<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-CA"><generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator><link href="https://isaphia.com/feed.xml" rel="self" type="application/atom+xml" /><link href="https://isaphia.com/" rel="alternate" type="text/html" hreflang="en-CA" /><updated>2026-07-21T16:55:16+00:00</updated><id>https://isaphia.com/feed.xml</id><title type="html">Isaphia Insights</title><subtitle>Practitioner notes from Isaphia Security on attack surface management, threat intelligence, penetration testing, and real-world offensive security.</subtitle><author><name>Isaphia Security Team</name></author><entry><title type="html">Attack Surface Management Doesn’t Stop at the Firewall</title><link href="https://isaphia.com/blog/internal-asm-module/" rel="alternate" type="text/html" title="Attack Surface Management Doesn’t Stop at the Firewall" /><published>2026-06-26T15:00:00+00:00</published><updated>2026-06-26T15:00:00+00:00</updated><id>https://isaphia.com/blog/internal-asm-module</id><content type="html" xml:base="https://isaphia.com/blog/internal-asm-module/"><![CDATA[<p>For years, attack surface management has meant one thing: looking at your company the way an attacker on the <em>outside</em> does. What domains do you own? What login portals, servers, and forgotten subdomains are exposed to the internet? That outside-in view is the foundation of <strong>Isaphia ASM + CTI</strong>, and it catches the doors and windows you didn’t know were unlocked.</p>

<p>But here’s the uncomfortable truth: attackers don’t stop at the front door. Once they get a foothold — a phished password, a vulnerable web app, an infected laptop — they’re <em>inside</em> your network. And the inside of most networks is a very different place from the polished perimeter. That’s the gap <strong>Internal ASM</strong> is built to close.</p>

<blockquote>
  <p>👉 <strong>New to ASM and CTI?</strong> Start with our plain-English primer: <a href="/blog/what-is-asm-and-cti/"><strong>What is ASM? What is CTI? And Why You Need Both →</strong></a></p>
</blockquote>

<h2 id="the-inside-of-your-network-is-its-own-attack-surface">The Inside of Your Network Is Its Own Attack Surface</h2>

<p>Think of external ASM as checking every door and window on the outside of a building. It’s essential — but it tells you nothing about what’s <em>inside</em>. And inside is where the real damage happens.</p>

<p>Once an attacker is past the perimeter, they don’t go straight for the crown jewels. They look around. They map the network, find the old server nobody patches, the file share with weak protocols, the workstation still running software from a decade ago — and they use those to move from one machine to the next until they reach something valuable. Security teams call this <em>lateral movement</em>. It’s how a single compromised laptop becomes a company-wide ransomware incident.</p>

<p>The problem is that most companies have <strong>no map of their own internal network.</strong> They know roughly what’s out there on the internet, but the inside is a fog — full of legacy systems, forgotten devices, and services that have been quietly running on default settings for years. You can’t defend what you can’t see, and inside the firewall, most organizations are flying blind.</p>

<h2 id="what-internal-asm-does">What Internal ASM Does</h2>

<p>Internal ASM extends the same outside-in discipline of attack surface management to the <em>inside</em> of your network. You deploy one or more lightweight <strong>collectors</strong> — small, safe agents — inside your environment. They quietly map what’s actually there and report it back to your Isaphia dashboard:</p>

<ul>
  <li><strong>Assets</strong> — every device, server, and workstation the collectors can see on the internal network.</li>
  <li><strong>Services</strong> — what each of those machines is actually running, and on which ports.</li>
  <li><strong>Sites and collectors</strong> — so you can see coverage across multiple offices, data centers, or network segments.</li>
  <li><strong>Findings</strong> — the part that matters most: the dangerous, exploitable problems hiding in plain sight, ranked by severity and tied automatically to the public vulnerability (CVE) that explains each one.</li>
</ul>

<p>It’s the same idea that makes external ASM valuable — <em>you can’t protect what you don’t know you have</em> — pointed at the half of your attack surface that lives behind the firewall.</p>

<h2 id="the-findings-attackers-are-counting-on">The Findings Attackers Are Counting On</h2>

<p>This is where Internal ASM earns its keep. When the collectors map an internal network, they surface exactly the kind of weaknesses attackers look for first — the ones that make lateral movement easy:</p>

<ul>
  <li><strong>EternalBlue (MS17-010)</strong> — the wormable flaw behind WannaCry, still alive on unpatched legacy systems years later.</li>
  <li><strong>BlueKeep (CVE-2019-0708)</strong> — a “wormable” Remote Desktop vulnerability that lets an attacker take over a machine with no password at all.</li>
  <li><strong>SMBv1 still enabled</strong> — an ancient file-sharing protocol that should have been retired long ago, and a favorite highway for ransomware spreading machine-to-machine.</li>
  <li><strong>Plaintext services like Telnet</strong> — logins sent across the network with no encryption, so anyone already inside can simply read the password as it goes by.</li>
</ul>

