Attack Surface Management

Attack Surface Management is the continuous recording, assessment and reduction of an organization's attackable digital surface. This includes known and unknown assets, internet-exposed systems, cloud resources, external services and other potential entry points. The term is so relevant because modern IT landscapes grow dynamically and frequently change faster than classic inventory can keep up. Attack surface management creates transparency about risks that are otherwise easily overlooked.

These include forgotten subdomains, open services, shadow IT or exposed test environments. In combination with vulnerability and threat information, it is possible to prioritize which exposure should be reduced first. For organizations, this is particularly important because undetected attack surface is often the starting point of successful attacks. The term thus stands for a proactive view of one's own visibility from the perspective of potential attackers. Automated Security Validation can help to continuously test protective measures against realistic attack scenarios.

See also: Vulnerability Management, Cloud Security and Security Posture.