Start outside the building
Most SME security conversations start with laptops and passwords. Sensible. Incomplete. Attackers often begin with what answers on the public internet: your domains, mail setup, and leftover remote services.
External Security Posture Management (ESPM) is the discipline of checking that outside view on a schedule, then fixing what should not be there. It is not a scare PDF from 2022. It is a living list.
For how Stride IT defines required ESPM under uplift, see /security-standard/security-stack/espm/ and /one-plan/.
Email authentication without the jargon fog
SPF says which servers may send mail for your domain. DKIM adds a cryptographic signature so receivers can check the message was not quietly altered in transit. DMARC tells receivers what to do when SPF or DKIM fail, and where to send reports.
When those records are missing, weak, or stuck on monitor-forever, scammers have an easier time sending mail that looks like it came from you. Your clients ring you angry. Your bank flags you. Trust burns fast.
Perth professional firms and trade businesses feel this hard because so much money movement still starts in email. ESPM keeps auth posture visible when you add newsletters, CRMs, and accounting senders that change DNS needs.
A practical tip: every new outbound mail system should trigger an SPF and DKIM check the same week it goes live. Waiting for “the big DMARC project” is how gaps stay open for years.
Forgotten doors are still doors
A staging site from a rebrand. A remote access tool left open after a project. An old VPN portal on a leftover public IP. None of these need a clever attacker. Automated scans find them.
ESPM aims to discover assets tied to your domains and brands, then flag exposures that matter. The win is not a longer report. The win is a shorter list of open risks with owners.
Shadow IT makes this worse. Someone in sales buys a tool with a public form “for the campaign”. IT never hears. Six months later the campaign is dead and the form is still collecting junk — or worse.
Trading names and project microsites count. If customers type that name into a browser, attackers will too. Scope ESPM to the brands you actually use in the market.
What “continuous” should mean
A one-off external assessment answers yesterday’s question. Continuous posture answers today’s. New subdomains appear. Certificates change. Vendors publish portals using your brand.
Your provider should show new findings as they appear, with severity and a fix path. High-risk items need alerts, not a footnote in next quarter’s slide pack.
Quarterly uplift reviews should prove the trend: fewer stale exposures, DMARC moving toward real enforcement when ready, no surprise hosts.
Continuous also means clear DNS and registrar ownership. If nobody can change records quickly, you cannot close findings quickly. Boring control problems sit under many “security” failures.
Questions that cut through MSP theatre
Show me our public asset list as of this month. If they cannot, they are guessing.
Show me SPF, DKIM, and DMARC in plain English, including what still blocks enforcement.
Who owns each open finding, and what is the due date?
What happens when marketing launches a new site or mail sender mid-quarter?
How do external findings appear beside Secure Score in uplift reviews?
Which of our trading names and project domains are monitored today?
How ESPM fits the rest of your defence
Business Premium strengthens what happens inside your tenant. ESPM watches the public edge around it. You need both.
SAT and mail filters help when spoofing still gets through. Hardening authentication records makes spoofing harder up front.
Fewer internet-facing services means fewer easy paths for the incidents your detection stack must catch. Posture reduces load on response.
Stride IT requires ESPM for every managed client. Read the stack detail at /security-standard/security-stack/espm/ and the program frame at /one-plan/. If a provider treats outside-in checks as optional paperwork, ask what they are hoping you will not notice.
A simple operating rhythm
Register every new public site and mail sender with IT the week it goes live.
Review DMARC report signals when you change senders.
Retire temporary remote access the day the project ends.
Keep domain and DNS ownership clear so records do not drift in silence.
Track external risk closure the same way you track patch backlog: owners, dates, done means done.
Once a quarter, walk the public list with a non-technical owner and ask “do we still need this online?” That question alone closes a surprising number of risks.
A Perth-shaped example
A mid-size contractor finishes a project portal for a joint venture. The joint venture ends. The portal stays up because renewing the certificate was automatic and nobody cancelled the host.
Months later a scanner finds an outdated login page. Nobody in the business remembers it. That is not exotic hacking. That is ordinary drift. ESPM exists to catch ordinary drift.
Another common path: marketing adds a mail platform for newsletters. SPF is updated poorly. Legitimate mail starts failing. Someone “fixes” it by widening SPF until anything can send as you. Spoofing becomes easy again.
ESPM with owners stops both stories: retire the portal, and keep mail authentication intentional instead of “whatever makes the bounce stop”.
Add a third story: a temporary remote desktop left open for a vendor over a long weekend. The weekend ends. The rule stays. Bots find it. ESPM should make that leftover rule visible before the weekend becomes a month.
What “done enough” looks like
You will never have zero internet presence. You need a website. You need mail. Done enough means the public list is known, auth records are intentional, and leftover doors are closed on purpose.
It also means spoofing is harder than it was last quarter, and nobody is shocked by a forgotten host during an insurance form.
If you want that outside-in control as required stack, start at /security-standard/security-stack/espm/ and see how Continual Security Uplift keeps it on the calendar at /one-plan/.
Want the required-stack definition we run with clients? Read /security-standard/security-stack/espm/ and the Our One Plan.
