The effectiveness of external attack surface management (EASM) and third-party risk management (TPRM) capabilities hinges on the depth, breadth, and timeliness of the underlying data they are based on. For this reason, Bitsight makes a significant ongoing investment in:
- Mapping the relationships between entities and assets that make up the global internet
- Observing and assessing the risk posture of connected assets
- Harnessing AI to reveal data-driven intelligence for our customers
The introduction of Bitsight’s next-generation data engine enabled many improvements to our capabilities across all of these areas throughout 2024. Critically, it also gave us the flexible and capable foundation we need to further our market leadership position as the industry evolves in new and exciting ways over the coming years.
In this post, I’ll share some thoughts on the biggest opportunities for enhanced risk insights on the horizon––and our strategy for helping customers capitalize through ongoing enhancements to our data platform in 2025 and beyond.
Key takeaways
- Attack surface management will likely evolve and converge with complementary security disciplines over the next several years.
- Bitsight’s 2025 data engine strategy will keep customers on the leading edge as this industry evolution progresses, enabling high-value product enhancements and new use cases for data-driven insights.
- Speed of data collection, asset mapping, and risk assessment will continue to be a major focus in 2025.
- We will also enrich our EASM and TPRM offerings with cyber threat intelligence (CTI), supported by our recent acquisition of Cybersixgill.
- Deeper visibility and context for assets in cloud service provider environments will ensure that our customers always have a complete picture of their attack surface.
- We will continue our ongoing efforts to refine the Bitsight Security Rating methodology with our annual ratings algorithm update (RAU), faster rating updates post-remediation, and other initiatives.
Broadening the definition of attack surface management
We’ve already proven that mapping the internet’s connected assets, linking them to specific entities, and directly observing risk indicators is an effective formula for revealing high-value insights about first-, third-, and nth-party risk. However, the impact of these capabilities is only maximized if they are integrated tightly with an organization’s broader security tool stack and remediation workflows.
According to Gartner®, “By 2027, EASM will be deployed primarily as an integrated feature of broader threat exposure management solution sets, such as cyberthreat intelligence/digital risk protection services (CTI/DRPS), adversarial exposure validation and exposure assessment platforms.”1
This makes perfect sense. After all, combining specific risk observables with CTI will help security teams prioritize the security weaknesses that are most likely to be targeted. Similarly, using threat data to inform CTEM and vulnerability remediation priorities will make the organizations more resilient over time.
We plan to take meaningful steps towards this vision in 2025, with a particular focus on the following themes:
- Bringing even more speed and flexibility to our core discovery, attribution, and assessment capabilities
- Adding CTI as an entirely new dimension of Bitsight’s EASM and TPRM offerings
- Further expanding our ability to discover, map, and assess the growing number of enterprise assets deployed in shared cloud service provider environments
Here’s an early preview of some of the exciting innovations we have planned in each of these areas for 2025.