Updated: October 2026
Your company has more ways in than any list shows. A forgotten test server, an old VPN login, a help desk that resets passwords over the phone. Here's what an attack surface is, how it quietly grows, and how to map it and shrink it before someone else maps it for you.
What Is an Attack Surface?
An attack surface is every place an attacker can try to get in. NIST puts it in one line: "the set of points on the boundary of a system, a system component, or an environment where an attacker can try to enter, cause an effect on, or extract data from" it. That definition comes from NIST SP 800-53 Rev. 5.
In plain terms, it's every door and window. A login page is a door. An open port is a window. A laptop left in a car is a window with no glass. So is an employee who trusts a caller claiming to be IT.
The size of the surface matters more than any single door. Each extra entry point is one more thing to patch, watch and remember. People searching for the "digital attack surface" or the "cyber attack surface" mean the same idea, limited to systems and networks.
The Three Kinds of Attack Surface
Security teams split the surface into three parts, because each one needs a different fix.
The digital surface is the biggest. Its external half is everything the internet can reach: websites, VPN gateways, remote desktop, email, SaaS logins, APIs and DNS records. Its internal half is what an attacker can reach once they're inside: flat networks, admin shares, old protocols like SMB1 and Telnet, and accounts nobody disabled.
The physical surface is the hardware you can touch. Laptops, USB ports, printers, the server closet that doesn't lock, the conference room network jack.
The human surface is people. Anyone who can be phished, rushed or talked into resetting a password. Help desks are a favourite target here, because their whole job is to say yes.
Attack Surface vs Attack Vector
The two terms get mixed up constantly. The attack surface is where an attacker could get in. The attack vector is how they do it.
Take one exposed VPN gateway. The gateway is part of your surface. A stolen password typed into it is one vector. An unpatched flaw in its firmware is another. A phishing email that harvests the login is a third.
The practical rule: you shrink the surface, and you block the vectors. Removing the gateway kills every vector through it at once. Patching it blocks one.
How an Attack Surface Grows
Nobody decides to grow their attack surface. It grows on its own, one reasonable decision at a time.
A marketing team signs up for a SaaS tool with a personal card. That's shadow IT, and it comes with its own logins and data. A developer spins up a test site on a subdomain and moves on.
Someone opens a port on the router so a vendor can reach one machine, and port forwarding turns into a permanent hole.
Forgotten DNS records are a quieter version. A subdomain can keep pointing at a cloud service you stopped paying for, and whoever claims that service next controls a page on your domain.
Management interfaces are the loudest version. In June 2023, CISA issued Binding Operational Directive 23-02, which gives federal agencies 14 days to pull management interfaces off the internet once one is found, or to put them behind separate access control. The list covers routers, switches, firewalls, VPN concentrators and out-of-band server management, over protocols from RDP and SSH to SNMP and Telnet. Private companies aren't bound by it, but the list doubles as a good checklist.
The cost of this drift shows up in breach data. Verizon's 2026 Data Breach Investigations Report says 31% of breaches now start with software vulnerabilities, ahead of stolen passwords. Every exposed service you forgot about is a vulnerability you can't patch.
This r/cybersecurity_help thread from September 2026 describes the problem well. Every time the team thinks the external inventory is under control, "something else turns up": old dev environments, random subdomains, things another team spun up and forgot.
How to Map Your Attack Surface
You can't shrink what you haven't listed. Mapping works best from two directions: what you think you own, and what the internet can see.
- Start with the inside list. Devices, user and service accounts, SaaS apps, domains, public IP ranges and cloud subscriptions. Pull it from your directory, your device management tool, finance records and DNS registrar, not from memory.
- Look from the outside. Scan your own public IP ranges for open ports, and only ranges you own or have written permission to test. Search engines like Shodan and Censys index exposed services, so check what they already show for your IPs.
- Read the certificate logs. Certificate Transparency logs publicly record which certificates were issued "for which domains". Searching them for your domain lists hostnames people forgot they created.
- Walk the DNS. Export every record from your DNS host and check each one still points at something you run.
- Compare the two lists. Whatever the outside view finds that the inside list missed is your shadow surface. Give each item an owner or a shutdown date.
A network penetration test is the deeper version of step 2, with a tester trying the doors instead of only counting them. OpenFrame keeps a live device inventory and can run a script across a client's devices to list listening ports, with the output collected in one place.
Attack Surface Management vs Vulnerability Management
Attack surface management (ASM) answers "what do we have, and what can the internet reach?" It's discovery that never stops, because the surface keeps changing. Vulnerability management answers "what's wrong with the things we already know about, and what do we fix first?"
| Attack surface management | Vulnerability management | |
|---|---|---|
| Starts from | The outside, with no list | Your asset list |
| Finds | Unknown and forgotten assets, exposed services | Missing patches, misconfigurations, known CVEs |
| Main output | An inventory of what's exposed | A prioritised fix list |
| Blind spot | Doesn't prove a flaw is exploitable | Can't scan what isn't on the list |
They depend on each other. ASM feeds new assets into the list, and vulnerability management tools then scan and prioritise them. Our comparison of vulnerability management software covers the second half.
IBM Technology's short explainer walks through how ASM discovery works from the attacker's point of view.
How to Shrink Your Attack Surface
Shrinking comes in four moves, in this order. The earlier the move, the more it removes.
Remove what you don't need. Decommission old servers and test sites, delete DNS records that point nowhere, disable accounts of people who left, and cancel SaaS nobody uses. A service that doesn't exist can't be attacked.
Restrict what has to stay. Take admin and management interfaces off the internet, the way BOD 23-02 requires of federal agencies. Put remote access behind a VPN or zero trust gateway, close forwarded ports, and require MFA on every internet-facing login.
Harden what's left. Patch on a schedule, turn off legacy protocols like SMB1 and Telnet, and give accounts only the access their job needs.
Watch for regrowth. Re-run the outside scan and the certificate search on a schedule, and alert when a new hostname or open port appears. The surface grows back the moment you stop looking.
A reply in this r/SecurityBlueTeam thread puts the priority bluntly: "The only way to manage attack surface is to reduce it." Tools that only find assets and open tickets leave the reducing to you.
The Short Version
Your attack surface is every way in: digital, physical and human. It grows through ordinary decisions like a new SaaS tool, a forwarded port or a test subdomain nobody deleted. Map it from both sides, inside list and outside view, then shrink it by removing first, restricting second and hardening third. Then look again, because it grows back.
Your own remote access tools belong on the map too. Our guide to RMM security covers hardening the stack you use to manage everything else.
Content Marketing Lead
Ohayo! I run content, SEO, social, and community at Flamingo. Before IT, I worked as a correspondent for Ukraine's Public Broadcasting Company and have a Master's in journalism.