<p>None of these would ever appear on an <em>external</em> scan, because they live inside the network. But to an attacker who’s already gotten in, they’re a gift — the difference between being stuck on one machine and owning the entire environment. Internal ASM finds them first, labels each one <strong>Critical</strong> or <strong>High</strong>, and correlates it to the known CVE so your team knows exactly what it is and why it matters.</p>

<h2 id="one-picture-external-internal-and-what-attackers-already-know">One Picture: External, Internal, and What Attackers Already Know</h2>

<p>Internal ASM is one layer of a larger picture. <strong>Isaphia ASM + CTI</strong> gives you all three in one place:</p>

<ul>
  <li><strong>External ASM</strong> — what you expose to the internet (the attacker’s way <em>in</em>).</li>
  <li><strong>Internal ASM</strong> — what’s reachable once they’re inside (the attacker’s way <em>around</em>).</li>
  <li><strong>CTI</strong> — what’s already being said, sold, or leaked about you on the dark web (what the attacker already <em>knows</em>).</li>
</ul>

<p>An attack is rarely a single event. It’s a chain: a leaked password (CTI) used against an exposed login portal (external ASM) that gives an attacker a foothold they then use to pivot across a flat, unpatched internal network (internal ASM). Seeing only one link in that chain leaves you guessing about the rest. Seeing all three — in one dashboard — is what lets you break the chain before it reaches anything that matters.</p>

<h2 id="what-you-should-do">What You Should Do</h2>

<h3 id="1-map-your-inside-not-just-your-outside">1. Map your inside, not just your outside</h3>

<p>If you’ve already got visibility into your external footprint, the internal network is the obvious blind spot to close next. You almost certainly have more there than you think.</p>

<h3 id="2-hunt-down-the-legacy-systems-first">2. Hunt down the legacy systems first</h3>

<p>EternalBlue, BlueKeep, SMBv1, plaintext logins — these are the findings that turn a small incident into a catastrophic one. Prioritize retiring or patching them above almost anything else.</p>

<h3 id="3-assume-the-perimeter-will-be-breached">3. Assume the perimeter will be breached</h3>

<p>Modern security planning doesn’t assume the firewall holds. It assumes an attacker eventually gets in — and asks how far they can get once they do. Internal ASM answers that question with evidence instead of hope.</p>

<h3 id="4-make-it-continuous">4. Make it continuous</h3>

<p>Networks change every day — new devices, new services, a contractor’s laptop, a server spun up “just for testing.” A one-time look goes stale fast. Continuous internal discovery is what keeps the map honest.</p>

<h2 id="the-bottom-line">The Bottom Line</h2>

<p>Your firewall isn’t a wall — it’s a door, and doors get opened. The companies that weather an intrusion aren’t the ones who kept every attacker out forever; they’re the ones who could <em>see</em> their own network well enough to stop a foothold from becoming a disaster.</p>

<p>Internal ASM gives you that view. Not the polished outside the world sees — the real inside an attacker would, the moment they get past the perimeter.</p>

<h2 id="how-isaphia-helps">How Isaphia Helps</h2>

<p><strong>Isaphia ASM + CTI</strong> sees your attack surface from every angle: what you expose to the internet, what’s reachable inside your network, and what attackers already know about you on the dark web — all in one dashboard, with every critical finding tied to the vulnerability that explains it.</p>

<p>You can see what’s exposed about your company right now, for free. No credit card. No sales call. Sign up and find out what attackers already see.</p>

<p>👉 <a href="https://app.isaphia.com/signup"><strong>Start your free trial at app.isaphia.com/signup</strong></a></p>

<hr />

<p><em>Isaphia is an attack surface management and threat intelligence platform that helps organizations discover, monitor, and protect their external and internal digital footprint — before attackers exploit it.</em></p>]]></content><author><name>Isaphia Security Team</name></author><category term="Attack Surface" /><category term="Risk" /><summary type="html"><![CDATA[Isaphia ASM + CTI sees inside the firewall. Internal ASM deploys lightweight collectors on your network to map the assets, services, and dangerous legacy systems attackers pivot to once they get in — and ties them to known CVEs automatically.]]></summary></entry><entry><title type="html">What’s Leaking About Your Company on the Dark Web Right Now</title><link href="https://isaphia.com/blog/what-leaks-on-the-dark-web/" rel="alternate" type="text/html" title="What’s Leaking About Your Company on the Dark Web Right Now" /><published>2026-06-22T15:00:00+00:00</published><updated>2026-06-22T15:00:00+00:00</updated><id>https://isaphia.com/blog/what-leaks-on-the-dark-web</id><content type="html" xml:base="https://isaphia.com/blog/what-leaks-on-the-dark-web/"><![CDATA[<p>Right now, somewhere on a forum you’ll never visit, there’s a good chance someone is offering a list of email-and-password combinations that belong to your employees. Not because your company was hacked. Because <em>somewhere else</em> was — a service one of your staff signed up for with their work email — and the fallout rolled downhill to you.</p>

<p>Most companies have no idea. They’re watching their own front door while their keys are being copied in a building across town.</p>

<blockquote>
  <p>👉 <strong>New to ASM and CTI?</strong> Start with our plain-English primer: <a href="/blog/what-is-asm-and-cti/"><strong>What is ASM? What is CTI? And Why You Need Both →</strong></a></p>
</blockquote>

<h2 id="where-the-leaks-actually-come-from">Where the Leaks Actually Come From</h2>

<p>The phrase “dark web” conjures up hooded figures and elaborate hacks. The reality is more mundane — and far more common.</p>

<p>Most of what leaks about your company never involves your company being breached at all:</p>

<ul>
  <li><strong>Third-party breaches.</strong> An employee used their work email to sign up for a marketing tool, a fitness app, a forum, a conference site. That service got breached. Now their work email — and often the password they reused — is in a dump being traded online.</li>
  <li><strong>Infostealer malware.</strong> A laptop (sometimes a personal one) gets infected with software that quietly harvests every saved password in the browser. Those bundles, called “stealer logs,” are sold in bulk and include the exact login URLs.</li>
  <li><strong>Misconfigured cloud storage.</strong> A spreadsheet, a backup, a customer export left in a storage bucket with no password. It gets found, copied, and listed.</li>
  <li><strong>Accidental exposure.</strong> Credentials hard-coded into a public code repository. An internal document attached to a public support ticket. A database left open to the internet for “just a few days.”</li>
</ul>

<p>None of these announce themselves. There’s no alarm, no email, no breach notification. The data simply appears in places you’re not looking — and stays there.</p>

<h2 id="why-leaked-credentials-are-so-dangerous">Why Leaked Credentials Are So Dangerous</h2>

<p>A single leaked password might sound minor. It isn’t — for one reason: <strong>people reuse passwords.</strong></p>

<p>When an attacker buys a dump of leaked credentials, they don’t manually try each one. They feed the whole list into automated tools that test those email-and-password pairs against hundreds of other services — your email portal, your VPN, your cloud admin console, your payroll system. This is called <em>credential stuffing</em>, and it’s one of the most common ways companies get breached today.</p>

<p>The math is brutally in the attacker’s favor. They don’t need every password to work. They need <em>one</em>. One employee who used the same password for a breached forum that they also use for the company VPN, and the attacker walks straight in through the front door — with valid credentials, looking exactly like a legitimate login.</p>

<p>No malware. No exploit. No alarm. Just a login.</p>

<h2 id="what-else-is-out-there-besides-passwords">What Else Is Out There Besides Passwords</h2>

<p>Credentials are the headline, but they’re not the whole story. The same threat intelligence sources that surface leaked passwords also reveal:</p>

<ul>
  <li><strong>Your company being discussed or targeted</strong> in attacker forums and marketplaces — sometimes before an attack, when access to your network is being advertised for sale.</li>
  <li><strong>Customer or employee data</strong> from a third-party breach that included your records.</li>
  <li><strong>Exposed API keys and tokens</strong> that grant access to your cloud services or payment systems.</li>
  <li><strong>Your domains and IP ranges showing up on blacklists</strong> — a sign your infrastructure may already be compromised and sending spam or hosting malicious content. (We wrote about that specific problem in <a href="/blog/ip-reputation-damaged/"><strong>Your Company’s IP Reputation May Be Damaged →</strong></a>.)</li>
</ul>

<p>Each of these is a piece of the picture an attacker builds <em>before</em> they ever touch you. The uncomfortable truth is that they often know more about your exposure than you do — because they’re looking, and you’re not.</p>

<h2 id="this-is-what-cti-is-for">This Is What CTI Is For</h2>

<p>This is exactly the gap <strong>Cyber Threat Intelligence (CTI)</strong> exists to close.</p>

<p>Where Attack Surface Management (ASM) tells you <em>what you own</em> on the internet, CTI tells you <em>what’s being said and sold about it</em> — continuously monitoring breach dumps, stealer logs, paste sites, dark web marketplaces, forums, and blacklists for any mention of your organization, your domains, your people, or your data.</p>

<p>The two work as a pair. ASM finds the exposed login portal; CTI finds the leaked password that opens it. One without the other leaves half the door unguarded. That’s why <strong>Isaphia ASM + CTI</strong> treats them as a single picture: your external footprint <em>and</em> everything attackers already know about it, in one place.</p>

<h2 id="what-you-should-do">What You Should Do</h2>

<h3 id="1-find-out-whats-already-leaked">1. Find out what’s already leaked</h3>

<p>You can’t react to what you can’t see. The first step is a simple one most companies skip: actually check whether your domains, employee emails, and credentials are already circulating. Most are surprised by what comes back.</p>

<h3 id="2-force-a-reset-on-exposed-accounts">2. Force a reset on exposed accounts</h3>

<p>Any credential that shows up in a leak should be treated as compromised — full stop. Reset it, and reset it everywhere that password may have been reused. This is the single highest-impact action you can take in an afternoon.</p>

