[{"data":1,"prerenderedAt":1063},["ShallowReactive",2],{"\u002Fblog\u002Funderstanding-your-true-attack-surface-part-two":3,"blog-all-posts":988},{"_path":4,"_dir":5,"_draft":6,"_partial":6,"_locale":7,"title":8,"description":9,"cardTitle":10,"titleLines":11,"descriptionLines":15,"bodyLeadTitle":18,"publishedAt":19,"updatedAt":19,"tags":20,"coverImage":24,"coverAlt":25,"heroLayout":26,"heroTitleSize":27,"heroCopyPosition":28,"featured":6,"draft":6,"body":29,"_type":982,"_id":983,"_source":984,"_file":985,"_stem":986,"_extension":987},"\u002Fblog\u002Funderstanding-your-true-attack-surface-part-two","blog",false,"","Understanding Your True Attack Surface: Part Two","Few companies understand how they look to an attacker. Your Internet attack surface is exactly what attackers see first.","Understanding Your True Attack Surface Part Two",[12,13,14],"Understanding Your","True Attack Surface:","Part Two",[16,17],"Few companies understand how","they look to an attacker.","Two Views","2026-07-28",[21,22,23],"attack surface","internet security","cybersecurity strategy","\u002Fblog\u002Funderstanding-your-true-attack-surface-part-two\u002Fcover.jpg","Cyber operations control tower monitoring a connected city and its Internet-facing attack surface","overlay","compact","right",{"type":30,"children":31,"toc":970},"root",[32,48,58,63,71,76,84,101,106,114,121,126,131,141,146,207,212,263,268,276,282,287,299,349,354,360,365,370,453,458,470,475,494,500,505,510,568,573,578,637,642,652,657,669,674,679,691,696,702,707,712,717,729,741,746,751,757,762,767,826,831,836,887,892,900,905,911,916,926,931,939,944,952,958],{"type":33,"tag":34,"props":35,"children":36},"element","p",{},[37,40,46],{"type":38,"value":39},"text","Every company has ",{"type":33,"tag":41,"props":42,"children":43},"strong",{},[44],{"type":38,"value":45},"two views",{"type":38,"value":47}," of itself.",{"type":33,"tag":34,"props":49,"children":50},{},[51,53],{"type":38,"value":52},"The first is the internal view, the systems, applications, users, and infrastructure ",{"type":33,"tag":41,"props":54,"children":55},{},[56],{"type":38,"value":57},"IT believes it manages.",{"type":33,"tag":34,"props":59,"children":60},{},[61],{"type":38,"value":62},"The second is the external view, the collection of Internet-facing assets that cybercriminals can discover, analyze, and attack.",{"type":33,"tag":34,"props":64,"children":65},{},[66],{"type":33,"tag":41,"props":67,"children":68},{},[69],{"type":38,"value":70},"These two views are rarely identical.",{"type":33,"tag":34,"props":72,"children":73},{},[74],{"type":38,"value":75},"The Internet has fundamentally changed how organizations operate. Cloud computing, remote work, SaaS platforms, mobile apps, APIs, and third-party integrations have expanded business capabilities while simultaneously expanding the attack surface available to cybercriminals.",{"type":33,"tag":34,"props":77,"children":78},{},[79],{"type":33,"tag":41,"props":80,"children":81},{},[82],{"type":38,"value":83},"Few companies understand how they look to an attacker.",{"type":33,"tag":34,"props":85,"children":86},{},[87,89,94,96],{"type":38,"value":88},"Unlike physical facilities that close their doors at night, ",{"type":33,"tag":41,"props":90,"children":91},{},[92],{"type":38,"value":93},"Internet-facing infrastructure is accessible 24 hours a day, 365 days a year.",{"type":38,"value":95}," Automated scanning systems operated by threat actors continuously search the Internet looking for vulnerable systems, exposed services, weak configurations, and forgotten assets. Most organizations are being ",{"type":33,"tag":41,"props":97,"children":98},{},[99],{"type":38,"value":100},"probed thousands of times every day, often without realizing it.",{"type":33,"tag":34,"props":102,"children":103},{},[104],{"type":38,"value":105},"Before an attacker targets an organization, they first perform reconnaissance. They inventory everything they can reach from the Internet, identify weaknesses, prioritize targets, and determine the easiest path into the