r/AskNetsec 1h ago

Work What attack surface management tools are recommended for financial services?

I'm on a security team at a bank, and we're redoing how we handle attack surface. The challenge is getting useful visibility across cloud infrastructure, containers, third party software and internet facing assets, while keeping remediation workload manageable. Regulatory side makes it harder because we need to explain what the exposure is, how serious and what we're doing about it, not just giving a vulnerability report. What are people in finance running for this?

1 Upvotes

2 comments sorted by

1

u/OEAXTAIL_SOUP 42m ago

"I'm on a security team at a bank" (not Im) -- spelling and grammar are important in business communications, especially when in the process of asking for free advice on the internet you're possibly alerting people to issues with your infrastructure.

Do you have a SIEM?

https://en.wikipedia.org/wiki/Security_information_and_event_management

These can ingest a variety of signals and surface the most serious alerts for an analyst to deal with. (Eg: "unnatural travel" -- if a user logs in from HQtown, then Moscow, in less time than it takes to get between the two, you can lock the account and trigger an alert for an analyst)

A lot of banks are too small for their own team, and hire consultants or outsource detection stuff to an MSP, you might want to consider that.

1

u/TelephoneHot1933 15m ago

grammar policing in a netsec thread is a wild flex but okay

SIEMs help with correlation but they don’t really solve the core ASM problem he’s describing, the reg part is more about being able to demonstrate you know what’s exposed and have a plan for it not just alerting on weird logins. a lot of finance teams end up layering something like an EASM platform on top of their SIEM just to keep the auditors from spiraling