We are a 14-person freight brokerage firm based in the UK. Our publicly exposed assets consist of a main website, a tracking portal for clients, two subdomains, and a cloud server we use for internal file sharing. Last week we met with an external cybersecurity consultant, and they insisted we purchase recurring "attack surface management" software. The annual subscription for the automated platform they recommended runs around 7,200 GBP.
The consultant claims all our internet-facing assets need continuous monitoring. For a business like ours with only a handful of servers and domains, is attack surface management genuinely critical, or is it a luxury designed for enterprises? Can't we maintain the same level of oversight using simpler or free methods without spending that budget?