A Single Partner for Everything You Need With more than 450 technology partners in its ecosystem, Optiv provides clients with best-in-class security technology and solutions that equip organizations to detect and manage cyber threats effectively and efficiently in today's growing attack surface. Optiv's Partner of the Year Awards recognize forward-thinking innovation, performance and growth, and unparalleled technology solutions.
We Are Optiv Security Greatness is every team working toward a common goal. Winning in spite of cyber threats and overcoming challenges in spite of them. It’s building for a future that only you can create or simply coming home in time for dinner. However you define greatness, Optiv is in your corner. We manage cyber risk so you can secure your full potential.
Crossing the CAASM: Closing the Attack Surface Gap for CTEM Breadcrumb Home Insights Blog Crossing the CAASM: Closing the Attack Surface Gap for CTEM September 11, 2026 When it comes to cyber asset inventory and attack surface visibility, the distinction between external attack surface management (EASM) and cyber asset attack surface management (CAASM) matters. Both are often discussed under the broader umbrella of attack surface management (ASM), which can make them easy to confuse, but they solve different problems and offer distinct advantages. In this article, we’ll break down EASM and CAASM and explain how both fit into a comprehensive continuous threat exposure management (CTEM) program. ASM is the broad practice of continuously discovering, analyzing, prioritizing and reducing an organization’s potential security weaknesses across all digital assets, external and internal. EASM focuses on internet-facing assets from an attacker’s perspective, while CAASM builds an inside-out inventory by aggregating asset, ownership, and security control data across IT and security tools. EASM is like looking at your house from the street, CAASM is like taking inventory from inside the house, and ASM is the broader practice of securing the entire property. Let’s look at the key differences between the EASM and CAASM programs: Area EASM CAASM Practitioner Implication Main Question "What assets could an attacker find and exploit?" "What assets do we own, and are they properly secured? " Use EASM to find what the internet sees; use CAASM to determine ownership, criticality, control coverage and remediation path Primary Goal Discover and reduce external assets and exposures Create a complete unified asset inventory, identify ownership, validate security control coverage and uncover visibility gaps Pair EASM exposure reduction with CAASM inventory completeness so teams are fixing real, owned assets instead of chasing disconnected findings Viewpoint Attacker's perspective Defender's perspective Use EASM to think like an attacker, then use CAASM to assign accountability and validate whether defensive controls are actually in place Focus Vulnerabilities, exposed services, internet-facing assets Devices, users, identities, cloud resources, applications, security controls Prioritize internet-facing vulnerabilities first, but enrich them with CAASM context such as ownership, identity links and missing controls before remediation Asset Scope Domains, IPs, hosts, web apps, APIs, cloud services, certificates, external third-party exposure Devices, cloud workloads, users, identities, applications, software, code, SaaS, OT/IoT, and control data from integrated systems EASM is strongest for external unknowns; CAASM is strongest for enterprise-wide correlation Data Source External scanning, reconnaissance, internet visibility Integrations with CMDBs, EDR, vulnerability scanners, cloud platforms, IAM, MDM, etc. Treat EASM as an external discovery signal and CAASM as the normalization layer that reconciles scanner, cloud, identity, endpoint and configuration management database (CMDB) data Typical Output Exposed assets, shadow IT, attack paths Unified asset inventory, control gaps, missing agents, unmanaged assets Convert EASM discoveries into CAASM-backed work items that include owner, business context, control gaps, and a clear remediation path Ownership Often security operations, vulnerability management, external risk, AppSec, cloud security or threat exposure team Security architecture, asset management, SecOps, vulnerability management, GRC, IT operations or platform teams Define shared ownership early: EASM teams surface exposure, while CAASM owners maintain asset truth, control coverage and remediation routing Roles in CTEMContinuous threat exposure management (CTEM) must cover internal and external assets to strengthen security controls and prevent external threats from becoming internal compromises. Both EASM and CAASM have their place in creating a comprehensive CTEM program. For more on what CTEM is and why customers need it, check out our previous CTEM blog here. EASM provides continuous asset discovery. EASM identifies: Internet-facing assetsCloud resourcesExternal applicationsDomains and subdomainsShadow ITUnknown or unmanaged exposed systems This gives CTEM its baseline understanding of what attackers can actually see and target. Without EASM, you can't measure exposure you don't know exists, prioritization becomes incomplete and validation exercises miss assets. EASM feeds CTEM prioritization. Once EASM discovers assets, CTEM combines that data with: Vulnerability dataIdentity dataThreat intelligenceBusiness criticalitySecurity control coverage This allows security teams to focus on which exposures matter most right now rather than which vulnerabilities have the highest common vulnerability scoring system (CVSS) score. EASM provides attacker-perspective visibility. One of CTEM's key goals is understanding risk from a likely attacker's viewpoint. EASM answers questions such as: What systems are externally exposed? What applications are reachable from the internet? What forgotten assets could be abused? Where are potential entry points? This outside-in visibility is a foundational CTEM input. CAASM provides the asset visibility and context layer. While EASM helps CTEM understand what attackers can see, CAASM helps CTEM understand what the organization owns, how it is configured, who owns it, and whether security controls are working properly. 1. Comprehensive Asset Discovery and InventoryCTEM starts with understanding the environment. CAASM aggregates data from: CMDBsEDR platformsVulnerability scannersCloud platformsIdentity providersMDM toolsSecurity products It creates a unified inventory of assets, users, applications, workloads, and cloud resources. This eliminates blind spots that can undermine CTEM efforts. CTEM question: What do we have?CAASM answer: Here's every known and unknown asset across the enterprise. 