External Attack Surface Management (EASM) and Continuous Threat Exposure Management (CTEM) are related but operate at different scopes. EASM is a discovery discipline focused on the external, internet facing attack surface. CTEM is the wider program that consumes discovery, including EASM output, and adds prioritisation, validation and mobilisation across the full environment. EASM is an input to CTEM, not a substitute for it.
What EASM actually does
EASM discovers and monitors assets reachable from the public internet, often including assets the organisation does not know it owns. It typically works from an outside in perspective using:
The output is a continuously updated inventory of the external footprint: exposed services, expired or misconfigured certificates, forgotten hosts, shadow IT with public endpoints, and exposed storage. This is genuinely valuable, because unknown external assets are a common initial access vector. EASM largely stops at discovery of the external surface. It tells you what exists and is exposed. It does not, by itself, prove exploitability, cover internal assets, or drive remediation.
EASM vs CAASM
A frequent point of confusion. EASM sees the surface from outside, with no internal access. CAASM (Cyber Asset Attack Surface Management) builds an internal asset picture by aggregating data from cloud APIs, EDR, identity providers, CMDB and scanners. EASM answers "what can an attacker see from the internet." CAASM answers "what assets do we actually have and how are they configured." Both are discovery feeds. CTEM consumes both.
What CTEM adds on top of EASM
CTEM takes discovery output, external and internal, and runs three further stages that EASM does not:
CTEM also spans what EASM cannot reach: internal assets, identity and entitlement exposure, and third party connections. An external asset discovered by EASM only becomes a prioritised exposure once CTEM establishes that it is exploitable and what it chains into. For that discovery layer in full, see the attack surface management guide.
Side by side
| Dimension | EASM | CTEM |
|---|---|---|
| Perspective | Outside in, external only | Full: external, internal, identity, third party |
| Core function | Discover exposed external assets | Discover, prioritise, validate, mobilise |
| Validation | Rarely, if ever | Core stage |
| Prioritisation | Basic, presence based | Exploitability, reachability, business impact |
| Output | External asset inventory | Ranked, validated, tracked program |
Which do you need
If the requirement is purely to find unknown internet facing assets, EASM may be sufficient on its own. If the requirement is to know which exposures, external and internal, are actually exploitable and worth remediating first, that is CTEM, with EASM as one of its feeds. In practice most organisations run EASM inside a CTEM program rather than as a standalone. The same input relationship applies to vulnerability scanning, covered in CTEM vs vulnerability management, and the overall model is set out in what CTEM is.
Clarifying the terminology
Is EASM part of CTEM?
Yes. EASM is the external discovery feed into the CTEM discovery stage. CTEM adds prioritisation, validation and mobilisation.
What is the difference between EASM and ASM?
ASM (Attack Surface Management) covers both internal and external surface. EASM is the external only subset. CAASM covers the internal asset picture.
Can EASM replace CTEM?
No. EASM discovers external exposure but does not validate exploitability or cover internal assets, identities and third parties.
Crossbow runs CTEM as a managed program that consumes external and internal discovery, then validates exploitability with a CREST accredited testing team. See the CTEM programme.


