Attack Surface
An attack surface is the sum of all digital entry points an adversary could exploit in a target organization: exposed IP addresses, open ports, web applications, DNS records, subdomains, email servers, and more. In third-party cyber risk management, an organization's effective attack surface includes not just its own assets but those of every vendor with access to its systems or data.
That latter is the one most attack surface discussions skip. A security team can spend a quarter mapping its own perimeter down to the last forgotten subdomain and still be blind to the majority of its real exposure, because a modern organization’s risk doesn’t stop at assets it owns. It extends through every vendor, contractor, and service provider connected to it.
What Makes Up an Organization’s Attack Surface?
An attack surface is made up of every externally reachable asset an organization owns or controls: network infrastructure, web applications, identity systems, and the certificates that secure them.
- Network-facing assets: IP addresses, open ports, and exposed services that respond to an outside connection.
- Web and application assets: public-facing web apps, APIs, and login portals.
- Identity and email infrastructure: email servers, DNS records, and domain configurations.
- Certificates and encryption: SSL/TLS certificates and how they’re configured and maintained.
- Leaked credentials: usernames, passwords, and tokens already circulating outside the organization, exposure that exists whether or not any system was misconfigured to produce it.
- Third-party scripts and embedded services: code loaded from someone else’s infrastructure into a web page or app, an external asset the organization doesn’t operate but is still exposed through.
Each category is a different kind of door. A misconfigured DNS record and a credential already for sale on a criminal marketplace fail in completely different ways, but both count toward the same total, and both are equally invisible to a team that’s only looking at one category.
How Is a Vendor’s Attack Surface Different From an Organization’s Own?
A vendor’s attack surface is exactly the same category of thing as an organization’s own, just observed from outside a relationship the organization doesn’t control.
An organization can patch its own servers the same day a vulnerability is disclosed. It has no such lever over a vendor’s servers. It can only see what’s externally visible, track whether that visible surface is shrinking or growing, and decide how much of its own risk tolerance that vendor is allowed to consume. The vendor’s attack surface becomes, functionally, an extension of the organization’s own, and a third-party breach is what happens when that extension gets exploited before anyone outside the vendor notices.
Why Does the Attack Surface Keep Growing?
The attack surface most organizations map today is smaller than the one that actually exists, because cloud services, forgotten subdomains, and unmanaged vendor relationships expand it continuously.
Cloud and SaaS Sprawl
Black Kite’s 2026 Wholesale & Retail Cyber Exposure Report found that 68% of critical vendors in a mapped supply chain carried at least one critical-level patch management vulnerability, a gap that widens every time a new SaaS tool, cloud bucket, or sub-processor gets added to the chain without a corresponding update to what’s being tracked. Nobody sits down once a quarter and decides to expand the attack surface. It happens by accumulation.
Mergers, Acquisitions, and Inherited Infrastructure
A company gets acquired and its infrastructure comes along largely unreviewed, often running on different standards, patched on a different schedule, and known to almost nobody on the acquiring side’s security team. That inherited infrastructure counts toward the combined attack surface from the day the deal closes, whether or not anyone has mapped it yet.
Does Attack Surface Size Vary by Industry?
Attack surface size and composition vary significantly by industry, shaped by how much of the business runs through public-facing digital infrastructure versus physical operations.
A retail organization with hundreds of point-of-sale integrations and a marketing stack built from a dozen SaaS tools carries a fundamentally different attack surface than a manufacturer whose main digital footprint is a handful of corporate domains and an increasingly connected set of operational technology. Retail and financial services tend to run much of their business through public-facing digital infrastructure, customer-facing web properties, payment integrations, and a steady churn of new vendors and tools, each of which adds to the attack surface as it's deployed.
Retail organizations in particular inherit this complexity twice: once in their own footprint, and again through every supplier in a physical and digital supply chain at once.
How Do Organizations Discover and Manage Their Attack Surface?
Attack Surface Management (ASM) is the discipline built specifically to answer that question, covering both the assets an organization can see from inside its own network and the ones only visible from outside it.
Attack Surface Management (ASM) covers both halves. The internal half uses agents, credentials, and network access an organization already has. The external half, the piece that actually applies to a vendor relationship, is External Attack Surface Management (EASM), since no organization has agents or credentials inside a vendor’s network. A vulnerability assessment picks up where attack surface mapping leaves off, testing whether a discovered entry point is actually exploitable.
How Is This Applied Across a Vendor Portfolio?
Mapping the attack surface of one vendor is straightforward. Mapping it continuously across hundreds of vendors, none of which will install an agent or grant credentials, is the actual operational problem.
Black Kite's cyber risk rating includes a dedicated Attack Surface category that scores exactly this kind of exposure: open critical ports, out-of-date services, application weaknesses, SSL/TLS strength, and misconfigurations, correlated from internet-wide scanners like Censys and Shodan. That's the same discipline ASM describes, aimed at a vendor's cyber ecosystem instead of an organization's own network.
Feeding that category continuously, across an entire portfolio, is what Black Kite Monitor does. It builds each vendor's digital footprint starting from a single top-level domain, then continuously tracks its IP addresses, subdomains, DNS records, WHOIS data, running services, and ASNs without ever touching the vendor's internal systems. A current, accurate vendor inventory is what makes that tracking possible at scale. For a third-party risk management team, that removes the two things a vendor relationship never provides on its own: credentialed access and a reason for the vendor to keep an inventory updated on the buyer's behalf.
What Are the Limits of Attack-Surface Thinking Alone?
Mapping the attack surface only shows where an adversary could get in. It says nothing about whether a specific entry point is actually vulnerable, or whether anyone is currently trying to use it.
Exposure Is Not the Same as Exploitability
An open port or an old subdomain is a potential entry point, not a confirmed one. Whether it’s actually exploitable depends on what’s running behind it, how current the software is, and whether a known weakness exists in that specific version, questions an attack surface map alone was never built to answer.
A Map Has No Sense of Urgency
A complete inventory treats a five-year-old forgotten subdomain and an asset actively being probed by a ransomware group’s scanning tools as the same kind of entry: present. Risk intelligence is the layer that adds real-world threat activity on top of the map, turning an inventory of what exists into a queue of what to act on first.
See also: