Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementSecurity NewswireSecurity Enterprise ServicesSecurity Leadership and ManagementLogical SecurityCybersecurity News

Attack surfaces are mushrooming. Are you prepared?

By Paul Giorgi
network-security-freepik1170.jpg

Image via Freepik

November 7, 2022



Today’s businesses are constantly investing in technology to ensure efficient and agile operations. This is a positive development, but the practice has also significantly expanded the “attack surface” of the enterprise — including various devices, networks, IT systems and teams, data, and more vulnerable to cybersecurity risks.


This isn’t only true for businesses either; the global attack surface is constantly growing. There are now 40 trillion gigabytes of data on the internet, and this figure grows daily. So perhaps it’s not surprising that an estimated 375 new threats are born every minute.


Organizations may feel that they have strong security defenses for their enterprise networks, but how can they be sure that Joe in Accounting is using the correct protocols while he works from home? Much has been said about the potential pitfalls of a distributed workforce, and the shift has definitely opened up huge holes in network security. Hackers can simply find a vulnerability in a worker’s home computer and use it to sneak onto the company network or cloud applications.


These implications have propelled attack surface management to the top of the list of needs for organizations to keep their business’ critical assets secure.


Understanding Attack Surface Management

An attack surface can be defined as anywhere that an organization is vulnerable to cyberattacks. This includes all possible attack vectors where an adversary can penetrate a system and steal assets. Attack surfaces can contain applications, servers, websites or devices — all the software and hardware that connects to an organization’s network. Attack vectors are the methods by which cyber adversaries attempt to breach the attack surface. 


Most organizations have dozens — or even hundreds — of attack vectors. The most common include things such as weak passwords, vulnerabilities, overly permissive identities and misconfigurations. 


Given the increasing size and complexity of attack surfaces, and the sheer number of vulnerabilities, it’s important to have a systematic approach for managing these risks. 


Attack surface management is one such framework. By creating a comprehensive strategy, organizations can understand the scope of their attack surface, identify the attack vectors, and discover the most effective way to protect their most critical assets. The key goal is to reduce the size of the attack surface to manage defenses and remediations efficiently. 


Attack surface reduction can be accomplished through tactics such as:

·        Analyzing the attack surface using advanced software tools to better understand the risk to critical assets

·        Creating network segmentation

·        Improving endpoint control and password management 

·        Adhering to least privilege principles for access/permissions

·        Eliminating outdated or redundant code

·        Minimizing the complexity of the IT environment by disabling unused devices and software

·        Investing in employee training, which can significantly reduce the odds of human error and help eliminate attack vectors


The Role of Attack Paths

Malicious actors seeking to access data and deploy ransomware and other cyberattacks are not looking at a simple, one-step process: they must first breach the network, then laterally move to the target assets, and finally exfiltrate the data. To do so, they exploit hidden connections between misconfigurations, vulnerabilities, credentials and user activities located throughout the network. These connections form an “attack path,” which hackers use to move throughout the network and to cloud assets until they reach the ‘crown jewels,’ where they can hold sensitive data hostage or conduct a series of malware attacks. 


Attack paths have frustrated security professionals for decades and are present in essentially all enterprise networks. The issue is that cyber pros often aren’t aware of the paths, or even the likely entities within a path, as they should be, making remediation more difficult. In many cases, attack paths take unexpected routes, sometimes leveraging cloud entities as a detour within an on-premise lateral movement strategy.


Any attack surface management strategy must include detecting and remediation attack paths. The first step in preventing malicious actors from pivoting and accessing critical assets is to map an attack graph that outlines all possible routes to those critical assets; this number can be in the hundreds or even thousands! 


Creating an attack graph enables the identification and prioritization of the “choke points” throughout the network. Essentially, these are the key intersections through which most attack paths must traverse in order to reach the critical assets. By locking them down, security teams can ensure that, even if an attacker enters the network, they won’t be able to access anything important. Many security tools do some form of attack surface management, but they’re missing a key element by not visualizing attack paths and identifying the choke points that make remediation so quick and easy. 


Given how rapidly attack surfaces expand in today’s business environment, a better management approach has become crucial. Fortunately, a comprehensive solution that incorporates attack path management is a proven method for safely reducing the attack surface and decreasing the risk of a devastating breach.

KEYWORDS: cyber security data protection network security password risk management

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Paul Giorgi is director of sales engineering for XM Cyber.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Top Cybersecurity Leaders
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Career Intelligence
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

Paparazzi

When Private Events Become Public Infrastructure: What Celebrity OSINT Teaches Security Leaders

Broken wet floor sign

Why Response Time Is Becoming the Missing Metric in Workplace Safety and Security

People watching fireworks

Security Guard Assaulted at Firework Show

Cargo ship sailing

You Can’t Secure a Ship Like a Laptop

Medical professional

Nearly 85% of Nurses Experienced Workplace Violence in the Last Year

Kaseware sponsored webinar
Schneider Electric sponsored webinar

Events

August 19, 2026

From Investigative Question to Defensible Answer: AI in Digital Forensics and Incident Response

LIVE: August 19, 2026 at 2 PM EDT We'll examine where AI can deliver meaningful value, where incomplete context or black-box reasoning can introduce risk, and what governance, validation, and evidence-traceability controls organizations should establish.

August 25, 2026

Critical Infrastructure Security Is National Security: Protecting Essential Operations in an Era of Escalating Risk

LIVE: August 25, 2026 at 2 PM EDT Learn why critical infrastructure security has become a national security imperative, and the strategies organizations can adopt to improve visibility, collaboration, and response across their security operations.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar

Related Articles

  • Are You Prepared for 2015's Cyber Threats?

    See More
  • CCPA

    CCPA enforcement deadline has arrived - are you prepared?

    See More
  • hurricane

    It's Hurricane Season: Are You Prepared?

    See More

Related Products

See More Products
  • CPTED.jpg

    CPTED and Traditional Security Countermeasures: 150 Things You Should Know

  • 150 things.jpg

    Physical Security: 150 Things You Should Know 2nd Edition

  • Risk Analysis and the Security Survey, 4th Edition

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing