The total number of points where an attacker could potentially access or exploit a system.
Attack surface encompasses all potential entry points attackers could use to access or attack systems—exposed services, open ports, user accounts, application interfaces, physical access points, and supply chain connections. Reducing attack surface minimises opportunities for compromise. Attack surface management involves identifying all assets and exposures, eliminating unnecessary ones, and protecting what remains. The shift to cloud and remote work has dramatically expanded most organisations' attack surfaces.
Why It Matters
The DSC Perspective:
You can't protect what you don't know about. Attack surface assessment reveals unknown exposures—shadow IT, forgotten systems, unnecessary services. Regular attack surface assessment, especially external, identifies risks you may not realise you have.