organization.",{"type":33,"tag":34,"props":107,"children":108},{},[109],{"type":33,"tag":41,"props":110,"children":111},{},[112],{"type":38,"value":113},"Your Internet attack surface is exactly what attackers see first.",{"type":33,"tag":115,"props":116,"children":118},"h2",{"id":117},"dns",[119],{"type":38,"value":120},"DNS",{"type":33,"tag":34,"props":122,"children":123},{},[124],{"type":38,"value":125},"It all begins with DNS.",{"type":33,"tag":34,"props":127,"children":128},{},[129],{"type":38,"value":130},"The Domain Name System (DNS) serves as the Internet's directory service. DNS translates numerical IP addresses (such as 8.8.8.8) into easy-to-remember domain names (such as dns.google).",{"type":33,"tag":34,"props":132,"children":133},{},[134,139],{"type":33,"tag":41,"props":135,"children":136},{},[137],{"type":38,"value":138},"Every public-facing system generally begins with DNS.",{"type":38,"value":140}," Companies manage their infrastructure with DNS entries. When they transfer a server, application, or resource into production, they give it a DNS entry.",{"type":33,"tag":34,"props":142,"children":143},{},[144],{"type":38,"value":145},"DNS records reveal valuable intelligence, including:",{"type":33,"tag":147,"props":148,"children":149},"ul",{},[150,159,167,175,183,191,199],{"type":33,"tag":151,"props":152,"children":153},"li",{},[154],{"type":33,"tag":41,"props":155,"children":156},{},[157],{"type":38,"value":158},"Public hostnames",{"type":33,"tag":151,"props":160,"children":161},{},[162],{"type":33,"tag":41,"props":163,"children":164},{},[165],{"type":38,"value":166},"Mail servers",{"type":33,"tag":151,"props":168,"children":169},{},[170],{"type":33,"tag":41,"props":171,"children":172},{},[173],{"type":38,"value":174},"Cloud providers",{"type":33,"tag":151,"props":176,"children":177},{},[178],{"type":33,"tag":41,"props":179,"children":180},{},[181],{"type":38,"value":182},"Third-party services",{"type":33,"tag":151,"props":184,"children":185},{},[186],{"type":33,"tag":41,"props":187,"children":188},{},[189],{"type":38,"value":190},"Geographic infrastructure",{"type":33,"tag":151,"props":192,"children":193},{},[194],{"type":33,"tag":41,"props":195,"children":196},{},[197],{"type":38,"value":198},"Development environments",{"type":33,"tag":151,"props":200,"children":201},{},[202],{"type":33,"tag":41,"props":203,"children":204},{},[205],{"type":38,"value":206},"Disaster recovery sites",{"type":33,"tag":34,"props":208,"children":209},{},[210],{"type":38,"value":211},"Attackers routinely analyze DNS to:",{"type":33,"tag":147,"props":213,"children":214},{},[215,223,231,239,247,255],{"type":33,"tag":151,"props":216,"children":217},{},[218],{"type":33,"tag":41,"props":219,"children":220},{},[221],{"type":38,"value":222},"Discover forgotten systems",{"type":33,"tag":151,"props":224,"children":225},{},[226],{"type":33,"tag":41,"props":227,"children":228},{},[229],{"type":38,"value":230},"Identify cloud providers",{"type":33,"tag":151,"props":232,"children":233},{},[234],{"type":33,"tag":41,"props":235,"children":236},{},[237],{"type":38,"value":238},"Enumerate subdomains",{"type":33,"tag":151,"props":240,"children":241},{},[242],{"type":33,"tag":41,"props":243,"children":244},{},[245],{"type":38,"value":246},"Locate remote access portals",{"type":33,"tag":151,"props":248,"children":249},{},[250],{"type":33,"tag":41,"props":251,"children":252},{},[253],{"type":38,"value":254},"Identify email infrastructure",{"type":33,"tag":151,"props":256,"children":257},{},[258],{"type":33,"tag":41,"props":259,"children":260},{},[261],{"type":38,"value":262},"Build target profiles",{"type":33,"tag":34,"props":264,"children":265},{},[266],{"type":38,"value":267},"DNS is often the first external data source attackers query because it can reveal an organization's structure without ever interacting with the target itself. Even without exploiting a single vulnerability, DNS often provides a detailed blueprint of an organization's Internet presence.",{"type":33,"tag":34,"props":269,"children":270},{},[271],{"type":33,"tag":41,"props":272,"children":273},{},[274],{"type":38,"value":275},"Companies often do not understand that DNS