Attack Surface Management Explained

By Joseph HarissonPublished March 8, 2023Updated October 1, 20264135 views

Every new SaaS subscription, every forgotten staging server, every cloud storage bucket someone spun up for a two-week project: all of it is attack surface, whether your security team knows it exists or not. That's the uncomfortable starting point for this topic. Most organizations are defending an environment smaller than the one they actually have.

Research on this gap is more precise than it used to be. Analysis of enterprise deployments by exposure management firm IONIX found that organizations running standard discovery programs are typically aware of only about 62% of their real external attack surface, leaving the other 38% invisible to the team responsible for defending it. And that invisible share isn't evenly distributed across low-risk systems. It concentrates exactly where attackers look first.

What counts as attack surface in 2026

The attack surface is every point where an unauthorized party could get in, exfiltrate data, or cause damage: devices, digital access points, and people. It's grown considerably as work has spread across cloud platforms, SaaS tools, and remote connections, and it keeps growing even when headcount and budgets don't.

A few categories dominate current exposure data:

  • Public-facing applications and vulnerabilities. Wiz's 2026 Cloud Attack Retrospective found that 26% of documented cloud breaches began with exploitation of a public-facing application, and a separate analysis found 40% of documented cloud intrusions started with a weaponized vulnerability, exploitation, not credential theft, as the most common path in.
  • Shadow IT. Gartner estimated in 2024 that 30 to 40% of large enterprise IT expenditure goes toward tools and services the security team never formally approved. Every one of those is a live, internet-facing asset that nobody is patching.
  • Third-party and vendor exposure. The 2026 Verizon Data Breach Investigations Report, covering more than 22,000 confirmed breaches across 145 countries, found third-party involvement grew 60% year over year to reach 48% of all breaches, a 19th edition that Verizon itself describes as reflecting the scale of a growing problem, not a reason to celebrate better detection.
  • People. Credential abuse still appears somewhere in the attack chain of 39% of all breaches tracked by Verizon this year, even though vulnerability exploitation edged past it as the single most common initial access method.

What attack surface management actually is

Attack surface management (ASM) is the discipline of continuously discovering, scoring, and reducing all of the above, rather than treating it as a one-time inventory exercise. The distinction matters: a scanner that starts from known IP ranges and domains will find more of what you already know about. It won't find the acquired subsidiary running its own infrastructure, or the marketing team's SaaS deployment with a corporate subdomain pointed at it. Real ASM starts from the organizational entity and works outward, which is the only way to catch what a standard inventory misses.

1. Discovery

This stage builds the actual inventory: hardware, software, cloud assets, subsidiaries, and forgotten test environments. A 2024 study cited by exposure management researchers found organizations typically have 20 to 30% more internet-facing assets than they believe, with roughly 15% of those presenting critical risk. Discovery is also where shadow IT gets caught. The gap between what security teams believe they run and what they actually run compounds quickly once you account for individual SaaS sign-ups, each one invisible until someone goes looking.

2. Scoring

Once assets are mapped, each one gets ranked by likelihood of compromise and potential impact if compromised. This is where teams decide what to fix first when they can't fix everything at once, which is always the real constraint. Use likelihood (how exposed, how exploitable) multiplied by impact (financial, operational, regulatory) to produce a priority order, not a flat list sorted by discovery date.

3. Remediation

Fixing what scored highest first, accepting that resources (time, budget, staff) are always more limited than the list of things that need fixing. This is the stage most organizations underinvest in relative to discovery. Finding 38% more assets than you knew about is only useful if someone actually closes the gaps on the ones that matter.

4. Continuous monitoring

The attack surface isn't static. Every new hire, new vendor, and new cloud deployment changes it, and a point-in-time assessment goes stale within weeks. Continuous monitoring is what catches new exposure before an attacker does, rather than during the next scheduled audit.

Rob Gurzeev, CEO and co-founder of CyCognito, framed the shift this way in the company's 2026 forecast, based on analysis of Global 2000 internet-facing assets: "Enterprises that align attack-surface management directly with business outcomes will be the ones resilient enough to withstand tomorrow's threats." That's a reasonable summary of where the discipline is heading: from a technical inventory exercise toward something boards actually ask about.

Why this matters financially

The business case for ASM comes down to three numbers that translate cleanly into a board conversation. First, the average cost of a data breach dropped to $4.44 million globally in 2025, a 9% decline and the first drop in five years, according to IBM's 2025 Cost of a Data Breach Report. That's an encouraging trend, but it's still a number most small and midsize businesses can't absorb without serious damage.

Second, breaches originating from unknown or unmanaged assets carry a real detection-time penalty. If an asset isn't in any monitored inventory, the clock on detecting a compromise doesn't start until the damage surfaces somewhere else, typically well after an attacker has already moved laterally and staged data for exfiltration.

Third, regulatory frameworks increasingly require documented visibility as a baseline, not an aspiration. NIS2 requires entities to document and manage supply chain security as part of formal risk management, and DORA requires financial entities to maintain a complete Register of Information covering every ICT third-party relationship. An organization that can't see 38% of its own attack surface cannot satisfy either requirement, regardless of how good its internal controls are for the part it can see.

Attack surface management tools worth evaluating

The market has matured considerably. A few platforms worth knowing by name and approach:

Wiz ASM

Wiz correlates externally discovered assets with internal cloud context, permissions, and vulnerabilities, so teams can see not just what's exposed but whether that exposure creates an actual path to sensitive data. This kind of correlation is increasingly table stakes rather than a differentiator, given how much external exposure data alone fails to prioritize correctly.

CyCognito

CyCognito focuses on discovering and scoring assets the way an attacker would see them, prioritizing by exploitability rather than raw asset count. Its approach mirrors a broader industry shift: security teams are no longer measured by how many assets they find but by how effectively they reduce validated, real exposure.

Detectify

Detectify combines automated discovery with a crowdsourced ethical hacking community that continuously surfaces new vulnerability patterns in widely used technologies, useful for catching emerging exposure classes before they show up in standard scanner signatures.

JupiterOne

JupiterOne's cyber asset attack surface management (CAASM) approach maps both internal and external assets, which matters for organizations whose risk isn't purely external-facing, since internal lateral movement after an initial compromise is where a lot of the real damage happens.

Where teams still get this wrong

Brandefense's 2026 research on the visibility gap put the underlying issue plainly: "The security program's visibility boundary is the attacker's opportunity boundary. Everything the security program cannot see is something the attacker can potentially exploit without triggering any internal alert." That's the whole argument for continuous ASM in one sentence, and it's worth keeping in mind before treating discovery as a box to check once a year.

The most common mistake isn't skipping discovery; it's treating discovery as the finish line. Finding your real asset inventory and then not funding remediation against the highest-scored findings leaves you with a more accurate map of the same risk, not a smaller one. The second common mistake is running a one-time assessment instead of continuous monitoring, which means your accurate map from six months ago is now missing every asset added since.

A smaller but real limitation worth acknowledging: ASM tools are very good at external, internet-facing discovery and less reliable at catching insider-driven exposure or already-compromised credentials circulating outside your infrastructure entirely. It's one layer of exposure management, not the whole program. Pair it with the identity and access controls discussed in our guide on privilege creep, and with dark web credential monitoring covered in our piece on dark web threats, for a more complete picture.

Joseph Harisson

Joseph Harisson

Founder of IT Companies Network

Joseph Harisson is the founder of IT Companies Network, a web-based platform that connects IT companies with each other, potential clients, and indust...

277 articles by this author