ESPM: External Security Posture Management

See what attackers see: domains, email authentication, and internet-facing exposure.

Required for all clients

External Security Posture Management (ESPM) is the outside-in view of your business. It asks what a stranger on the internet can see and abuse: your domains, email authentication, and services left reachable from the public net.

Many Perth SMEs secure the office LAN and forget the public edge. Old VPN portals. Forgotten test sites. Weak or missing SPF, DKIM, and DMARC. Attackers start there because they do not need a key to the building.

Stride IT requires ESPM for every client. It feeds Continual Security Uplift with findings you can fix on a schedule, not a one-off pen test PDF that gathers dust.

What ESPM is

ESPM continuously checks your public attack surface. Think of it as a regular walk around the outside of the building, not only the locks on the desks inside.

Domain and brand discovery finds internet-facing assets tied to your names. That includes websites, mail hosts, remote access points, and forgotten systems that still answer when probed.

Email authentication posture covers SPF, DKIM, and DMARC. Those records tell receiving servers whether mail claiming to be from you is allowed to use your domain. Gaps make spoofing easier.

Exposure checks flag risky public services and weak configs: open remote admin paths, outdated portals, and services that should never have been left on the internet after a project ended.

Findings get prioritised. A missing DMARC policy and an abandoned remote desktop host are not the same urgency. ESPM should push clear owners and due dates into your uplift backlog.

It is posture management, not a single scan. Drift happens. Someone stands up a temporary site and forgets it. ESPM is how you notice before a stranger does.

Plain English reporting matters. Your operations manager should understand “this host should not be public” without needing a security glossary. If the output is only raw scanner noise, nobody will act.

Why it matters for Perth SMEs

Smaller firms often inherit years of ad-hoc IT. A previous provider left a portal online. A marketing agency spun up a staging site. Nobody owns the cleanup.

Domain spoofing hurts trust fast. Clients in mining services, professional firms, and local retail all rely on email for invoices and variations. Fake mail from “your” domain is expensive to unwind.

Remote work across WA means more services get published “just for now”. Temporary often becomes permanent. ESPM keeps the temporary list honest.

Cyber insurers ask about internet-facing risk. Being able to show ongoing external checks is stronger than saying you had a scan two years ago.

Perth attackers and opportunistic bots do not care that you are a fifteen-person team. Automated scans hit everyone. Your job is to shrink what answers back.

Many WA businesses use multiple brand names, trading names, and project domains. Each one can carry mail or web exposure. ESPM should cover the names customers actually see, not only the primary company domain.

Day-to-day reality

You should expect a living inventory of what is public: domains, subdomains, and known exposed services. New findings appear when something changes, not only at annual audit time.

Email auth gets reviewed when you add senders: newsletters, CRM mail, accounting systems. Each new sender can break SPF or leave DMARC in monitor-only forever.

When a finding is high risk, your MSP should open a fix with a named owner. “Noted” is not a fix. Closing the port or retiring the host is a fix.

Quarterly uplift reviews should show external posture trending cleaner: fewer open risks, DMARC moving toward enforcement where ready, no surprise assets.

Marketing and ops changes need a simple rule: anything new on the internet gets registered with IT the same week it goes live.

DNS ownership should be clear. If only one departed contractor knew the registrar login, you do not control your outside face. ESPM work often starts by fixing that boring control problem.

Common failure modes

Treating SPF, DKIM, and DMARC as a one-hour project that never gets revisited after the first senders are added.

Leaving DMARC on “none” forever so spoofed mail still lands without friction.

Shadow IT websites and remote tools stood up on personal credit cards, then abandoned still online.

Assuming the firewall at the office covers cloud apps and third-party hosts that use your brand.

Buying an external scan once for insurance paperwork, then ignoring new exposures for eighteen months.

No owner for domain renewals and DNS changes, so records drift and nobody notices until mail fails or spoofing succeeds.

Ignoring lookalike domains and brand misuse signals when they appear, because “that is not our server”. Reputation damage does not care who owns the fake host.

Questions for your IT provider

Do you continuously monitor our public domains and internet-facing services, or only run occasional scans?

Can you show our current SPF, DKIM, and DMARC status in plain English, including what still blocks enforcement?

How are new findings triaged into fixes with owners and dates?

What happens when marketing or a vendor adds a new mail sender or public site?

How does ESPM show up in our Continual Security Uplift reviews alongside Secure Score?

If something high risk appears overnight, who gets alerted and how fast?

Which trading names and project domains are in scope, and how do we add a new one?

Fit with Continual Security Uplift and Business Premium

Business Premium hardens identity, devices, and mailbox filtering inside your tenant. ESPM watches what the world can already see outside that tenant.

In uplift, Baseline captures external exposure early. Stabilise and Uplift close the worst gaps. Continual reviews stop new holes from becoming permanent.

ESPM pairs with SAT and email protections. Strong filters and trained staff help when spoofing still occurs. Hardening SPF, DKIM, and DMARC makes spoofing harder in the first place.

It also pairs with SIEM and detection. Fewer open services means fewer easy entry points for the incidents those tools must catch.

Stride IT requires ESPM for every client. If you will not address what attackers can already see, we are not the right fit. Outside-in posture is part of the Standard, not an optional report.

The Stride IT Security Standard treats external posture as finishable work with owners. You should leave each quarter with fewer public surprises, not a thicker unread binder.

ESPM is how you stay honest about your public face: domains, email authentication, and services that should not still be online. For Perth SMEs in Continual Security Uplift, it turns “we think we are fine” into a checked list that keeps getting shorter.

Further reading

What Is External Security Posture Management (ESPM) for Perth Businesses?

A longer owner’s guide on the same topic, written for Perth businesses comparing providers.

Read the blog

WHAT YOU GET

Fewer “we did not know that was still online” moments.

Harder for attackers to spoof your domain or probe forgotten systems.

External posture tracked alongside Secure Score, not as a one-off pen test PDF.

FREQUENTLY ASKED QUESTIONS

Is ESPM required for Stride IT clients?

Yes. External Security Posture Management (ESPM) is required for every client under the Stride IT Security Standard. It is not an optional add-on. If you will not run it, we decline.

How does ESPM fit Our One Plan?

ESPM is part of the required detection and posture stack inside Our One Plan. It sits on top of Microsoft 365 Business Premium. We baseline it in the Baseline Review, implement it during Stabilise and Uplift, and review it in quarterly Continual reviews.

Do you sell this as a standalone product?

No. This stack runs as part of Our One Plan with Continual Security Uplift. We do not cherry-pick detection controls while leaving the rest of the Standard unfinished.

THE REST OF THE STACK

APPLY FOR BASELINE

We confirm Business Premium readiness and the full required stack, including ESPM, before we start.

Apply for Our One Plan

Still here? Apply for Our One Plan.

Baseline is an application, not a shopping cart. We confirm Business Premium readiness, the required stack (EDR, ITDR, SIEM, SAT, ESPM, ISPM), map Secure Score to the Stride IT Security Standard, and show a tailored uplift plan and schedule. If you will not support the minimum, we decline. Early, clearly, and without drama.