{"id":5848,"date":"2021-09-28T11:00:00","date_gmt":"2021-09-28T08:00:00","guid":{"rendered":"https:\/\/blog.eset.ee\/?p=5848"},"modified":"2026-06-14T10:27:15","modified_gmt":"2026-06-14T07:27:15","slug":"what-is-a-cyberattack-surface-and-how-can-you-reduce-it","status":"publish","type":"post","link":"https:\/\/blog.eset.ee\/et\/en\/2021\/09\/28\/what-is-a-cyberattack-surface-and-how-can-you-reduce-it\/","title":{"rendered":"What is a cyberattack surface and how can you reduce it?"},"content":{"rendered":"<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>In almost all coverage of modern breaches you\u2019ll hear mention of the \u201ccyberattack surface\u201d or something similar. It\u2019s central to understanding how attacks work and where organizations are most exposed. During the pandemic the attack surface has grown arguably further and faster than at any point in the past. And this has created its own problems. Unfortunately, organizations are increasingly unable to define the true size and complexion of their attack surface today\u2014leaving their digital and physical assets exposed to threat actors.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>Fortunately, by executing a few best practices, these same defenders can also improve their visibility of the attack surface, and with it, gain enhanced understanding of what\u2019s necessary to minimize and manage it.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:heading \u2013><\/p>\n<h2><strong>What is the corporate attack surface?<\/strong><\/h2>\n<p><!\u2013 \/wp:heading \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>At a basic level, the attack surface can be defined as the physical and digital assets an organization holds that could be compromised to facilitate a cyber-attack. The end goal of the threat actors behind it could be anything from deploying ransomware and stealing data to conscripting machines into a botnet, downloading banking trojans or installing crypto-mining malware. The bottom line is: the bigger the attack surface, the larger the target the bad guys have to aim at.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>Let\u2019s take a look at the two main attack surface categories in more detail:<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:heading {\"level\":3} \u2013><\/p>\n<h3><strong>The digital attack surface<\/strong><\/h3>\n<p><!\u2013 \/wp:heading \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>This describes all of an organization\u2019s network-connected hardware, software and related components. These include:<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p><strong>Applications:&nbsp;<\/strong>Vulnerabilities in apps are commonplace, and can offer attackers a useful entry point into critical IT systems and data.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p><strong>Code<\/strong>: A major risk now that much of it is being compiled from third-party components, which may contain malware or vulnerabilities.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p><strong>Ports:<\/strong>&nbsp;Attackers are increasingly scanning for open ports and whether any services are listening on a specific port (e.g., TCP port 3389 for RDP). If those services are misconfigured or contain bugs, these can be exploited.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p><strong>Servers:&nbsp;<\/strong>These could be attacked via vulnerability exploits or flooded with traffic in DDoS attacks.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p><strong>Websites:&nbsp;<\/strong>Another part of the digital attack surface with multiple vectors for attack, including code flaws and misconfiguration. Successful compromise can lead to web defacement, or implanting malicious code for drive-by and other attacks (e.g.,&nbsp;<a href=\"https:\/\/twitter.com\/esetresearch\/status\/1272408821072384000\">formjacking<\/a>).<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p><strong>Certificates:<\/strong>&nbsp;Organizations frequently&nbsp;<a href=\"https:\/\/help.eset.com\/era_admin\/65\/en-US\/certificate_replacement.html\">let these expire<\/a>, allowing attackers to take advantage.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>This is far from an exhaustive list. To highlight the sheer scale of the digital attack surface, consider this 2020 research into firms on the FTSE 30 list.&nbsp;<a href=\"https:\/\/www.csoonline.com\/article\/3562329\/enterprise-internet-attack-surface-is-growing-report-shows.html\">It found<\/a>:<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:list \u2013><\/p>\n<ul>\n<li>324 expired certificates<\/li>\n<li>25 certificates using the obsolete SHA-1 hashing algorithm<\/li>\n<li>743 possible test sites exposed to the internet<\/li>\n<li>385 insecure forms of which 28 were used for authentication<\/li>\n<li>46&nbsp;web frameworks featuring known vulnerabilities<\/li>\n<li>80 instances of now defunct PHP 5.x<\/li>\n<li>664 web server versions with known vulnerabilities<\/li>\n<\/ul>\n<p><!\u2013 \/wp:list \u2013><\/p>\n<p><!\u2013 wp:heading {\"level\":3} \u2013><\/p>\n<h3><strong>The physical attack surface<\/strong><\/h3>\n<p><!\u2013 \/wp:heading \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>This&nbsp;comprises all endpoint devices that an attacker could \u201cphysically\u201d access, such as:<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:list \u2013><\/p>\n<ul>\n<li>Desktop computers<\/li>\n<li>Hard drives<\/li>\n<li>Laptops<\/li>\n<li>Mobile phones\/devices<\/li>\n<li>Thumb drives<\/li>\n<\/ul>\n<p><!\u2013 \/wp:list \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>There\u2019s also a case for saying that your employees are a major party of the organization\u2019s physical attack surface, as they can be manipulated&nbsp;<a href=\"https:\/\/www.eset.com\/int\/social-engineering-business\/\" target=\"_blank\" rel=\"noreferrer noopener\">via social engineering<\/a>&nbsp;(phishing and its variants) in the course of a cyberattack. They\u2019re also responsible for shadow IT, the unauthorized use of applications and devices by employees to circumvent corporate security controls. By using these unapproved\u2014and often inadequately secured\u2014tools for work, they could be exposing the organization to additional threats.