For procurement · CISO · security ops
Twenty-plus questions to ask any attack-surface platform. Use it against us. Use it against anyone. The questions are the questions; the answers are how you tell platforms apart.
Shadow IT, M&A inheritance, abandoned cloud accounts. The platform is only as good as its discovery.
Look for: passive DNS, certificate transparency, ASN enumeration, Wayback, code-search.
Look for: bucket-naming heuristics, IP reputation linkage, SSL SAN cross-reference, code-repo signals.
Look for: confidence scoring, suppression workflow, audit trail. Avoid: opaque ML black box.
Look for: a number, with measurement methodology. Avoid: “industry-leading accuracy.”
If the platform produces a rating, you should be able to defend it to a board, an auditor, and the vendor it’s scoring.
Look for: published whitepaper, exact weights, formula. Avoid: “proprietary algorithm.”
Look for: documented workflow, named analyst, < 5 business days. Avoid: “email support.”
Look for: continuous (within 24h of a finding change). Avoid: monthly recompute.
Look for: a candid answer with examples. Avoid: deflection.
A platform that only does TLS hygiene is not an attack-surface platform.
Look for: dedicated modules, not feature checkboxes. Avoid: “via integration.”
Look for: 10+, with named frameworks. Avoid: “customisable templates.”
Look for: included, with SLA. Avoid: “professional services engagement.”
A platform that doesn’t route findings to the right owner is a dashboard nobody opens.
Look for: out-of-the-box, with field mapping. Avoid: “via Zapier.”
Look for: hours to days. Avoid: 4-6 weeks of scoping.
Look for: REST & webhooks, documented limits, free sandbox. Avoid: API as paid add-on.
Look for: tiered pricing, transparent inclusions. Avoid: “contact us.”
Look for: one clear axis. Avoid: per-user fees on a platform you already pay for.
Look for: a free rating, no scoping call. Avoid: 90-day paid POC.