HomeAttack Surface

Attack Surface

An attack surface is the total set of points where an attacker could try to interact with a system and cause harm. It includes internet-facing assets such as websites, APIs, DNS, email services and exposed ports. It also covers internal services, cloud accounts, SaaS tenants, identities and roles, VPNs, endpoints, mobile devices and IoT. Third-party links, CI/CD pipelines, code repositories and data stores are part of it as well. Physical entry points like badge readers and console ports count, and so do human touchpoints such as help desks and social media profiles. People often group the surface into external, internal and partner areas, and into digital, physical and human layers. Some parts are known and inventoried. Others are unknown or shadow IT. The attack surface changes over time as new features ship, staff and suppliers change, misconfigurations appear, and vulnerabilities are disclosed. Typical ways to describe it include the number and type of exposed services, the sensitivity of data behind them, the privileges tied to identities, and the dependency on third parties. In short, the attack surface is the practical map of where risk can enter.