<h3 id="3-turn-on-mfa-everywhere-it-matters">3. Turn on MFA everywhere it matters</h3>

<p>Multi-factor authentication is what turns a leaked password from a break-in into a non-event. If a stolen credential still needs a second factor the attacker doesn’t have, the leak is far less useful to them. Prioritize email, VPN, and any cloud admin console.</p>

<h3 id="4-kill-password-reuse">4. Kill password reuse</h3>

<p>Most leaked-credential attacks succeed because of reuse. A password manager and a clear policy against reusing work passwords on outside services removes the mechanism the entire attack depends on.</p>

<h3 id="5-make-the-monitoring-continuous">5. Make the monitoring continuous</h3>

<p>Leaks don’t happen on a schedule. A one-time check tells you about today; new dumps surface every week. Ongoing monitoring is the difference between learning about a leak when <em>you</em> find it versus when an attacker does.</p>

<h2 id="the-bottom-line">The Bottom Line</h2>

<p>The data is already out there for most companies — the only variable is who finds it first. If it’s you, a leaked password is a five-minute reset. If it’s an attacker, it’s the first step of a breach that looks, from the inside, exactly like a normal day.</p>

<p>You don’t get to choose whether you’re exposed. You only get to choose whether you’re watching.</p>

<h2 id="how-isaphia-helps">How Isaphia Helps</h2>

<p>Isaphia ASM + CTI continuously monitors breach dumps, stealer logs, dark web marketplaces, and blacklists for any sign of your organization — leaked credentials, exposed data, damaged IP reputation, mentions in attacker forums — and ties it directly to the external attack surface those leaks put at risk.</p>

<p>You can see what’s already leaking about your company right now, for free. No credit card. No sales call. Sign up and find out what attackers may already know.</p>

<p>👉 <a href="https://app.isaphia.com/signup"><strong>Start your free trial at app.isaphia.com/signup</strong></a></p>

<hr />

<p><em>Isaphia is an attack surface management and threat intelligence platform that helps organizations discover, monitor, and protect their external digital footprint — before attackers exploit it.</em></p>]]></content><author><name>Isaphia Security Team</name></author><category term="Threat Intel" /><category term="Dark Web" /><category term="Risk" /><summary type="html"><![CDATA[Leaked credentials, exposed customer data, and your company's name in attacker forums — most of it is already out there, and most companies never look. Here's what leaks, how it happens, and how to find out what attackers already know about you.]]></summary></entry><entry><title type="html">Why Your Cyber Insurance Premium Just Went Up (And What ASM Has to Do With It)</title><link href="https://isaphia.com/blog/cyber-insurance-premium-asm/" rel="alternate" type="text/html" title="Why Your Cyber Insurance Premium Just Went Up (And What ASM Has to Do With It)" /><published>2026-06-15T15:00:00+00:00</published><updated>2026-06-15T15:00:00+00:00</updated><id>https://isaphia.com/blog/cyber-insurance-premium-asm</id><content type="html" xml:base="https://isaphia.com/blog/cyber-insurance-premium-asm/"><![CDATA[<p>If your cyber insurance renewal quote arrived recently and the number made you blink twice, you’re not alone. Premiums have climbed sharply, coverage limits have shrunk, and the questionnaires have tripled in length. Underwriters are no longer interested in checkboxes — they want evidence.</p>

<p>And the evidence they want most is something most companies can’t actually produce: a complete, current picture of what they own on the internet.</p>

<blockquote>
  <p>👉 <strong>New to ASM and CTI?</strong> Start with our plain-English primer: <a href="/blog/what-is-asm-and-cti/"><strong>What is ASM? What is CTI? And Why You Need Both →</strong></a></p>
</blockquote>

<h2 id="what-changed-in-cyber-insurance">What Changed in Cyber Insurance</h2>

<p>For years, cyber insurance was easy to buy. You filled in a short form, ticked a few boxes about antivirus and backups, and a policy showed up in your inbox a few days later.</p>

<p>That market is gone.</p>

<p>After years of catastrophic ransomware losses, insurers have done the math. They’ve discovered that the businesses filing the biggest claims were often the ones most confidently ticking the boxes. The questionnaires didn’t reflect reality. Companies didn’t know what they didn’t know — and the insurer found out the expensive way.</p>

<p>So underwriters changed their approach. They started:</p>

<ul>
  <li><strong>Asking dramatically more detailed questions</strong> about your internet-facing assets.</li>
  <li><strong>Independently scanning your external footprint</strong> before issuing a quote.</li>
  <li><strong>Adding exclusions</strong> for incidents traced back to assets you failed to disclose or monitor.</li>
  <li><strong>Raising premiums or refusing renewal</strong> when what they see on their scan doesn’t match what you said on your application.</li>
</ul>

<p>In other words: your attack surface is now a line item on your insurance bill, whether you measure it or not.</p>

<h2 id="the-questions-underwriters-are-actually-asking">The Questions Underwriters Are Actually Asking</h2>

