Attack surface
The sum of every point of an organisation that attackers can reach: domains, subdomains, open ports, applications, APIs, cloud resources and information that has leaked outside.
- 01
Why it matters
You cannot protect an asset you do not know about. A forgotten test site, an old campaign page or a server opened by a supplier is an easier way in than the up-to-date main site. Shrinking the attack surface, that is, shutting down everything unused, is one of the cheapest security measures.
- 02
Example
A company's main site is updated and protected, but a subdomain opened two years ago for an event still runs an old content management system. The attacker gets in through it; once the subdomain is shut down, that route disappears.
- 03
Common mistake
Thinking of the attack surface as only the company's own servers. Cloud services, sites built by agencies, leaked employee passwords and third-party integrations are part of the surface too.
- 04
Related terms
Related services and guides
Let's talk about your project.
Tell us what you need; we will define the scope together.