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:heading \u2013><\/p>\n<h2><strong>Is the attack surface getting bigger?<\/strong><\/h2>\n<p><!\u2013 \/wp:heading \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>Organizations have been building out their IT and digital resources for many years. But the advent of the pandemic saw investment&nbsp;<a href=\"https:\/\/www.welivesecurity.com\/2020\/05\/07\/digital-transformation-could-be-accelerated-covid-19\/\">on a massive scale<\/a>, to support remote working and maintain business operations at a time of extreme market uncertainty. It expanded the attack surface in several obvious ways:<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:list \u2013><\/p>\n<ul>\n<li>Remote working endpoints (e.g., laptops, desktops)<\/li>\n<li>Cloud apps and infrastructure<\/li>\n<li>IoT devices and 5G<\/li>\n<li>Use of third-party code and DevOps<\/li>\n<li>Remote working infrastructure (VPNs, RDP etc)<\/li>\n<\/ul>\n<p><!\u2013 \/wp:list \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>There\u2019s no going back.&nbsp;<a href=\"https:\/\/www.mckinsey.com\/business-functions\/strategy-and-corporate-finance\/our-insights\/how-covid-19-has-pushed-companies-over-the-technology-tipping-point-and-transformed-business-forever\">According to experts<\/a>, many businesses have now been pushed over a digital tipping point that will change their operations forever. That\u2019s potentially bad news for the attack surfaces, as it could invite:<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:list \u2013><\/p>\n<ul>\n<li>Phishing attacks exploiting a lack of security awareness in employees<\/li>\n<li>Malware and vulnerability exploits targeted at servers, apps and other systems<\/li>\n<li>Stolen or brute forced passwords used for unauthorized log-ins<\/li>\n<li>Exploitation of misconfigurations (e.g., in cloud accounts)<\/li>\n<li>Stolen web certificates<\/li>\n<\/ul>\n<p><!\u2013 \/wp:list \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>\u2026and much more. In fact, there are hundreds of attack vectors in play for threat actors, some of which are hugely popular.&nbsp;<a href=\"https:\/\/www.eset.com\/uk\/about\/newsroom\/press-releases\/latest-ransomware-paper-reports-71-billion-attacks-on-remote-access\/\" target=\"_blank\" rel=\"noreferrer noopener\">ESET found<\/a>&nbsp;71 billion compromise attempts via misconfigured RDP between January 2020 and June 2021.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:heading \u2013><\/p>\n<h2><strong>How to mitigate attack surface risks<\/strong><\/h2>\n<p><!\u2013 \/wp:heading \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>The attack surface matters fundamentally to best practice cybersecurity because understanding its size and taking steps to reduce or manage it is the first step towards proactive protection. Here are some tips:<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:list \u2013><\/p>\n<ul>\n<li>First, understand the size of the attack surface with asset and inventory audits, pen testing, vulnerability scanning and more.<\/li>\n<li>Reduce the size of the attack surface and associated cyber-risk where you can via:\n<ul>\n<li>Risk-based patching and configuration management<\/li>\n<li>Consolidating endpoints, ditching legacy hardware<\/li>\n<li>Upgrading software and operating systems<\/li>\n<li>Segmenting networks<\/li>\n<li>Following DevSecOps best practices<\/li>\n<li>Ongoing vulnerability management<\/li>\n<li>Supply chain risk mitigation<\/li>\n<li>Data security measures (i.e., strong encryption)<\/li>\n<li>Strong identity and access management<\/li>\n<li>Zero trust approaches<\/li>\n<li>Continuous logging and monitoring of systems<\/li>\n<li>User awareness training programs<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><!\u2013 \/wp:list \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>The corporate IT environment is in a constant state of flux\u2014thanks to the widespread use of VM, containers and micro services, and the continuous arrival and departure of employees and new hardware and software. That means any attempts to manage and understand the attack surface must be undertaken with agile, intelligent tools that work from real-time data. As always, \u201cvisibility and control\u201d should be your watchwords on this journey.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In almost all coverage of modern breaches you\u2019ll hear mention of the \u201ccyberattack surface\u201d or something similar. It\u2019s central to understanding how attacks work and where organizations are most exposed. During the pandemic the attack surface has grown arguably further and faster than at any point in the past. And this has created its own [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":5849,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[2880],"tags":[],"class_list":["post-5848","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-digital-security"],"acf":[],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/5848","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/comments?post=5848"}],"version-history":[{"count":0,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/5848\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/media\/5849"}],"wp:attachment":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/media?parent=5848"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/categories?post=5848"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/tags?post=5848"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}