<p>Modern cyber insurance applications ask things like:</p>

<ul>
  <li>Do you maintain a continuously updated inventory of all internet-facing systems?</li>
  <li>Do you scan your external attack surface for vulnerabilities and exposures?</li>
  <li>Are all administrative interfaces (RDP, SSH, admin panels) protected and not exposed to the public internet?</li>
  <li>Do you have MFA on every internet-facing authentication endpoint?</li>
  <li>How quickly do you remediate critical vulnerabilities discovered on external systems?</li>
  <li>Have any of your credentials, domains, or IP ranges appeared in threat intelligence feeds in the last 12 months?</li>
</ul>

<p>Most companies answer these questions optimistically — because honestly, they don’t know. They’re describing the <em>intended</em> state of their environment, not the actual one.</p>

<p>The problem is that the underwriter often <em>does</em> know. They’re running their own external scans before they price the policy. When their findings don’t match your answers, you don’t get to explain. You get a higher premium, a tighter exclusion clause, or no policy at all.</p>

<h2 id="failure-to-maintain--the-exclusion-that-catches-everyone">“Failure to Maintain” — The Exclusion That Catches Everyone</h2>

<p>Buried in nearly every modern cyber policy is a clause that goes by names like “failure to maintain controls” or “failure to follow minimum required practices.” The wording varies. The effect is the same: <strong>if the breach happened through an asset or weakness you should have known about and failed to address, the insurer can deny the claim.</strong></p>

<p>The harshest part of that clause is the word <em>should</em>. You don’t have to have actually known. You only have to have reasonably been expected to know.</p>

<p>A forgotten subdomain pointing at an expired cloud bucket. A dev environment a contractor spun up two years ago and nobody decommissioned. An admin login page exposed on an old subsidiary domain. None of those things look like risk to the company that owns them — because the company doesn’t remember owning them.</p>

<p>To an insurer evaluating a claim after the breach, every one of those is “should have known.”</p>

<h2 id="why-asm-and-cti-are-now-insurance-tools">Why ASM and CTI Are Now Insurance Tools</h2>

<p>Attack Surface Management and Cyber Threat Intelligence — taken together — answer the questions your insurer is now asking, with evidence, on demand.</p>

<p><strong>ASM</strong> continuously discovers everything tied to your organization on the internet — domains, subdomains, IPs, cloud assets, exposed services, certificates, login portals. It gives you the inventory the questionnaire assumes you have.</p>

<p><strong>CTI</strong> continuously monitors threat intelligence feeds, blacklists, breach dumps, and dark web sources for any sign of your organization being mentioned, targeted, or already compromised — leaked credentials, damaged IP reputation, mentions in attacker forums. It gives you the visibility into “have you been targeted” that underwriters increasingly want to see.</p>

<p>Together, <strong>Isaphia ASM + CTI</strong> gives you:</p>

<ul>
  <li>A defensible, current inventory of internet-facing assets — so your questionnaire answers are accurate and provable.</li>
  <li>Early warning on the exposures underwriters scan for — so you can fix them before renewal, not explain them after.</li>
  <li>Documented evidence of continuous monitoring — exactly the kind of operational maturity that lowers premiums.</li>
  <li>A clear paper trail showing what you knew and when — the difference between a covered claim and a denied one.</li>
</ul>

<h2 id="what-you-should-do-before-your-next-renewal">What You Should Do Before Your Next Renewal</h2>

<h3 id="1-find-out-what-your-insurer-already-sees">1. Find out what your insurer already sees</h3>

<p>Underwriters use the same kind of external scanning that ASM platforms provide. You don’t want the first time you see your external footprint to be on their pricing call. See it first. Fix what you can. Have answers ready for what you can’t.</p>

<h3 id="2-reconcile-your-reality-with-your-application">2. Reconcile your reality with your application</h3>

<p>Pull up the cyber insurance questionnaire you filled out last year. Walk through each question. For every “yes,” ask whether you can actually prove it today. The gaps between <em>answered yes</em> and <em>can prove it</em> are your renewal risk.</p>

<h3 id="3-close-the-exposures-that-get-scored-hardest">3. Close the exposures that get scored hardest</h3>

<p>Exposed admin interfaces, missing MFA on external logins, expired certificates, known-vulnerable software on internet-facing systems — these are the high-impact findings that move premium math. Most are fixable in days once you know they exist.</p>

<h3 id="4-make-this-continuous">4. Make this continuous</h3>

<p>A point-in-time audit one month before renewal doesn’t help you. Your attack surface changes weekly. Insurers know that. The companies getting the best terms are the ones who can demonstrate ongoing visibility, not a single annual snapshot.</p>

<h2 id="the-bottom-line">The Bottom Line</h2>

<p>Cyber insurance has stopped being a paperwork exercise and become an operational test. Underwriters are asking you to prove that you know your environment and can defend it — and they have the tools to check.</p>

<p>You can’t insure what you can’t see. And increasingly, you can’t <em>afford</em> not to see it.</p>