2. Exposure Context and PrioritizationFinding a vulnerability alone is not enough. CAASM enriches exposure data with: Asset ownershipBusiness criticalitySecurity control statusIdentity relationshipsCloud metadataRisk context This allows CTEM to prioritize exposures based on actual business impact rather than just severity scores. For example, if two servers have the same critical vulnerability, CAASM may reveal: Server A hosts a public-facing customer applicationServer B is a retired development system CTEM can then prioritize Server A first. 3. Control ValidationOne of CAASM's most valuable CTEM functions is identifying gaps in security controls. CAASM can identify: Devices missing EDRUsers without MFAServers not being scannedCloud workloads lacking monitoringAssets missing patch management agents These findings become CTEM exposure candidates even when no vulnerability exists. CTEM question: Are our controls actually deployed everywhere?CAASM answer: No, here are the assets where controls are missing. 4. Exposure Reduction and RemediationCTEM aims to drive action, not just produce findings. CAASM helps operationalize remediation by: Identifying asset ownersMapping dependenciesTracking remediation statusAutomating workflows through integrations Teams can quickly determine who owns the asset, what business function it supports and which exposure needs correction. This accelerates mobilization and remediation efforts. 5. Measurement and Continuous MonitoringCTEM is continuous, not periodic. CAASM continuously updates asset data and provides metrics such as: Total managed vs unmanaged assetsCoverage gapsMissing security controlsAsset ownership completenessExposure trends This enables CTEM programs to measure progress over time. In summary, EASM gives CTEM visibility. CAASM gives CTEM context. Validation gives CTEM confidence. CTEM then tells you what to fix first and makes sure you are achieving a measurable reduction in exposures. The Check Point ApproachCheck Point puts CAASM into action through extensive API integrations that correlate asset information from security, cloud, IT, and identity platforms into a single place. Tools like CMDB, vulnerability management, and EDR provide the needed context around assets so that a CTEM program can make informed decisions on which assets are the most important, which exposures to those assets are the most critical, and what actions can be taken to address them. Speaking of what actions can be taken, Check Point CAASM helps identify gaps in coverage from existing security controls. These gaps can be addressed by security teams through configuration changes, additional purchases, or virtual patching through Check Point’s threat exposure management platform. With 150 connectors to security and IT tooling, Check Point CAASM provides a single source of truth for assets by deduplicating all of the data that comes in from these tools. This leads to a 95% reduction in the number of queries needed, and the end result is a significant decrease in MTTR from days to just hours. As for EASM, Check Point provides this as-a-service. The service utilizes Open Source Intelligence (OSINT) to discover digital assets, as well as to identify all interconnected entities. Check Point EASM offers real-time insights into business context around discovered assets, such as role, sensitivity and relevance. This is accomplished through bi-weekly scanning and testing, the results of which are included in monthly vulnerability reports with remediation steps. Turn Check Point Visibility into Action with OptivTechnology alone does not create a mature CTEM program. As a Check Point partner, Optiv helps organizations connect Check Point’s CAASM and EASM capabilities to the people, processes and broader security ecosystem required to reduce exposure. Optiv brings vendor-informed expertise with an enterprise-wide perspective, helping clients translate asset and exposure data into a practical, risk-aligned program. Optiv can help clients: Advise: Assess attack surface and CTEM maturity, define the target state and build a prioritized roadmap aligned to business riskDeploy: Integrate Check Point with cloud, identity, endpoint, vulnerability management, CMDB and workflow platforms to improve asset correlation and remediation routingOperate: Establish repeatable governance, monitoring, reporting and continuous improvement processes that keep asset context and control coverage currentOptimize: Rationalize overlapping tools, close visibility gaps and help teams turn prioritized exposures into accountable remediation actions Together, Optiv and Check Point help security teams move beyond fragmented findings toward a connected CTEM program, one that improves visibility, adds business context, validates control coverage and drives measurable exposure reduction. Interested in a demo? Reach out to our team. By: Jerrod Piker Partner Architect – Check Point Jerrod comes from a diverse IT/Security background in financial services, telecom and critical infrastructure with a specialization in cybersecurity, dating all the way back to 2004. He spent 8+ years at Check Point – first as a generalist, then as a specialist. With a broad understanding of all types of cyberthreats, his areas of focus are network security, endpoint and email security and securing the customer edge. As a Partner Architect at Optiv, Jerrod brings a deep technical and sales knowledge of the whole Check Point solution catalog. While at Check Point, he was the SME for Harmony Email and Collaboration, Harmony Endpoint and the Sandblast Threat Prevention solution set. By: Vik Phonsa Director of Research and Development at Optiv Vik Phonsa is a director of research and development at Optiv. He has over 15 years of experience in product management and R&D in various cybersecurity and software engineering domains. At Optiv, he is responsible for researching and analyzing the ever changing cybersecurity landscape and developing an innovation and partnership strategy for the company. Prior to Optiv, Vik has held product management positions at Tenable, Qualys, Symantec, Verizon and Contrast Security where he launched cloud-based security products. Share: Optiv About Optiv Security: Secure greatness.® Optiv is the world’s largest pure-play cybersecurity company. With unmatched technology partnerships and deep technical expertise, Optiv securely enables the AI era for more than 6,000 clients. From financial services and health care, to government, energy and retail, organizations trust Optiv to advise, deploy and operate cybersecurity programs that reduce risk and deliver real results. Learn why Optiv is the most trusted brand in cyber at optiv.com.
About Optiv Security: Secure greatness.® Optiv is the world’s largest pure-play cybersecurity company. With unmatched technology partnerships and deep technical expertise, Optiv securely enables the AI era for more than 6,000 clients. From financial services and health care, to government, energy and retail, organizations trust Optiv to advise, deploy and operate cybersecurity programs that reduce risk and deliver real results. Learn why Optiv is the most trusted brand in cyber at optiv.com.