Attack surface
The set of points where an attacker can try to get in: exposed systems, accounts, vendors and, above all, people.
Full definition
The attack surface is the set of all points through which an attacker can try to enter an organization or extract data from it: exposed servers and applications, accounts and credentials, devices, vendors with access, and people reachable by email, phone or social media.
It grows with every new tool, every integration and every employee with a digital footprint, and the human part is now among the most exploited: every inbox is a door the attacker can knock on directly, without passing through the firewall. Remote work and SaaS multiplied those doors.
Managing it starts with inventory, systems, accounts, employees' public exposure, and continues with reduction and surveillance: closing what is unnecessary, hardening what is exposed, and measuring the risk of the human layer with the same discipline as infrastructure.
Related terms
Human factor
The human dimension of cybersecurity risk: the decisions and habits of people that an attacker can exploit. It is not a synonym for blame.
Shadow IT
Tools and services employees use without IT approval. Every invisible account is risk that nobody is watching.
OSINT
Intelligence built from public sources: websites, social media, records. The same information serves defense and attack preparation.
Threat actor
Any person or group with the intent and capability to attack: organized crime, state groups, hacktivists or insiders. Knowing them orders your defense.
From definition to data: measure your company's human risk
Fensivo detects leaked credentials, simulates real attacks and validates with retests that behavior changed.