reveals much more about their external and internal infrastructure than they would like.",{"type":33,"tag":115,"props":277,"children":279},{"id":278},"certificates",[280],{"type":38,"value":281},"Certificates",{"type":33,"tag":34,"props":283,"children":284},{},[285],{"type":38,"value":286},"Digital certificates establish encrypted communications and verify identity. Secure communication across the Internet can't happen without them.",{"type":33,"tag":34,"props":288,"children":289},{},[290,292,297],{"type":38,"value":291},"Public Certificate Transparency (CT) logs were created to improve Internet security by recording every publicly trusted TLS certificate issued worldwide. ",{"type":33,"tag":41,"props":293,"children":294},{},[295],{"type":38,"value":296},"While this improves trust, it also provides attackers with a continuously updated inventory of publicly deployed systems.",{"type":38,"value":298}," This is a valuable source of reconnaissance information. From these records, attackers can often identify:",{"type":33,"tag":147,"props":300,"children":301},{},[302,310,318,326,333,341],{"type":33,"tag":151,"props":303,"children":304},{},[305],{"type":33,"tag":41,"props":306,"children":307},{},[308],{"type":38,"value":309},"New subdomains",{"type":33,"tag":151,"props":311,"children":312},{},[313],{"type":33,"tag":41,"props":314,"children":315},{},[316],{"type":38,"value":317},"Internal naming conventions",{"type":33,"tag":151,"props":319,"children":320},{},[321],{"type":33,"tag":41,"props":322,"children":323},{},[324],{"type":38,"value":325},"Cloud deployments",{"type":33,"tag":151,"props":327,"children":328},{},[329],{"type":33,"tag":41,"props":330,"children":331},{},[332],{"type":38,"value":198},{"type":33,"tag":151,"props":334,"children":335},{},[336],{"type":33,"tag":41,"props":337,"children":338},{},[339],{"type":38,"value":340},"Geographic locations",{"type":33,"tag":151,"props":342,"children":343},{},[344],{"type":33,"tag":41,"props":345,"children":346},{},[347],{"type":38,"value":348},"Recently deployed applications",{"type":33,"tag":34,"props":350,"children":351},{},[352],{"type":38,"value":353},"Organizations frequently discover forgotten Internet-facing systems simply by reviewing their own certificates. Certificate management is therefore both a security and an asset management function.",{"type":33,"tag":115,"props":355,"children":357},{"id":356},"internet-facing-assets",[358],{"type":38,"value":359},"Internet-Facing Assets",{"type":33,"tag":34,"props":361,"children":362},{},[363],{"type":38,"value":364},"Every organization intentionally exposes certain systems to the Internet. These assets enable customers, employees, partners, and vendors to interact with the business. This is how the Internet works.",{"type":33,"tag":34,"props":366,"children":367},{},[368],{"type":38,"value":369},"Typical Internet-facing assets include:",{"type":33,"tag":147,"props":371,"children":372},{},[373,381,389,397,405,413,421,429,437,445],{"type":33,"tag":151,"props":374,"children":375},{},[376],{"type":33,"tag":41,"props":377,"children":378},{},[379],{"type":38,"value":380},"Corporate websites",{"type":33,"tag":151,"props":382,"children":383},{},[384],{"type":33,"tag":41,"props":385,"children":386},{},[387],{"type":38,"value":388},"Customer portals",{"type":33,"tag":151,"props":390,"children":391},{},[392],{"type":33,"tag":41,"props":393,"children":394},{},[395],{"type":38,"value":396},"Employee portals",{"type":33,"tag":151,"props":398,"children":399},{},[400],{"type":33,"tag":41,"props":401,"children":402},{},[403],{"type":38,"value":404},"Remote access gateways",{"type":33,"tag":151,"props":406,"children":407},{},[408],{"type":33,"tag":41,"props":409,"children":410},{},[411],{"type":38,"value":412},"Email services",{"type":33,"tag":151,"props":414,"children":415},{},[416],{"type":33,"tag":41,"props":417,"children":418},{},[419],{"type":38,"value":420},"Cloud applications",{"type":33,"tag":151,"props":422,"children":423},{},[424],{"type":33,"tag":41,"props":425,"children":426},{},[427],{"type":38,"value":428},"APIs",{"type":33,"tag":151,"props":430,"children":431},{},[432],{"type":33,"tag":41,"props":433,"children":434},{},[435],{"type":38,"value":436},"Mobile