<h2 id="how-isaphia-helps">How Isaphia Helps</h2>

<p>Isaphia ASM + CTI continuously discovers your external attack surface, monitors it against the same threat intelligence and blacklist data your insurer is checking, and gives you the documented, current picture of your environment that today’s underwriters require.</p>

<p>You can see your own attack surface and threat exposure right now, for free. No credit card. No sales call. Sign up and see exactly what your insurer is going to see — before they do.</p>

<p>👉 <a href="https://app.isaphia.com/signup"><strong>Start your free trial at app.isaphia.com/signup</strong></a></p>

<hr />

<p><em>Isaphia is an attack surface management and threat intelligence platform that helps organizations discover, monitor, and protect their external digital footprint — before attackers exploit it.</em></p>]]></content><author><name>Isaphia Security Team</name></author><category term="Attack Surface" /><category term="Threat Intel" /><category term="Risk" /><summary type="html"><![CDATA[Cyber insurance premiums are climbing, coverage is shrinking, and underwriters are asking harder questions. Here's why your attack surface is now a line item on your insurance bill — and what to do about it.]]></summary></entry><entry><title type="html">What is ASM? What is CTI? And Why You Need Both</title><link href="https://isaphia.com/blog/what-is-asm-and-cti/" rel="alternate" type="text/html" title="What is ASM? What is CTI? And Why You Need Both" /><published>2026-06-09T15:00:00+00:00</published><updated>2026-06-09T15:00:00+00:00</updated><id>https://isaphia.com/blog/what-is-asm-and-cti</id><content type="html" xml:base="https://isaphia.com/blog/what-is-asm-and-cti/"><![CDATA[<p>Security has an acronym problem. EDR, XDR, SIEM, SOAR, IAM, ASM, CTI, ZTNA, CASB — most leadership teams nod along during vendor demos and walk out unsure which of those eighteen letters they actually need to budget for next quarter.</p>

<p>This post is about two of them: <strong>ASM</strong> and <strong>CTI</strong>. The reason we’re starting here is simple. Most of the other categories assume you already know two things — <em>what you have on the internet</em>, and <em>what attackers think of it</em>. ASM and CTI are how you find out.</p>

<p>Here’s what each one actually means, why every business should understand both, and what changes when you have them working together.</p>

<h2 id="what-is-asm-attack-surface-management">What is ASM (Attack Surface Management)?</h2>

<p>Your <strong>attack surface</strong> is everything an attacker can see from the outside. The websites you host. The mail servers, login portals, file shares, dev environments, marketing landing pages, third-party tools, forgotten subdomains, expired SSL certificates, the random VM someone spun up for a vendor pilot two years ago and never shut down.</p>

<p><strong>Attack Surface Management</strong> is the practice of continuously discovering all of that — and keeping it under control.</p>

<p>Sounds simple. It almost never is, for one reason that surprises most teams:</p>

<blockquote>
  <p>Your attack surface is <em>always larger than your asset inventory</em>. Often by a lot.</p>
</blockquote>

<p>The IT spreadsheet that says you own 47 domains and 200 IPs is rarely wrong on the things it lists. It’s wrong on what it <em>doesn’t</em> list. Cloud accounts spun up by individual developers. Marketing landing pages registered under personal credit cards. Subsidiaries acquired without an IT integration step. Vendor portals branded with your name that you’ve never logged into. SaaS tools your sales team signed up for last week.</p>

<p>Every one of those is a door an attacker can knock on. None of them are in the inventory.</p>

<p>ASM, done properly, is the discipline of finding all of those doors — continuously, not as a one-time audit — and giving you a working map of what attackers can actually see. The same map they’re already building about you, except now you have it too.</p>

<h2 id="what-is-cti-cyber-threat-intelligence">What is CTI (Cyber Threat Intelligence)?</h2>

<p>If ASM tells you <em>what you own</em>, <strong>CTI</strong> tells you <em>what the rest of the world knows about it</em>.</p>

<p>Threat intelligence is the broad category of information about threats, threat actors, and the state of the internet around them. The useful, business-relevant slice of it looks like this:</p>

<ul>
  <li><strong>Reputation feeds.</strong> Is one of your IPs on a spam blacklist? Is a domain you own flagged as a phishing site? Are you sending traffic that other security tools quietly block?</li>
  <li><strong>Leaked credentials.</strong> Have employee emails and passwords from your domain shown up in a recent breach dump?</li>
  <li><strong>Dark web and underground mentions.</strong> Is your company name appearing in marketplaces selling access, on ransomware leak sites, or in target lists?</li>
  <li><strong>Vulnerability and exploit chatter.</strong> Is a vulnerability in software you run being actively traded or exploited?</li>
</ul>

<p>A lot of “threat intelligence” sold today is really just news — scary articles about attacks happening to other people. That’s not what we mean. <strong>Useful CTI is signal that maps to a specific thing you own, with enough context that you can make a decision.</strong> “Your IP 198.51.100.42 was added to Spamhaus yesterday” is signal. “Ransomware is up 30% globally” is news.</p>

