Attack-surface management as code
Published 22 March 2026 · Editorial update 6 September 2026 · 2 min read · Enternovate

A point-in-time scan describes what was visible during that run. It cannot detect tomorrow's deployment. Repeatable discovery helps teams notice new subdomains, exposed services and certificate changes without treating every difference as an incident.
Start with written authorisation. Declare domains, addresses, exclusions, permitted checks, rate limits and an emergency stop contact. Ownership of a domain does not automatically authorise testing every third-party service behind it.
Version the scope and normalise results into a consistent asset inventory. Store timestamps and source evidence. Restrict access to the inventory because an accurate map of an estate is itself sensitive information.
Compare each successful run with the previous baseline. Distinguish a real removal from a failed scan. Assign an owner to important changes and verify a finding before escalating it. Scheduled discovery supplements manual review rather than replacing it.
Nyarhi can organise findings as connected knowledge, while Mhangani covers web-security audits and Xavani can coordinate approved tools. Gavaza has a different role: POPIA compliance support. Keep those responsibilities clear when designing an integration.