forumNew topic

Security consultant recommended an attack surface management tool, is it overkill for a small company?

IIrmak S***MemberCommunity member
Joined
Feb 2024
Message
381
#1

We are a 14-person freight brokerage firm based in the UK. Our publicly exposed assets consist of a main website, a tracking portal for clients, two subdomains, and a cloud server we use for internal file sharing. Last week we met with an external cybersecurity consultant, and they insisted we purchase recurring "attack surface management" software. The annual subscription for the automated platform they recommended runs around 7,200 GBP.

The consultant claims all our internet-facing assets need continuous monitoring. For a business like ours with only a handful of servers and domains, is attack surface management genuinely critical, or is it a luxury designed for enterprises? Can't we maintain the same level of oversight using simpler or free methods without spending that budget?

YYağmur K***Member
Job title
Administrative manager
Sector
E-commerce
Organization type
40-person manufacturing company
Joined
Jul 2022
Message
1
Most Helpful#2

Short answer: Attack surface management is a security approach that continuously maps all internet-accessible entry points, forgotten servers, and open ports across your organization; however, paying 7,200 GBP a year for a 14-person business with barely a few domains is a blatant waste of resources. In an environment of this scale where your assets don't even exceed the fingers on two hands, continuous automated discovery software isn't necessary.

Attack surface tools are designed for large enterprises with hundreds of domains, dozens of cloud accounts, and thousands of employees. In those massive environments, developers spin up test servers without telling anyone, people leave behind forgotten subdomains, and management can't keep track. In your setup, the chances of an unknown asset appearing out of nowhere are extremely slim.

Instead, you can run this simple, free three-step check: 1) List all your externally visible records using free DNS and subdomain discovery tools, 2) Verify that only necessary ports are open on your servers using open-source port scanning utilities, 3) Calendar your SSL certificate expiration dates and security patch updates for your web software.

You or your current sysadmin can knock out these checks in two hours as part of a quarterly routine. Rather than spending 7,200 GBP a year, allocating that budget toward two-factor authentication infrastructure or employee phishing awareness training will improve your company's security significantly more.

SSerdar K***Veteran
Job title
Growth marketing
Joined
May 2023
Message
264
#3

The consultant is probably an affiliate for that tool and gets a commission. Trying to push continuous attack surface scanning on a company with four addresses is definitely not done in good faith.

SSena Y***Member
Job title
Front office accounting
Sector
Healthcare services
Organization type
chain store
Joined
May 2023
Message
205
#4

Attack surface tools basically just poll DNS records, open ports, cert validity, and service versions on a loop. When you only have a few servers, running an open-source port scanner and reviewing the results yourself won't even take half an hour.

TTülay A***Member
Job title
Store associate
Sector
Packaging
Organization type
8-person team
Joined
Dec 2023
Message
64
#5

We're a 30-person software shop. We scan our external assets once a month using free open-source scripts. Aside from a single forgotten test subdomain, we've never had any surprises, and it costs us zero.

GGizem Ö***Member
Job title
QA Tester
Sector
Consulting
Organization type
regional distributor
Joined
Jul 2024
Message
257
#6

Your immediate action items are simple: log into your domain registrar, delete any unused subdomains, close unneeded ports on the server, and enforce two-factor authentication across all logins.

SSultan A***Member
Job title
QA Tester
Sector
Freight
Organization type
300-person organization
Joined
Aug 2025
Message
143

Doki · KVKK compliance consulting · 2023

#7

Standard security certifications in the UK don't require expensive continuous monitoring tools like this either. An annual basic vulnerability scan alongside an asset inventory is generally considered sufficient.

UUğur Y***VeteranCommunity member
Joined
Oct 2024
Message
3
#8

buying a nice coffee machine for the office with that 7k quid instead of spending it on 4 servers would do the company way more good, totally pointless.

SSelim K***Member
Job title
Sales Manager
Sector
Media and publishing
Organization type
120-person company
Joined
Mar 2025
Message
305

Doki · SEO consulting · 2024

#9

Did the consultant's report highlight any concrete vulnerabilities, or did they just pitch this software as a general recommendation?

SSelin T***Member
Job title
Software developer
Sector
Printing
Organization type
40-person manufacturing company
Joined
Oct 2025
Message
409
#10

Bottom line, this tool is massive overkill for your size. Track your inventory manually, maintain basic security hygiene, and save that budget for authentication vulnerabilities that pose an actual risk.

DDamla A***MemberCommunity member
Joined
Jul 2025
Message
179
#11

Looking at it as a process, the picture changes. If you get three different answers on a topic, the question was asked wrong.

Having backups accessible on the same network and with the same identity makes them part of the target. Correct me if I'm wrong.

YYasemin K***MemberCommunity member
Joined
Jan 2023
Message
3
#12

Could you elaborate on that? If it's your first time, start small; scaling comes later.

If I were you, I'd go this route.

KKemal K***Veteran
Job title
Software developer
Sector
Furniture manufacturing
Organization type
family business
Joined
Feb 2023
Message
57

Doki · Interface design · 2026

#13

Let me speak from the other side; I'm on the supplier side. Mistakes made on the attack surface management side are usually reversible but expensive.

Of course, it varies if your situation is different.

BBarış B***Member
Job title
Project manager
Sector
Cosmetics
Organization type
regional distributor
Joined
Aug 2024
Message
77
#14

This thread is archived. Mistakes made on the attack surface management side are usually reversible but expensive.

I'm also curious if anyone does it differently.

RRıdvan B***MemberCommunity member
Joined
May 2023
Message
180
#15

To get into the details: If 2FA is on, a stolen password alone is useless.

The real issue isn't the number, but what it's based on. Good luck with that.

VVolkan U***MemberCommunity member
Joined
Feb 2024
Message
56
#16

We need to make a distinction here. If you scold false alarms, nobody will report again.

Of course, it varies if your situation is different.

ZZerrin M***MemberCommunity member
Joined
Feb 2024
Message
1
#17

Following.

UUfuk A***ExpertCommunity member
Joined
Dec 2024
Message
410
#18

Thanks for writing this, that's the right way. If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection.

Good luck with that.

OOsman T***Member
Job title
Technical service technician
Sector
Furniture manufacturing
Organization type
a company within a holding
Joined
Jan 2022
Message
3
#19

This thread is archived.

GGürkan D***Member
Job title
Human Resources Specialist
Sector
Plastic
Organization type
300-person organization
Joined
May 2023
Message
362
#20

Exactly, and not many people know this. The biggest time-waster for us was not knowing who had the final say.

Most incidents start with a leaked password, not a vulnerability. This is my opinion, I'm not claiming it's absolute truth.

Reply