<p>CTI on its own can feel academic. Lots of data, lots of feeds, lots of “interesting” but no clear action. The thing that makes it actionable is knowing what to map it against — which is exactly the job of ASM.</p>

<h2 id="why-you-need-both">Why You Need Both</h2>

<p>Here’s the most important sentence in this post:</p>

<blockquote>
  <p><strong>ASM tells you what you own. CTI tells you what attackers think of what you own.</strong></p>
</blockquote>

<p>Either one alone gives you half the picture.</p>

<ul>
  <li><strong>ASM without CTI:</strong> a complete map of your external footprint, with no context about which parts of it are flagged, exposed, leaked, or already being targeted.</li>
  <li><strong>CTI without ASM:</strong> a firehose of “interesting” signals about threats and bad actors, with no way to tell which of them actually point at <em>you</em>.</li>
</ul>

<p>Together, they’re how you go from <em>guessing</em> to <em>knowing</em>. A concrete example — the same one we explored in our <a href="/blog/ip-reputation-damaged/">last post on IP reputation damage</a>:</p>

<p>Your sales team mentions that some outbound emails aren’t reaching customer inboxes. With ASM alone, you can see all your mail-sending IPs. With CTI alone, you can see that <em>some</em> IPs somewhere are on a blacklist — but you can’t tell which of them are yours. With both, you can immediately see that the IP your marketing automation tool uses was added to Spamhaus eight days ago, and that’s why sales emails are silently disappearing. Fix the underlying issue, request delisting, problem solved — in hours instead of months.</p>

<p>The same pattern repeats across every category of risk: leaked credentials, exposed dev environments, expired certificates, forgotten subdomains pointing at hijacked infrastructure. <strong>ASM finds what’s yours. CTI tells you which pieces are already being weaponized.</strong></p>

<p>That’s not a “nice to have” combination. For most businesses today, it’s the foundation everything else sits on.</p>

<h2 id="what-to-do-next">What to Do Next</h2>

<p>If you’ve never had a clean picture of your external attack surface and what threat intel says about it, the fastest way to find out is to look — for free.</p>

<p>Isaphia ASM + CTI does both, in one place. Sign up, point it at your domains, and you’ll see your real attack surface and what the internet thinks of it within minutes. No credit card. No sales call.</p>

<p>👉 <a href="https://app.isaphia.com/signup"><strong>Start your free trial at app.isaphia.com/signup</strong></a></p>

<hr />

<p><em>Isaphia is an attack surface management and threat intelligence platform that helps organizations discover, monitor, and protect their external digital footprint — before attackers exploit it.</em></p>]]></content><author><name>Isaphia Security Team</name></author><category term="Guide" /><category term="Attack Surface" /><category term="Threat Intel" /><summary type="html"><![CDATA[ASM tells you what you own on the internet. CTI tells you what attackers think of it. A plain-English guide to attack surface management and threat intelligence — what each one is, why they matter, and why they're stronger together.]]></summary></entry><entry><title type="html">Your Company’s IP Reputation May Be Damaged — And You Don’t Know It</title><link href="https://isaphia.com/blog/ip-reputation-damaged/" rel="alternate" type="text/html" title="Your Company’s IP Reputation May Be Damaged — And You Don’t Know It" /><published>2026-06-07T19:00:00+00:00</published><updated>2026-06-07T19:00:00+00:00</updated><id>https://isaphia.com/blog/ip-reputation-damaged</id><content type="html" xml:base="https://isaphia.com/blog/ip-reputation-damaged/"><![CDATA[<p>Most businesses focus on what they can see. Firewalls. Antivirus. Patched software. But there’s a silent threat hiding in plain sight — your IP reputation — and by the time you notice it, the damage is already done.</p>

<blockquote>
  <p>👉 <strong>New to ASM and CTI?</strong> Start with our plain-English primer: <a href="/blog/what-is-asm-and-cti/"><strong>What is ASM? What is CTI? And Why You Need Both →</strong></a></p>
</blockquote>

<h2 id="what-is-ip-reputation">What Is IP Reputation?</h2>

<p>Every device that connects to the internet does so through an IP address. Over time, those IP addresses build a reputation — good or bad — based on the traffic and behavior associated with them.</p>

<p>Threat intelligence feeds, spam databases, and security vendors constantly monitor and score IP addresses globally. If an IP gets flagged, it gets added to blacklists and blocklists that thousands of organizations and security tools rely on automatically.</p>

<p>Your emails, your traffic, your services — all judged by that score.</p>

<h2 id="how-does-an-ip-get-a-bad-reputation">How Does an IP Get a Bad Reputation?</h2>

<p>This is where most businesses are surprised. <strong>You don’t have to do anything wrong.</strong></p>

<p>Here’s how it happens:</p>

<h3 id="1-ip-history-you-didnt-create">1. IP History You Didn’t Create</h3>

<p>IP addresses get recycled. If your cloud provider or ISP assigned you an IP that a previous user abused — spamming, hosting malware, running botnets — that history follows the IP, not the previous owner. You inherited the damage.</p>

