Attack Surface Management in Canada

What Canadian organizations actually need from attack surface management — and why ASM on its own only covers a third of the problem.

Talk to a Canadian Security Team

The short answer

Attack surface management is the practice of continuously finding everything your organization exposes that an attacker could reach, and reducing it. For Canadian organizations, three things make it different from the generic advice you will find on US vendor sites: where your security data is allowed to live, what PIPEDA and provincial privacy law expect you to be able to demonstrate, and — if you are a federally regulated financial institution — what OSFI B-13 expects you to know about your own technology assets.

ASM alone will not get you there. Knowing what is exposed is one third of the picture; you also need to know what is already leaking about you, and how your cloud is configured. That is why this page is about unified exposure management — External ASM, Internal ASM, threat intelligence, and cloud posture — rather than ASM in isolation.

What attack surface management actually is

Your attack surface is everything an attacker could reach and try to use. That includes the obvious — your website, your customer portal, your VPN endpoint — and the parts nobody is tracking: a marketing subdomain spun up for a campaign three years ago, a test environment someone exposed "temporarily," a cloud storage bucket that was set to public during a migration and never set back.

Attack surface management is the discipline of finding all of that continuously, from the outside in, the way an attacker would. The word continuously is what separates it from a spreadsheet-based asset inventory. Asset lists are accurate the day they are written. Attack surfaces change every week, and the things that hurt you are almost always the assets nobody remembered to add to the list.

External ASM and Internal ASM are different problems

External ASM maps what you expose to the internet — domains, IP ranges, certificates, exposed services, login portals, cloud storage. It answers the question an attacker asks first: where do I even start?

Internal ASM maps what is reachable once someone is already inside, whether through a phished employee, a compromised VPN credential, or a contractor's laptop. This is where unpatched legacy systems, flat network segments, and forgotten domain controllers live. Most Canadian mid-market organizations have far more internal exposure than they expect, because internal systems have historically been treated as "behind the firewall" and therefore safe.

Why ASM on its own leaves gaps

Attacks are a chain. Tools that see one link at a time make you reconstruct the chain yourself.

Consider a realistic incident. An employee reuses a work password on a personal site. That site is breached, and the credential ends up in a dump traded online. An attacker buys it, tries it against a login portal your team forgot was exposed, and gets in. From there they move sideways across a flat internal network to a server running software that has not been patched in years.

ASM would have flagged the exposed portal. It would not have told you the credential was circulating. Threat intelligence would have caught the credential, but not that the portal existed. Neither would have noticed that the cloud account holding your backups was configured to allow public access. Three tools, three partial views, and a chain that nobody sees end to end.

This is the practical argument for unified exposure management: External ASM for the internet-facing footprint, Internal ASM for what is reachable inside, CTI for credentials and data already leaking, and CSPM for how your cloud accounts are configured — all resolving against one shared asset inventory, so a leaked credential and an exposed portal and an unpatched host read as one story instead of three unrelated alerts.

The Canadian regulatory picture

No Canadian law names "attack surface management" as a required control. But several create obligations you cannot meet without knowing what you have.

PIPEDA

Federal · most private-sector organizations

Requires safeguards appropriate to the sensitivity of the personal information you hold. It also requires reporting breaches to the Office of the Privacy Commissioner where there is a real risk of significant harm, notifying affected individuals, and keeping a record of every breach — not only reportable ones — for 24 months after you determine it occurred. You cannot safeguard or report on a system you do not know exists. Source: Office of the Privacy Commissioner of Canada

Quebec — Law 25

Quebec · strictest in Canada

Phased in from September 2022 through September 2024, Law 25 goes further than PIPEDA: a designated person responsible for protecting personal information, confidentiality incident reporting to the Commission d'accès à l'information, privacy impact assessments before communicating personal information outside Quebec, and — since September 2024 — data portability on request. If you hold data on Quebec residents, this is usually the highest bar you have to clear. Source: Commission d'accès à l'information

