Your Attack Surface Is Bigger Than You Think

The attack surface the security team has been defending is a fraction of the actual surface. The asset the security team knows about, the system the security team has patched, the application the security team has tested, the surface that…

Dark cinematic editorial image for Your Attack Surface Is Bigger Than You Think - abstract cyan digital composition, hacker aesthetic, no text no logos





4 MIN READ

Picture the asset inventory the security org ships to the board. Patched, tested, monitored, defended. That list is real, and it sits as roughly a third of the actual attack surface in use. Other two thirds are the things nobody scanned, the integrations nobody decommissioned, the SaaS subscriptions nobody asked permission for. Gap is the breach waiting to be claimed.

Here is the honest version. A modern enterprise is not a clean diagram of owned infrastructure. It is a sprawl. Marketing, finance, engineering, the line of business are all buying their own tools, opening their own cloud accounts, shipping their own integrations. List the board sees is a curated subset, and an attacker walks around the curation.

Where the hidden surface lives

Shadow IT leads. A line of business buys a SaaS subscription on a corporate card, an engineering team later builds an integration against the API, and the security org finds out about it from a quarterly review of the expense report. Cloud account is the same shape. A developer spins up an AWS sandbox on a personal credit card, forgets it for a year, leaves an S3 bucket readable to the public internet. None of it shows up in the asset inventory because it was never bought through procurement.

Forgotten subdomains come second. Marketing set up a subdomain for a campaign that ended three years ago, and the subdomain still points to a cloud storage bucket. DNS record still resolves, certificate still valid, bucket still public. Anyone running Subfinder or Amass finds the subdomain in under a minute, queries crt.sh to confirm the certificate, and walks straight in. Certificate transparency logs have made this trivial, and nobody has reason to know the campaign URL is still live.

Legacy integrations round out the trio. Original developer wrote an API call against a production system and left it running. Years later, the API is still there, still documented, still answering requests from outside the network. API key is in a public repo or a Stack Overflow answer. Nobody monitors it because the integration is not on any current roadmap. Exposure surfaces through the documentation leak, the GitHub search, or a Shodan query against a known endpoint pattern. Same shape as the last two: real, accessible, and invisible to the official inventory.

How it gets found

Certificate transparency first. Every certificate an enterprise issues to a public facing service is published to a public log, by CA policy. A query against crt.sh returns every subdomain the enterprise has ever issued a cert for, and a cross reference against the current DNS turns up the ones still pointing somewhere. Legacy subdomain from the campaign that ended three years ago is in the log, dev subdomain from last quarter is in the log, both still pointing somewhere. The log is a complete record of what the enterprise has ever exposed to the public internet, and it is searchable by anyone with a browser.

DNS enumeration second. Subfinder, Amass, and the half dozen open source tools built on top of them will find the subdomains the certificate log misses. Brute force, permutation scans, passive DNS data. The point is that obscurity is not a defence. Tooling is the same on both sides, and the offensive side has had a decade of practice at running it at scale.

Leaked credentials close the trio. A credential dump from a previous breach, the email and password pairs run through HaveIBeenPwned, and the working ones get tested against the public facing SaaS the enterprise has not enrolled in single sign on. Credential from the LinkedIn breach in 2021 is the same one an employee reused for the CRM. The login looks like a normal user, and the security team finds out only when the data starts leaving the network.

How to find it before the breach

Run an external attack surface scan, quarterly, against the full internet exposed footprint. Shodan, Censys, and runZero will surface the subdomains, the open ports, the forgotten cloud assets, the certificates, in a single report. The scan does not need to be clever. It needs to be regular, and it needs to feed back into the asset inventory the security org ships to the board.

Audit the SaaS. SaaS Management Platform tools (Zylo, Productiv, Torii) will pull the subscription list from the financial system, join it against the SSO directory, and surface the SaaS the line of business bought without telling IT. Audit catches the shadow IT, the duplicate subscriptions, the SaaS that should have had a security review and did not. Manual review of the expense report is the same exercise at smaller scale.

Decommission the legacy integration. Pick one per quarter, kill the API, rotate the credential, update the documentation. Integration that is not on the current roadmap is the one that is leaking. Operations has been postponing the work for years, and the postponement is what an incident is waiting on.

Abstract attack surface as glowing cyan expanding ripple on a dark navy surface, dramatic chiaroscuro lighting from above.
The hidden attack surface in 2026: 3 places the surface hides, 3 ways the attacker finds it, 3 moves to map it before the breach.

The bottom line

Scan the external attack surface, audit the SaaS, decommission the legacy integration. The org that runs the three holds the line; the org that does not serves as the breach disclosure the board reads on a Sunday night.


Sources & Further Reading

All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.

Spotted an error? Email the editor. Corrections are issued with a visible correction note.

Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.

Continue reading