application backends",{"type":33,"tag":151,"props":438,"children":439},{},[440],{"type":33,"tag":41,"props":441,"children":442},{},[443],{"type":38,"value":444},"DNS infrastructure",{"type":33,"tag":151,"props":446,"children":447},{},[448],{"type":33,"tag":41,"props":449,"children":450},{},[451],{"type":38,"value":452},"Identity providers",{"type":33,"tag":34,"props":454,"children":455},{},[456],{"type":38,"value":457},"Each exposed asset represents another doorway into the organization.",{"type":33,"tag":34,"props":459,"children":460},{},[461,463,468],{"type":38,"value":462},"The challenge for executives is that these ",{"type":33,"tag":41,"props":464,"children":465},{},[466],{"type":38,"value":467},"assets continually change.",{"type":38,"value":469}," New applications are deployed, cloud resources are created and then torn down, acquisitions introduce additional infrastructure, and development teams publish services without security teams always having complete visibility.",{"type":33,"tag":34,"props":471,"children":472},{},[473],{"type":38,"value":474},"Each Internet-facing asset has its own protocols, software, and data that also contain potential security issues such as vulnerabilities, configuration weaknesses, and information disclosures.",{"type":33,"tag":34,"props":476,"children":477},{},[478,480,485,487,492],{"type":38,"value":479},"In the end, an organization's ",{"type":33,"tag":41,"props":481,"children":482},{},[483],{"type":38,"value":484},"actual attack surface",{"type":38,"value":486}," is significantly larger than the ",{"type":33,"tag":41,"props":488,"children":489},{},[490],{"type":38,"value":491},"known attack surface",{"type":38,"value":493},".",{"type":33,"tag":115,"props":495,"children":497},{"id":496},"websites",[498],{"type":38,"value":499},"Websites",{"type":33,"tag":34,"props":501,"children":502},{},[503],{"type":38,"value":504},"Corporate websites have evolved from simple marketing pages into complex business platforms. Companies often spend considerable time, money, and effort securing their network assets without a thought to securing their websites. And yet, websites are the assets that generate a substantial amount of their income and represent the public face of the company.",{"type":33,"tag":34,"props":506,"children":507},{},[508],{"type":38,"value":509},"Today's websites frequently contain:",{"type":33,"tag":147,"props":511,"children":512},{},[513,520,528,536,544,552,560],{"type":33,"tag":151,"props":514,"children":515},{},[516],{"type":33,"tag":41,"props":517,"children":518},{},[519],{"type":38,"value":388},{"type":33,"tag":151,"props":521,"children":522},{},[523],{"type":33,"tag":41,"props":524,"children":525},{},[526],{"type":38,"value":527},"Authentication systems",{"type":33,"tag":151,"props":529,"children":530},{},[531],{"type":33,"tag":41,"props":532,"children":533},{},[534],{"type":38,"value":535},"Shopping carts",{"type":33,"tag":151,"props":537,"children":538},{},[539],{"type":33,"tag":41,"props":540,"children":541},{},[542],{"type":38,"value":543},"Payment processing",{"type":33,"tag":151,"props":545,"children":546},{},[547],{"type":33,"tag":41,"props":548,"children":549},{},[550],{"type":38,"value":551},"Search functionality",{"type":33,"tag":151,"props":553,"children":554},{},[555],{"type":33,"tag":41,"props":556,"children":557},{},[558],{"type":38,"value":559},"Document repositories",{"type":33,"tag":151,"props":561,"children":562},{},[563],{"type":33,"tag":41,"props":564,"children":565},{},[566],{"type":38,"value":567},"Third-party integrations",{"type":33,"tag":34,"props":569,"children":570},{},[571],{"type":38,"value":572},"Every technology introduced into a website increases its complexity and potentially its attack surface.",{"type":33,"tag":34,"props":574,"children":575},{},[576],{"type":38,"value":577},"Attackers routinely analyze websites to identify:",{"type":33,"tag":147,"props":579,"children":580},{},[581,589,597,605,613,621,629],{"type":33,"tag":151,"props":582,"children":583},{},[584],{"type":33,"tag":41,"props":585,"children":586},{},[587],{"type":38,"value":588},"Outdated