Lesson 1 of 4
What counts as attack surface
External, internal, identity and human — four surfaces, four different inventories.
13 min 3-question quiz 3 guides to read next
Attack surface is every point where somebody could interact with your organisation in a way you did not intend. It is wider than a list of servers.
External
Everything reachable from the internet: web applications and APIs, remote access, mail, DNS, cloud storage and endpoints, exposed management interfaces, and anything an acquisition brought with it. The part people think of first, and the only part most organisations enumerate at all.
Internal
What becomes reachable once somebody is inside: file shares, databases, management consoles, printers, building systems, hypervisors, backup infrastructure, test environments holding production data. The size of this surface decides whether a single compromised laptop is an incident or a disaster.
Identity
Every account, key, token, certificate and consent that can authenticate — human and machine, in your directory and in every SaaS platform. For most organisations this is now the largest and least inventoried surface, and the one attackers prefer because it requires no exploit.
Human and supply chain
People who can be phoned, emailed or deceived; and suppliers, integrations and code with access into your environment. Neither appears on a network diagram, and both are routinely the entry point.
Why the framing matters
A programme that counts only external hosts will report a small, shrinking attack surface while its identity and supplier surfaces grow unmeasured. Enumerate all four, even roughly — a crude count of OAuth grants and privileged accounts tells you more than a precise count of web servers.
Check your understanding
3 questions · pass with 2 correct
Enrol for free to save your progress, unlock every lesson and earn a certificate.
Sign in to enrolFurther reading
Guides that go deeper on this lesson.
-
Attack Surface Discovery: DNS, Certificates and Cloud
Finding the internet-facing things you own, including the ones nobody remembers creating.
2 min read
-
Identity as the Attack Surface
When the perimeter is a token, the attack surface is every account, key and consent in the directory.
2 min read
-
Shadow IT and Unmanaged Assets
The systems nobody told you about, why they appear, and how to find them without becoming the enemy.
2 min read