Flamingo Raises $4.5M Seed Round

Skip to content

Updated: October 2026

Your company has more ways in than any list shows. A forgotten test server, an old VPN login, a help desk that resets passwords over the phone. Here's what an attack surface is, how it quietly grows, and how to map it and shrink it before someone else maps it for you.

What Is an Attack Surface?

An attack surface is every place an attacker can try to get in. NIST puts it in one line: "the set of points on the boundary of a system, a system component, or an environment where an attacker can try to enter, cause an effect on, or extract data from" it. That definition comes from NIST SP 800-53 Rev. 5.

In plain terms, it's every door and window. A login page is a door. An open port is a window. A laptop left in a car is a window with no glass. So is an employee who trusts a caller claiming to be IT.

The size of the surface matters more than any single door. Each extra entry point is one more thing to patch, watch and remember. People searching for the "digital attack surface" or the "cyber attack surface" mean the same idea, limited to systems and networks.

The Three Kinds of Attack Surface

Security teams split the surface into three parts, because each one needs a different fix.

The digital surface is the biggest. Its external half is everything the internet can reach: websites, VPN gateways, remote desktop, email, SaaS logins, APIs and DNS records. Its internal half is what an attacker can reach once they're inside: flat networks, admin shares, old protocols like SMB1 and Telnet, and accounts nobody disabled.

The physical surface is the hardware you can touch. Laptops, USB ports, printers, the server closet that doesn't lock, the conference room network jack.

The human surface is people. Anyone who can be phished, rushed or talked into resetting a password. Help desks are a favourite target here, because their whole job is to say yes.

Attack Surface vs Attack Vector

The two terms get mixed up constantly. The attack surface is where an attacker could get in. The attack vector is how they do it.

Take one exposed VPN gateway. The gateway is part of your surface. A stolen password typed into it is one vector. An unpatched flaw in its firmware is another. A phishing email that harvests the login is a third.

The practical rule: you shrink the surface, and you block the vectors. Removing the gateway kills every vector through it at once. Patching it blocks one.

How an Attack Surface Grows

Nobody decides to grow their attack surface. It grows on its own, one reasonable decision at a time.

A marketing team signs up for a SaaS tool with a personal card. That's shadow IT, and it comes with its own logins and data. A developer spins up a test site on a subdomain and moves on.

Someone opens a port on the router so a vendor can reach one machine, and port forwarding turns into a permanent hole.

Forgotten DNS records are a quieter version. A subdomain can keep pointing at a cloud service you stopped paying for, and whoever claims that service next controls a page on your domain.

Management interfaces are the loudest version. In June 2023, CISA issued Binding Operational Directive 23-02, which gives federal agencies 14 days to pull management interfaces off the internet once one is found, or to put them behind separate access control. The list covers routers, switches, firewalls, VPN concentrators and out-of-band server management, over protocols from RDP and SSH to SNMP and Telnet. Private companies aren't bound by it, but the list doubles as a good checklist.

The cost of this drift shows up in breach data. Verizon's 2026 Data Breach Investigations Report says 31% of breaches now start with software vulnerabilities, ahead of stolen passwords. Every exposed service you forgot about is a vulnerability you can't patch.

This r/cybersecurity_help thread from September 2026 describes the problem well. Every time the team thinks the external inventory is under control, "something else turns up": old dev environments, random subdomains, things another team spun up and forgot.

How to Map Your Attack Surface

You can't shrink what you haven't listed. Mapping works best from two directions: what you think you own, and what the internet can see.

  1. Start with the inside list. Devices, user and service accounts, SaaS apps, domains, public IP ranges and cloud subscriptions. Pull it from your directory, your device management tool, finance records and DNS registrar, not from memory.
  2. Look from the outside. Scan your own public IP ranges for open ports, and only ranges you own or have written permission to test. Search engines like Shodan and Censys index exposed services, so check what they already show for your IPs.
  3. Read the certificate logs. Certificate Transparency logs publicly record which certificates were issued "for which domains". Searching them for your domain lists hostnames people forgot they created.
  4. Walk the DNS. Export every record from your DNS host and check each one still points at something you run.
  5. Compare the two lists. Whatever the outside view finds that the inside list missed is your shadow surface. Give each item an owner or a shutdown date.

A network penetration test is the deeper version of step 2, with a tester trying the doors instead of only counting them. OpenFrame keeps a live device inventory and can run a script across a client's devices to list listening ports, with the output collected in one place.