software",{"type":33,"tag":151,"props":590,"children":591},{},[592],{"type":33,"tag":41,"props":593,"children":594},{},[595],{"type":38,"value":596},"Misconfigurations",{"type":33,"tag":151,"props":598,"children":599},{},[600],{"type":33,"tag":41,"props":601,"children":602},{},[603],{"type":38,"value":604},"Exposed administration interfaces",{"type":33,"tag":151,"props":606,"children":607},{},[608],{"type":33,"tag":41,"props":609,"children":610},{},[611],{"type":38,"value":612},"Authentication weaknesses",{"type":33,"tag":151,"props":614,"children":615},{},[616],{"type":33,"tag":41,"props":617,"children":618},{},[619],{"type":38,"value":620},"Business logic flaws",{"type":33,"tag":151,"props":622,"children":623},{},[624],{"type":33,"tag":41,"props":625,"children":626},{},[627],{"type":38,"value":628},"Sensitive information disclosure",{"type":33,"tag":151,"props":630,"children":631},{},[632],{"type":33,"tag":41,"props":633,"children":634},{},[635],{"type":38,"value":636},"Third-party vulnerabilities",{"type":33,"tag":34,"props":638,"children":639},{},[640],{"type":38,"value":641},"A public website is often the first opportunity attackers have to learn how an organization operates internally.",{"type":33,"tag":34,"props":643,"children":644},{},[645,647],{"type":38,"value":646},"Websites have their own vulnerabilities and weaknesses, just like traditional networks. ",{"type":33,"tag":41,"props":648,"children":649},{},[650],{"type":38,"value":651},"And yet companies create websites without putting sufficient effort into securing them.",{"type":33,"tag":115,"props":653,"children":655},{"id":654},"apis",[656],{"type":38,"value":428},{"type":33,"tag":34,"props":658,"children":659},{},[660,662,667],{"type":38,"value":661},"Modern organizations increasingly communicate through Application Programming Interfaces (APIs), which now account for a substantial share, ",{"type":33,"tag":41,"props":663,"children":664},{},[665],{"type":38,"value":666},"roughly 55–60% of dynamic web traffic",{"type":38,"value":668}," according to Cloudflare's global network observations.",{"type":33,"tag":34,"props":670,"children":671},{},[672],{"type":38,"value":673},"APIs are the server-to-server communication flows critical to business operations. Their uses include mobile and cloud applications, payment systems, healthcare platforms, ERP, and CRM, to name a few.",{"type":33,"tag":34,"props":675,"children":676},{},[677],{"type":38,"value":678},"Similar to websites, companies spin up APIs without a thought to the security issues surrounding them. Because APIs exchange structured data rather than web pages, vulnerabilities can expose entire business processes rather than isolated web pages.",{"type":33,"tag":34,"props":680,"children":681},{},[682,684,689],{"type":38,"value":683},"Unlike traditional websites, ",{"type":33,"tag":41,"props":685,"children":686},{},[687],{"type":38,"value":688},"APIs often expose direct access to business data and functionality.",{"type":38,"value":690}," Because they are designed for machine-to-machine communication, APIs may not receive the same level of security testing or visibility as public web applications.",{"type":33,"tag":34,"props":692,"children":693},{},[694],{"type":38,"value":695},"As organizations become increasingly API-driven, APIs frequently become one of the largest, and least understood, components of the modern attack surface.",{"type":33,"tag":115,"props":697,"children":699},{"id":698},"remote-networks",[700],{"type":38,"value":701},"Remote Networks",{"type":33,"tag":34,"props":703,"children":704},{},[705],{"type":38,"value":706},"Recent years have brought with them an explosion in remote and hybrid working, which has permanently expanded organizational boundaries. Employees now routinely connect from home offices, hotels, airports, customer sites, coffee shops, mobile devices, and international travel locations.",{"type":33,"tag":34,"props":708,"children":709},{},[710],{"type":38,"value":711},"Remote connectivity now commonly includes