<h3 id="2-a-compromised-device-on-your-network">2. A Compromised Device on Your Network</h3>

<p>One infected laptop. One misconfigured server quietly sending spam. One employee clicking the wrong link. A single compromised device can get your entire IP range flagged before your security team sees a single alert.</p>

<h3 id="3-shadow-it-and-unknown-assets">3. Shadow IT and Unknown Assets</h3>

<p>Does your security team know every IP associated with your organization? Cloud instances spun up by developers, forgotten test environments, third-party vendors operating on your behalf — these all represent IP addresses tied to your name that you may not be monitoring.</p>

<h3 id="4-misconfigurations">4. Misconfigurations</h3>

<p>Open relays, misconfigured mail servers, and poorly secured APIs can be exploited by external attackers to send traffic through your infrastructure — getting you blacklisted for activity you never intentionally performed.</p>

<h2 id="what-actually-happens-when-your-ip-reputation-is-damaged">What Actually Happens When Your IP Reputation Is Damaged?</h2>

<p>The consequences are real and they compound over time:</p>

<ul>
  <li><strong>Your emails stop reaching inboxes.</strong> Sales outreach, customer communications, invoices — silently landing in spam folders. You never get a bounce notification. You just never get a reply.</li>
  <li><strong>Your traffic gets blocked.</strong> Security tools at your partners, customers, and vendors automatically block traffic from flagged IPs. Integrations break. API calls fail. Support tickets pile up with mysterious errors.</li>
  <li><strong>Your credibility takes a hit.</strong> Security-conscious organizations run reputation checks on vendors. A flagged IP range can quietly cost you deals you never knew you lost.</li>
  <li><strong>Attackers take notice.</strong> A damaged reputation can signal to threat actors that your infrastructure is poorly monitored — making you a more attractive target.</li>
</ul>

<h2 id="the-worst-part--there-is-no-alarm">The Worst Part — There Is No Alarm</h2>

<p>Unlike a data breach or a ransomware attack, IP reputation damage doesn’t announce itself. There’s no alert. No notification. No obvious moment where something goes wrong.</p>

<p>You find out when a customer asks why your emails look like spam. You find out when a partner says their firewall is blocking your traffic. You find out when someone else finds it for you — and by then, the damage has been accumulating for weeks or months.</p>

<h2 id="what-you-should-do-right-now">What You Should Do Right Now</h2>

<h3 id="1-discover-every-ip-associated-with-your-organization">1. Discover every IP associated with your organization</h3>

<p>Start with what you know — your office networks, your cloud infrastructure, your hosting providers. Then go deeper. What about your subsidiaries? Your remote work infrastructure? Your third-party vendors?</p>

<h3 id="2-check-them-against-threat-intelligence-feeds-and-blacklists">2. Check them against threat intelligence feeds and blacklists</h3>

<p>There are dozens of major blacklists and threat intelligence databases that track IP reputation. Each one has different data, different sources, and different criteria. A proper check covers all of them — not just one or two.</p>

<h3 id="3-investigate-every-flagged-ip--even-if-you-didnt-cause-it">3. Investigate every flagged IP — even if you didn’t cause it</h3>

<p>“We didn’t do it” is not a defense when your infrastructure is the one flagged. Investigate the source, remediate the issue, and submit removal requests to the relevant blacklists.</p>

<h3 id="4-dont-make-this-a-one-time-audit">4. Don’t make this a one-time audit</h3>

<p>IP reputation changes constantly. New threats emerge. New IPs get associated with your organization. New infrastructure gets spun up. Continuous monitoring is the only way to stay ahead of damage before it impacts your business.</p>

<h2 id="how-isaphia-helps">How Isaphia Helps</h2>

<p>Isaphia’s attack surface management and threat intelligence platform does this automatically. We discover the IPs associated with your organization — including ones you may not know about — and continuously monitor them against major threat intelligence feeds and blacklists.</p>

<p>When something gets flagged, you find out immediately. Not when a customer tells you. Not when a deal falls through. <strong>Immediately.</strong></p>

<p>The best part — you can see your own IP reputation right now, for free. No credit card. No sales call. Sign up and see what’s out there associated with your organization in minutes.</p>

<p>👉 <a href="https://app.isaphia.com/signup"><strong>Start your free trial at app.isaphia.com/signup</strong></a></p>

<hr />

<p><em>Isaphia is an attack surface management and threat intelligence platform that helps organizations discover, monitor, and protect their external digital footprint — before attackers exploit it.</em></p>]]></content><author><name>Isaphia Security Team</name></author><category term="Threat Intel" /><category term="Attack Surface" /><summary type="html"><![CDATA[Most businesses don't realize their IP reputation is silently damaged — until emails land in spam, partners block traffic, or deals quietly disappear. Here's how it happens and what to do.]]></summary></entry></feed>