Skip to content
Back to Blog
·6 min read·guides

Attack Surface Management India — Bachao.AI Methodology

Bachao.AI's ASM service for Indian enterprises: continuous external attack surface discovery, exposed credential monitoring, third-party risk monitoring. Pricing per asset class, not per endpoint.

Shouvik Mukherjee, Founder of Bachao.AI

Shouvik Mukherjee

Founder & CEO, Bachao.AI

Map Your Attack Surface

What this means for your business

Indian SMBs without documented security controls face 3× higher breach costs (IBM Cost of a Data Breach 2024). This guide helps you close that gap.

What Attack Surface Management actually does

Attack Surface Management (ASM) is what every CISO has always wanted: a continuously updated map of every internet-facing asset that an adversary might find, plus continuous monitoring for changes.

Most enterprises think they have a complete asset inventory. They don't. The reasons:

    1. Shadow IT — marketing or sales teams spin up subdomains for campaigns
    2. Acquired entities — security teams inherit unknown assets
    3. Forgotten dev/staging environments — created during projects, never decommissioned
    4. Cloud sprawl — multi-account growth across departments
    5. Vendor SaaS — sub-processors that handle company data
    6. Third-party DNS / certificates — legacy from agency relationships
ASM continuously discovers all of these and monitors for changes.

What Bachao.AI's ASM covers

External attack surface discovery:

    1. Subdomain enumeration via passive DNS + certificate transparency logs
    2. IP block discovery (legitimate ASN ownership + cloud ranges)
    3. Port scanning for exposed services
    4. Web application discovery + technology fingerprinting
    5. SSL/TLS certificate inventory
    6. DNS record changes detection
Exposed credential monitoring:
    1. Dark web monitoring for company email + employee credentials
    2. Code repository monitoring for leaked secrets
    3. Pastebin / leak site monitoring
    4. Stealer log monitoring (for credentials harvested by infostealers)
Third-party risk monitoring:
    1. Sub-processor inventory tracking
    2. Third-party vendor security posture
    3. Public security incidents at known vendors
    4. Vendor SaaS configuration drift
Continuous change detection:
    1. New asset discovery alerts
    2. Configuration changes on existing assets
    3. Service exposure changes (new open ports)
    4. Certificate expiry warnings
    5. DNS hijacking patterns

Discovery output

A typical first ASM discovery report includes:

    1. Assets you knew about: typically 60–80%
    2. Assets you didn't know about: typically 20–40%
    3. Critical exposures you didn't know about: typically 3–8 critical findings
Sample first-month findings from a recent engagement (mid-tier fintech):
    1. 41 subdomains active, 17 not in customer's inventory
    2. 3 forgotten staging environments with weak authentication
    3. 1 production database publicly accessible (legacy from cloud migration)
    4. 6 employee credentials on dark web (4 still valid)
    5. 2 sub-processors with active security incidents
    6. 8 SSL certificates expiring in next 30 days (3 unmanaged)

Know your vulnerabilities before attackers do

Run a free VAPT scan — takes 5 minutes, no signup required.

Book Your Free Scan

The engagement

Month 0 — Onboarding (2 weeks):

    1. Asset inventory baseline established
    2. Discovery scan baseline
    3. Alert routing configured (Slack + email + Jira)
    4. Initial findings triage workshop with customer's security team
Month 1+ — Continuous monitoring:
    1. 24×7 discovery scanning
    2. Daily new-asset and change alerts
    3. Weekly digest report
    4. Monthly review call
    5. Quarterly executive summary
Ad-hoc — Findings response:
    1. Critical findings escalated within 4 hours
    2. Bachao.AI security team available for triage support
    3. Remediation guidance per finding

Pricing

TierMonthly fee
Startup (single brand, <500 assets)₹1.5L
Growth (multi-brand, <2,000 assets)₹3L
Enterprise (multi-brand, multi-region, <10,000 assets)₹5L
CustomQuote
Pricing includes the platform, the analyst team, the alerting, and the monthly review cadence.

What you receive

    1. Continuously updated asset inventory dashboard
    2. Real-time alerts for new assets, changes, exposures
    3. Weekly digest of all activity
    4. Monthly executive report
    5. Findings triaged before reaching your team

When ASM bundles with other services

Many Bachao.AI ASM customers combine with:

    1. MSSP — ASM-discovered assets get monitoring coverage automatically
    2. vCISO — ASM findings feed into the quarterly risk register
    3. VAPT — ASM scope drives VAPT engagement scope

How to start

ASM engagement starts with a 60-minute scoping call. We confirm scope (brands, regions, asset classes), tier selection, alert routing. Onboarding starts within 1 week of contract.

Schedule the ASM scoping call →


Related: Case Study: Enterprise Reduced External Attack Surface 60% in 90 Days · ASM for Indian Fintech

Shouvik Mukherjee, Founder of Bachao.AI

Shouvik Mukherjee

Founder & CEO, Bachao.AI

Ex-enterprise architect turned cybersecurity founder. Built systems for Fortune 500s, now making enterprise-grade security accessible to every Indian business. Writes about threats targeting Indian SMBs, practical defenses, and the DPDP Act.

Connect on LinkedIn

Get cybersecurity insights for Indian SMBs

Weekly vulnerability alerts, DPDP compliance tips, and security guides. No spam — unsubscribe anytime.

We respect your privacy. Your email is never shared.

Discover what of yours is exposed to the internet

Free automated scan — risk score in under 2 hours. No credit card required.

Map Your Attack Surface
Find your vulnerabilitiesStart free scan →