgot.
What should a UK SME budget for EASM?
As of September 2026 the realistic entry range for a UK SME is roughly £120 to £400 per month, depending on the pricing model and the size of the estate discovery finds. Free tiers exist (Intruder, Attaxion Community Edition, Detectify Starter) but are materially limited -- weekly or monthly scanning, restricted ports, or only part of the findings visible. Budget the model, not the headline price: a per-asset or per-target plan can cost several times its entry figure once discovery completes.
Does EASM help with Cyber Essentials?
Indirectly but usefully. Cyber Essentials and Cyber Essentials Plus both care about what your internet-facing services expose: unnecessary open services, unsupported or unpatched software reachable from the internet, and default or weak configuration on public-facing systems. An external scan gives you that picture before an assessor or a CE Plus tester does, which shortens remediation. EASM is not a certification tool and no vendor can certify you -- certification is done by an IASME-appointed certification body.
Do we need EASM if we already have an MSP?
You need the outcome; whether you buy the tool is a commercial question. Many UK MSPs run EASM across their client base and include the reporting in a managed service, which is usually cheaper and better supervised than an SME licence nobody logs into. If you go that route, ask your MSP which platform they use, whether your findings are reported to you monthly in writing, and who is accountable for remediation -- them or you.
Is one tool enough, or do we need several?
For most UK SMEs one EASM tool plus the security controls already in Microsoft 365 or Google Workspace is a sensible stopping point. Adding DAST makes sense when you build and ship your own web application; adding a full CTEM programme makes sense when you have someone whose job is to run it. Buying a second overlapping external scanner mostly buys a second set of the same findings.
How long should an EASM evaluation take?
Two weeks is enough to reach a decision, and most trials are 14 to 30 days. Week one: connect your domains, let discovery run, and count how many assets it finds that were not on your list. Week two: fix three findings using only what the tool tells you, then score each vendor against a weighted rubric. Anything longer usually means the evaluation has no owner.
Published 24 September 2026 · Last updated 24 September 2026 · Written by Nathan Hill-Haimes, co-founder of AMVIA and SurfaceLoop. Competitor pricing was taken from each vendor's published pricing information and is stated as of September 2026; prices and plan structures change, so confirm current figures with the vendor. First-party statistics are drawn from the UK SME External Exposure Snapshot, September 2026, whose methodology is public. This guide may be quoted with attribution to SurfaceLoop.
If you want to use the rubric against us: SurfaceLoop runs a seven-category external scan with discovery included, plain-English remediation on every finding, and one flat price. The trial runs on your own domains for 14 days without card details.