Skip to main content

Attack Surface

concept

An attack surface is the total set of reachable points, interfaces, identities, assets, and trust relationships that an attacker could attempt to exploit.

Status: published
Last reviewed: 2026-09-12

Technical explanation

It includes internet-facing services, APIs, endpoints, software dependencies, cloud resources, accounts, permissions, physical interfaces, suppliers, data flows, and human processes. Attack-surface management combines inventory, exposure discovery, prioritisation, remediation, and continuous monitoring.

Business relevance

Reducing unnecessary exposure limits opportunities for compromise and helps security teams focus on the assets and paths with the greatest potential impact.

Implementation example

An organisation discovers an obsolete public API, unused administrator accounts, and a supplier integration with excessive permissions, then removes or restricts them.

Limitations and common misconceptions

No inventory remains complete without continuous maintenance. A smaller surface is not automatically secure, and counting assets alone does not reflect exploitability, controls, or business impact.

Discuss your systems

Need help implementing or evaluating this concept? Keenfunnel designs connected AI, automation, and data systems.

Book a discovery session