About Course
Sales Enablement · Module 2 · Self-paced (~1 hour) · 10-question quiz (80% to pass).
Learning objectives
Explain what EASM and EASMLens are, how agentless continuous discovery works, how EASMLens feeds GRCLens, the three lead use cases, and how to position it vs Xpanse/CyCognito.
1. What is EASM, and what is EASMLens?
Your external attack surface is everything an attacker can see and reach from the internet — sites, subdomains, cloud instances, exposed services, forgotten dev/test servers, third-party assets. Most organisations lack a complete, current inventory of it, and breaches start in those unknown, unmanaged assets.
EASMLens is a continuous, agentless External Attack Surface Management platform that discovers internet-facing assets, finds and scores their exposures, and — uniquely — feeds the findings into GRCLens so they become tracked, remediated, auditable risk.
One-sentence pitch: “EASMLens continuously discovers everything you have exposed to the internet — including assets you didn’t know about — scores the risk, and pushes it straight into GRCLens so nothing falls through the cracks.”
2. How EASMLens works
- Agentless discovery — nothing to install; it maps outward from domains/brands/IP ranges and finds related (and forgotten) assets.
- Continuous — the surface changes daily, so EASMLens re-scans continuously rather than a once-a-year snapshot.
- Findings & risk scoring — open services, weak/expired TLS, exposed admin panels, misconfigurations, known vulnerabilities — each scored so teams fix the worst first.
- Live asset inventory — a categorised register of every external asset, including shadow IT.
3. The differentiator: EASMLens + GRCLens
Standalone EASM tools leave findings in a report. EASMLens integrates with GRCLens so a finding becomes a quantified risk with an owner, a remediation workflow, and an audit trail: discovery → risk quantification → remediation → evidence. It’s also a powerful door-opener — a discovery scan surfaces real unknowns and opens the wider GRC conversation.
4. Customer use cases
- Supply-chain / third-party risk — monitor vendors’ external exposure, not just your own.
- Shadow IT & cloud sprawl — find unmanaged cloud instances, dev/test servers, forgotten subdomains.
- Third-party / M&A exposure — instant visibility into an acquired company’s internet-facing risk.
Lead with EASMLens when the buyer is a security/CISO team worried about “what don’t we know about.”
5. Competitive positioning
- vs Palo Alto Cortex Xpanse / CyCognito: strong standalone tools, but findings stay in their console — EASMLens wins on GRC integration, agentless continuous discovery, and cost/ease.
- vs a periodic pen test: a snapshot; EASMLens is continuous and covers the full, changing surface.
6. Key takeaways
Continuous agentless discovery + risk scoring · unique value = GRCLens integration (tracked, remediated, auditable risk) · lead use cases = supply-chain, shadow IT, M&A · win vs Xpanse/CyCognito on integration, continuity, cost · great door-opener.
7. Assessment
Complete the 10-question Knowledge Check (80% to pass) in the curriculum below to finish this module.
Course Content
Module 2 — EASMLens Product Fundamentals
Knowledge Check — EASMLens Product Fundamentals

