FAQ
External Attack Surface Management

How often should shadow IT discovery run?

Discovery should run frequently enough to reflect the rate of change in the environment. Internet-facing assets and cloud services can appear quickly, so continuous or near-continuous monitoring is preferable for high-risk environments. Scan cadence, data refresh and alert latency should be evaluated separately because vendors define "continuous" in different ways.