Alberta & British Columbia PIPA

Provincial private-sector law

Alberta and BC have their own private-sector privacy statutes, recognized as substantially similar to PIPEDA, which apply in place of it for organizations operating within those provinces. Alberta's PIPA requires notifying the provincial Commissioner of breaches posing a real risk of significant harm; BC's PIPA has historically not carried the same mandatory reporting duty. Confirm which regime applies to you before assuming PIPEDA is the whole story. Sources: OIPC Alberta · OPC

OSFI Guideline B-13

Federally regulated financial institutions

Published July 2022 and in force since 1 January 2024, B-13 sets OSFI's expectations for technology and cyber risk management. It states that institutions "should maintain a current and comprehensive asset management system, or inventory, that catalogues technology assets throughout their life cycle" — which is difficult to satisfy with a hand-maintained list. B-13 is usually read alongside Guideline B-10 on third-party risk, in force since 1 May 2024, which matters when part of your exposure is operated by a vendor. Source: OSFI Guideline B-13

CCCS guidance

Canadian Centre for Cyber Security

The CCCS, part of the Communications Security Establishment, publishes the Baseline Cyber Security Controls for Small and Medium Organizations and the Top 10 IT Security Actions (ITSM.10.089). These are practical guidance rather than law. Neither names attack surface management, but the Baseline asks you to scope which systems and assets are in play, and Top 10 actions such as consolidating and defending internet gateways, patching, and isolating web-facing applications all assume you know which gateways and applications you have. Canadian buyers increasingly cite CCCS baselines in procurement. Sources: CCCS Baseline Controls · Top 10 IT Security Actions

Data residency

Contractual and procurement pressure

PIPEDA does not prohibit transferring personal information outside Canada for processing, but you must use contractual or other means to give it a comparable level of protection, remain accountable for it, and tell individuals clearly that it may be processed abroad and accessed by foreign authorities. Public-sector rules are stricter, and many private organizations adopt Canadian residency as policy anyway — it removes an entire category of question from vendor reviews, customer security questionnaires, and board reporting. Source: OPC guidelines on transborder data flows

One caution

No platform — ours included — makes you compliant with any of the above. These obligations sit with your organization, and none of these instruments names a product you can buy to satisfy them. What continuous discovery gives you is the evidence to demonstrate diligence: what you had, when you learned about it, and what you did next, at the point a regulator, an insurer, or an enterprise customer's security review asks you to show your work.

Each statement above links to the regulator's own published guidance so you can check it directly. This page is a practical summary for security teams, not legal advice: obligations vary by sector, province, and the kind of information you hold, and guidance is updated over time — confirm your specific requirements with qualified counsel. Last reviewed against the linked sources in September 2026.

What to look for in a platform

Vendor-neutral criteria worth putting in your evaluation, whoever you end up buying from.

  • Ask where the data lives, and get it in writing. Not where the vendor is headquartered — where your findings, asset inventory, and any personal information are actually stored and backed up. Ask whether Canadian residency is the default or a paid upgrade, and whether it applies to every module or only some.
  • Check whether discovery is continuous or scheduled. A platform that rescans quarterly is an audit tool. The exposures that cause incidents typically appear and are exploited well inside that window.
  • Find out how much is one product versus several acquisitions. Many vendors assembled their ASM, threat intelligence, and cloud posture capabilities through acquisition. Ask whether the modules share one asset inventory, or whether correlating them is left to you.
  • Confirm internal coverage, not just external. Plenty of platforms marketed as ASM only see the internet-facing side. If you want to know what an attacker reaches after the first foothold, ask specifically about internal discovery and how it is deployed.
  • Ask what happens when nobody is watching the dashboard. Most Canadian mid-market teams do not have someone assigned to triage findings daily. A managed option — where the vendor's own analysts work the queue — is often more realistic than another dashboard nobody opens.
  • Ask who wrote the prioritization logic. Severity scores generated from a generic database will bury the finding that actually matters. Ask whether practitioners who perform offensive engagements shaped the ranking, and how the platform decides what to show first.
  • Get the evidence trail you will need later. Exportable findings, historical snapshots, and an audit log matter when you are demonstrating due diligence to a regulator, an insurer, or an enterprise customer's security review.

