forumNew topic

What exactly is an attack surface, and where should a small company start reducing it?

SSerkan U***Member
Job title
Site Manager
Sector
Education
Organization type
medium-sized business
Joined
May 2025
Message
312
#1

We are an architecture and project management firm of 12 people based in the Paris suburbs. Last week, per the specifications required by an enterprise construction client, we had an initial meeting with an independent cybersecurity auditor. While reviewing our infrastructure, the auditor repeatedly said, "Your attack surface is far too broad, you need to reduce it immediately." Since we don't have a technical team we couldn't fully grasp what they meant during the meeting.

In our office, we have a local file server an open remote desktop port so staff can access architectural drawings from home, cloud-based business email, and company software installed on everyone's personal phones. We spend about 4,000 EUR annually on basic IT support, but none of us had ever heard of this "attack surface" concept before.

What exactly does attack surface mean, what constitutes this surface in a small business like ours, and where is the most critical place to start reducing it as the experts suggest?

MMustafa M***Member
Job title
Quality control inspector
Sector
Food wholesale
Organization type
regional distributor
Joined
Feb 2024
Message
106
Most Helpful#2

Short answer: An attack surface is the sum total of all exposed vulnerabilities, software, ports, and human factors that an unauthorized attacker can exploit to infiltrate your systems, steal your data, or disrupt your operations. Reducing this surface means cutting external touchpoints down to the absolute bare minimum without breaking your everyday workflow.

In your current setup, the concrete points that make up your attack surface are: the remote desktop connection (RDP) exposed directly to the internet, your on-premise file server, corporate accounts logged in on personal phones, and unpatched software. Leaving an RDP port wide open to the internet is essentially leaving your office front door unlocked so attackers can run automated scanners to guess your passwords.

To start shrinking it, here is your priority order:

1) Shut down public-facing remote desktop access immediately; require remote staff to connect to the office strictly via a virtual private network (VPN) protected by two-factor authentication (2FA/MFA). 2) Enforce two-factor authentication on all email and cloud accounts. 3) Wipe accounts belonging to former employees, uninstall unused software, and delete unnecessary port forwarding rules on your router.

Taking these steps will instantly block the vast majority of automated brute-force attacks coming from the internet on day one.

KKoray S***MemberCommunity member
Joined
Jul 2025
Message
286
#3

Leaving Remote Desktop Protocol (RDP) open to the public internet is the number one cause of breaches for small businesses. Automated scanning bots are constantly indexing open ports across the web, hammering away for days to crack weak passwords. That open port is definitely the main reason the auditor flagged your attack surface.

ZZaferMember
Job title
Insurance agency
Joined
May 2024
Message
88
#4

The quickest thing you can do right now: call the IT firm you pay for annual support and ask them to run an external port scan on your office's public IP. Tell them to close any entry points exposed to the internet and put remote access behind a VPN.

OOnur M***Expert
Job title
Accounting clerk
Sector
Plastic
Organization type
medium-sized business
Joined
May 2023
Message
7
#5

We also use remote desktop directly so our remote staff can connect. like does setting up a VPN require an expensive software license, or is it just a built-in feature on our existing network router?

OOrhan T***Member
Job title
Purchasing manager
Sector
Printing
Organization type
medium-sized business
Joined
Mar 2023
Message
348

Doki · E-commerce infrastructure · 2023

#6

Most current enterprise-grade modems and routers come with a built-in VPN server feature. Your IT support provider can set this up with a couple of hours of configuration without requiring you to buy extra hardware. If it's covered under your contract, it shouldn't cost you anything extra.

AAhmet A***Member
Job title
Human Resources Specialist
Sector
Construction
Organization type
a company within a holding
Joined
Apr 2024
Message
320
#7

We had a similar scan done at our 15-person consulting firm. It turned up 6 unnecessary ports exposed to the outside, 3 old intern accounts, and an outdated NAS device. Cleaning all that up took our IT guy half a day and significantly reduced our attack risk.

KKeremMember
Job title
Agency sales
Joined
Jul 2024
Message
94
#8

You mentioned employees check company emails from their personal phones. Is there a screen lock requirement on these devices, or can you remotely wipe the company account if a phone gets stolen? Physical device security is also an integral part of the attack surface.

EElif P***New member
Job title
Quality control inspector
Sector
Energy
Organization type
a company within a holding
Joined
Jul 2026
Message
130
#9

In short, the attack surface is all the entry points of your office facing the internet. Closing the RDP port, setting up a VPN, enforcing two-factor authentication, and deleting unnecessary accounts will bring this surface down to a secure level in no time.

ÖÖzgür D***Member
Job title
Front office accounting
Sector
Automotive aftermarket
Organization type
20-person company
Joined
Oct 2022
Message
2
#10

Great work.

UUğur Y***Veteran
Job title
Clinic manager
Sector
Catering
Organization type
medium-sized business
Joined
Mar 2023
Message
253
#11

Same here.

NNazlı T***Expert
Job title
Sales Manager
Sector
Insurance
Organization type
40-person manufacturing company
Joined
Jan 2025
Message
133
#12

Generally correct, but one part is missing. The biggest time-waster for us was not knowing who had the final say.

Hope this helps.

OOsman T***Member
Job title
Technical service technician
Sector
Furniture manufacturing
Organization type
a company within a holding
Joined
Jan 2022
Message
3
#13

Sorry, but this doesn't apply in every case. Taking measures without an inventory leaves doors you haven't seen open.

If it's your first time, start small; scaling comes later. Correct me if I'm wrong.

BBarış V***Member
Job title
Front office accounting
Sector
Food wholesale
Organization type
a company within a holding
Joined
Jan 2023
Message
2
#14

You're right. honestly start with a small trial; don't commit to everything at once.

Of course, it varies if your situation is different.

GGökhan Ç***Member
Job title
Secretary
Sector
Catering
Organization type
medium-sized business
Joined
Jan 2023
Message
323
#15

the opposite happened to me, that's why I'm writing. don't rely on a single measure; go layer by layer.

if I were you I'd go this route.

KKader K***Member
Job title
Board member
Sector
Real estate
Organization type
120-person company
Joined
Nov 2023
Message
256
#16

The discussion got scattered, let me summarize. Solutions that work at a small scale collapse when you grow; I learned this late.

Proven by experience.

MMert K***MemberCommunity member
Joined
Jul 2025
Message
365
#17

Let me share my experience. Processes without records never improve, because you don't know what to fix.

When you try to change everything at once, nothing settles. Just leaving this note, it might be useful.

MMustafa U***Member
Job title
Social media manager
Sector
Real estate
Organization type
8-person team
Joined
Aug 2023
Message
65
#18

I went through the same thing two years ago. Taking notes for two weeks yields better results than a six-month estimate.

If you post the result here, it will help others too.

TTaner Y***MemberCommunity member
Joined
Dec 2023
Message
166
#19

There's also a measurement aspect to this. The real issue isn't the number, but what it's based on.

When you try to change everything at once nothing settles.

OOkan A***Member
Job title
Clinic manager
Sector
Retail
Organization type
sole proprietorship
Joined
Apr 2023
Message
55
#20

I went through the same thing.

This topic has been closed.The moderator marked the topic as resolved. If you have a similar issue, you can open a new topic.
New topic