Attack Surface Management vs Vulnerability Management

Attack surface management (ASM) answers "what do we have, and what can the internet reach?" It's discovery that never stops, because the surface keeps changing. Vulnerability management answers "what's wrong with the things we already know about, and what do we fix first?"

Attack surface managementVulnerability management
Starts fromThe outside, with no listYour asset list
FindsUnknown and forgotten assets, exposed servicesMissing patches, misconfigurations, known CVEs
Main outputAn inventory of what's exposedA prioritised fix list
Blind spotDoesn't prove a flaw is exploitableCan't scan what isn't on the list

They depend on each other. ASM feeds new assets into the list, and vulnerability management tools then scan and prioritise them. Our comparison of vulnerability management software covers the second half.

IBM Technology's short explainer walks through how ASM discovery works from the attacker's point of view.

How to Shrink Your Attack Surface

Shrinking comes in four moves, in this order. The earlier the move, the more it removes.

Remove what you don't need. Decommission old servers and test sites, delete DNS records that point nowhere, disable accounts of people who left, and cancel SaaS nobody uses. A service that doesn't exist can't be attacked.

Restrict what has to stay. Take admin and management interfaces off the internet, the way BOD 23-02 requires of federal agencies. Put remote access behind a VPN or zero trust gateway, close forwarded ports, and require MFA on every internet-facing login.

Harden what's left. Patch on a schedule, turn off legacy protocols like SMB1 and Telnet, and give accounts only the access their job needs.

Watch for regrowth. Re-run the outside scan and the certificate search on a schedule, and alert when a new hostname or open port appears. The surface grows back the moment you stop looking.

A reply in this r/SecurityBlueTeam thread puts the priority bluntly: "The only way to manage attack surface is to reduce it." Tools that only find assets and open tickets leave the reducing to you.

The Short Version

Your attack surface is every way in: digital, physical and human. It grows through ordinary decisions like a new SaaS tool, a forwarded port or a test subdomain nobody deleted. Map it from both sides, inside list and outside view, then shrink it by removing first, restricting second and hardening third. Then look again, because it grows back.

Your own remote access tools belong on the map too. Our guide to RMM security covers hardening the stack you use to manage everything else.

Kristina Shkriabina

Content Marketing Lead

Ohayo! I run content, SEO, social, and community at Flamingo. Before IT, I worked as a correspondent for Ukraine's Public Broadcasting Company and have a Master's in journalism.

Related Content

Blog Posts

Product Releases

Podcasts

Webinars

Case Studies

Events

Onboarding Guides

Frequently Asked Questions

Attack Surface

It is every place an attacker can try to get in: internet-facing systems like websites, VPN gateways and SaaS logins, internal systems reachable once someone is inside, physical devices like laptops and USB ports, and people who can be phished or talked into resetting a password. NIST defines it as the set of points on the boundary of a system where an attacker can try to enter, cause an effect or extract data.
The attack surface is where an attacker could get in, such as an exposed VPN gateway. An attack vector is how they do it, such as a stolen password, an unpatched flaw or a phishing email. Patching or MFA blocks individual vectors. Removing the entry point shrinks the surface and blocks every vector through it at once.
Attack surface management (ASM) is continuous discovery of what you own and what the internet can reach, including forgotten subdomains, old test sites and exposed services. It differs from vulnerability management, which scans assets you already know about for missing patches and misconfigurations. ASM feeds new assets into the list that vulnerability management then scans.
Map it first, from an inside inventory and an outside scan of your own IP ranges, certificate logs and DNS records. Then remove what you do not need, restrict what has to stay (management interfaces off the internet, MFA on every login, forwarded ports closed), harden what is left with patching and least privilege, and re-scan on a schedule to catch regrowth.

MSP AI Agents

On a five-person desk, reported deployments show $78,000 to $130,000 in annual direct labor savings, roughly 30% fewer escalations, and 15% to 20% better SLA compliance. Broader MSP adoption data adds ticket handling time cut by 45% and five to 12 points of margin, all from reclaimed capacity rather than headcount cuts.
Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.

About OpenFrame

OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
Most platforms give you one piece and expect you to bolt the rest on. OpenFrame unifies the whole stack in one place, with AI copilots built in. Fewer logins, fewer bills, less duct tape.
In the cloud, on US soil. Your data stays stateside.
Both. It's built for MSPs and MSSPs alike.