Where Helios by Isaphia fits

Helios by Isaphia is a Canadian-built unified exposure management platform. It combines four modules — External ASM, Internal ASM, CTI, and CSPM — against one shared asset inventory, so the leaked credential, the exposed portal, and the unpatched internal host that make up a single attack chain appear as one story rather than three separate alerts.

Isaphia is headquartered in Toronto. Canadian data residency is the default across all four modules, with EU or US regions available on request — the full detail is in the Helios FAQ. You can run the platform yourself, or have Isaphia's own practitioners operate it for you as a managed service, which is how most teams without a dedicated security headcount use it.

The reason we build it this way is that Isaphia's other work is offensive security: penetration tests, red-team engagements, and OSINT investigations. Every module started as something we kept doing by hand on client engagements. When Helios ranks a finding first, that ordering reflects what a team that breaks into networks actually reaches for — not a generic severity score.

If you want to see this against your own environment rather than read about it, the fastest starting point is a scoped walkthrough.

Frequently asked questions

What is attack surface management?

Attack surface management (ASM) is the practice of continuously discovering everything your organization exposes that an attacker could reach, then tracking and reducing it. External ASM covers your internet-facing footprint — domains, IP ranges, cloud storage, login portals, forgotten test environments. Internal ASM covers what is reachable once someone is already inside your network. The defining feature is that discovery is continuous and attacker-driven, rather than a point-in-time list maintained by hand.

Is attack surface management enough on its own?

Usually not. ASM tells you what is exposed, but not whether anyone is preparing to use it. A leaked employee password sold online is invisible to ASM, and a misconfigured cloud storage bucket is a configuration problem rather than an exposed host. In practice ASM works best combined with cyber threat intelligence (CTI), which watches for leaked credentials and data about your organization, and cloud security posture management (CSPM), which checks how your cloud accounts are configured. Together these three give you the full picture of what an attacker could use.

Does Canadian privacy law require attack surface management?

No Canadian law names attack surface management as a required control. PIPEDA requires organizations to protect personal information with safeguards appropriate to its sensitivity, and requires reporting breaches to the Office of the Privacy Commissioner where there is a real risk of significant harm, notifying affected individuals, and keeping a record of every breach for 24 months after determining it occurred. You cannot safeguard, assess, or report on systems you do not know you have, which is why asset discovery underpins compliance in practice even though it is not named in the statute.

Does my security data have to stay in Canada?

For most private-sector organizations, no. PIPEDA permits transferring personal information outside Canada provided the organization uses contractual or other means to give it a comparable level of protection, and is transparent about the practice. Requirements are stricter in the public sector and in some provinces, and many Canadian organizations adopt Canadian data residency as policy regardless, because it simplifies procurement, vendor review, and answering questions from customers and regulators.

What does OSFI B-13 expect around attack surface?

OSFI Guideline B-13 (Technology and Cyber Risk Management), in force since January 2024, applies to federally regulated financial institutions. It sets expectations that an institution maintains a current inventory of its technology assets and manages technology and cyber risk across their lifecycle. A complete, continuously updated asset inventory is foundational to meeting that expectation. B-13 is often read alongside Guideline B-10 on third-party risk management, which is relevant when your exposure includes systems operated by vendors.

What is a Canadian-built alternative to the large US ASM vendors?

Helios by Isaphia is a Canadian-built unified exposure management platform. It combines External ASM, Internal ASM, CTI, and CSPM against one shared asset inventory, so external exposure, internal reachability, leaked credentials, and cloud misconfiguration are correlated rather than sitting in four separate tools. Isaphia is headquartered in Toronto, Canadian data residency is the default across all four modules, and the platform can be run by your own team or operated for you as a managed service.

See your exposure, mapped to Canadian requirements

We will walk through what is exposed today — outside, inside, and in your cloud — and what to fix first. Canadian team, Canadian data residency.

Book a Scoped Walkthrough