EASMAsset Discovery & Inventory
We find every internet-facing asset connected to your organisation.
We continuously discover your external footprint and compile everything into a single inventory — updated daily.
1.35
High-risk findings per scan — 69% more than internal networks
750,000+
Nordic scans in BSO 2025 State of Vulnerability Management
Trusted by:
Asset Discovery & Inventory — EASM
Most organisations underestimate the size of their external footprint.
What is Asset Discovery & Inventory?
We continuously discover your external footprint — forgotten campaign subdomains, undecommissioned cloud assets, and third-party integrations. Everything compiled into a single inventory updated daily, whether your team is tracking it or not.
How does BlackstoneOne help?
A vulnerability scan can only cover what it knows exists. Outdated third-party components and vendor-supplied software accounted for 41% of all external findings in 2025 — mostly on assets no one was actively watching.
How it works
1
Your known assets
Domains, IPs, org names
2
Automated discovery
Subdomains, cloud, 3rd-party
3
Asset classification
Type, owner, exposure level
4
Daily inventory update
New assets flagged instantly
From the 2025 State of Vulnerability Management Report
The numbers behind your external footprint..
1.35
High-risk findings per scan on internet-facing systems
BSO 2025
69%
More risk on external vs. internal networks
BSO 2025
41%
Of findings from outdated 3rd-party components — #1 for 2nd year
BSO 2025
NIS2 & compliance frameworks
BlackstoneOne’s platform gives you the overview, continuous risk management, and documentation to support compliance requirements like NIS2, other frameworks like ISO 27000 series, CIS Controls, NIST, and GDPR.
What gets discovered
Subdomains & forgotten assets
Old campaign sites, staging environments, and subdomains that were never decommissioned.
Cloud & shadow IT
Cloud resources spun up outside IT visibility — still part of your attack surface.
Third-party integrations
Vendor-supplied software and APIs connected to your systems, visible to attackers.
Inventory updates
Every new asset logged automatically. Your inventory stays current without manual work.
The difference it makes
✗ Without asset discovery
✗ Unknown subdomains stay exposed indefinitely
✗ Decommissioned assets remain accessible
✗ Vulnerability scans miss unknown assets
✗ No NIS2 asset documentation trail
✓ With BlackstoneOne
✓ Full external footprint mapped and updated daily
✓ New assets flagged the moment they appear
✓ Nothing falls outside your scan coverage
✓ Documented inventory supports NIS2 compliance
The platform

Your complete external inventory, in one place.

Every discovered asset — classified, scored, and updated daily. No manual input required.

THE DASHBOARD

WE HELP YOU FIND AND UNDERSTAND YOUR VULNERABILITIES

SCAN AND SECURE YOUR EXTERNAL INFRASTRUCTURE INSIDE AND OUT

Get an overview of your vulnerabilities and internet-facing assets today.

We offer a 30 days free trial of our security platform.

START SCANNING
BlackstoneOne Cyber Exposure Management Platform
Get a free trial
See your full external footprint in 24 hours.

Frequently asked
How does BSO find assets we don't know about?
We start from known domains and IPs, then map connected subdomains, cloud resources, and third-party integrations — the same way an attacker would.
How often is the inventory updated?
Daily. New assets are flagged automatically — no manual rescans needed.
What types of assets are included?
Domains, subdomains, IPs, open ports, SSL certificates, cloud assets, and third-party integrations.
Does this help with NIS2 compliance?
Yes. NIS2 requires an accurate IT asset inventory. BSO keeps it updated automatically with a documented audit trail.