- Job title
- Site Manager
- Sector
- Education
- Organization type
- medium-sized business
- Joined
- May 2025
- Message
- 312
We are an architecture and project management firm of 12 people based in the Paris suburbs. Last week, per the specifications required by an enterprise construction client, we had an initial meeting with an independent cybersecurity auditor. While reviewing our infrastructure, the auditor repeatedly said, "Your attack surface is far too broad, you need to reduce it immediately." Since we don't have a technical team we couldn't fully grasp what they meant during the meeting.
In our office, we have a local file server an open remote desktop port so staff can access architectural drawings from home, cloud-based business email, and company software installed on everyone's personal phones. We spend about 4,000 EUR annually on basic IT support, but none of us had ever heard of this "attack surface" concept before.
What exactly does attack surface mean, what constitutes this surface in a small business like ours, and where is the most critical place to start reducing it as the experts suggest?