VPNs, zero trust network access (ZTNA), virtual desktop infrastructure (VDI), remote desktop gateways, bastion hosts, and cloud identity providers.",{"type":33,"tag":34,"props":713,"children":714},{},[715],{"type":38,"value":716},"Every remote access technology becomes another Internet-facing entry point.",{"type":33,"tag":34,"props":718,"children":719},{},[720,722,727],{"type":38,"value":721},"Most companies do not understand that this has ",{"type":33,"tag":41,"props":723,"children":724},{},[725],{"type":38,"value":726},"dramatically expanded their security perimeter",{"type":38,"value":728}," into areas that are hard to identify and assess. The risk to this expanded perimeter must be captured and addressed with an appropriate control.",{"type":33,"tag":34,"props":730,"children":731},{},[732,734,739],{"type":38,"value":733},"Organizations increasingly ",{"type":33,"tag":41,"props":735,"children":736},{},[737],{"type":38,"value":738},"rely on devices and networks they do not own or control,",{"type":38,"value":740}," making visibility and policy enforcement substantially more difficult.",{"type":33,"tag":34,"props":742,"children":743},{},[744],{"type":38,"value":745},"Compromised credentials, weak authentication, vulnerable VPN appliances, or misconfigured remote access solutions have been responsible for numerous high-profile breaches.",{"type":33,"tag":34,"props":747,"children":748},{},[749],{"type":38,"value":750},"For executives, remote access is no longer simply an IT convenience. It is a critical business risk that requires continuous monitoring and validation.",{"type":33,"tag":115,"props":752,"children":754},{"id":753},"firewalls-vpns",[755],{"type":38,"value":756},"Firewalls & VPNs",{"type":33,"tag":34,"props":758,"children":759},{},[760],{"type":38,"value":761},"Firewalls remain an essential security control, but they should not be mistaken for a complete security strategy. Many organizations understandably assume that once a modern firewall has been deployed, their Internet-facing infrastructure is largely protected.",{"type":33,"tag":34,"props":763,"children":764},{},[765],{"type":38,"value":766},"Modern firewalls have now expanded to provide:",{"type":33,"tag":147,"props":768,"children":769},{},[770,778,786,794,802,810,818],{"type":33,"tag":151,"props":771,"children":772},{},[773],{"type":33,"tag":41,"props":774,"children":775},{},[776],{"type":38,"value":777},"Traffic filtering",{"type":33,"tag":151,"props":779,"children":780},{},[781],{"type":33,"tag":41,"props":782,"children":783},{},[784],{"type":38,"value":785},"Application awareness",{"type":33,"tag":151,"props":787,"children":788},{},[789],{"type":33,"tag":41,"props":790,"children":791},{},[792],{"type":38,"value":793},"Intrusion prevention",{"type":33,"tag":151,"props":795,"children":796},{},[797],{"type":33,"tag":41,"props":798,"children":799},{},[800],{"type":38,"value":801},"Threat intelligence",{"type":33,"tag":151,"props":803,"children":804},{},[805],{"type":33,"tag":41,"props":806,"children":807},{},[808],{"type":38,"value":809},"Geo-blocking",{"type":33,"tag":151,"props":811,"children":812},{},[813],{"type":33,"tag":41,"props":814,"children":815},{},[816],{"type":38,"value":817},"Malware inspection",{"type":33,"tag":151,"props":819,"children":820},{},[821],{"type":33,"tag":41,"props":822,"children":823},{},[824],{"type":38,"value":825},"SSL\u002FTLS inspection",{"type":33,"tag":34,"props":827,"children":828},{},[829],{"type":38,"value":830},"Despite these capabilities, firewalls intentionally expose services that organizations need for business operations.",{"type":33,"tag":34,"props":832,"children":833},{},[834],{"type":38,"value":835},"Similarly, VPN gateways are designed to provide secure remote access, yet they are among the most frequently targeted systems on the Internet. Attackers continually scan for:",{"type":33,"tag":147,"props":837,"children":838},{},[839,847,855,863,871,879],{"type":33,"tag":151,"props":840,"children":841},{},[842],{"type":33,"tag":41,"props":843,"children":844},{},[845],{"type":38,"value":846},"Unpatched VPN appliances",{"type":33,"tag":151,"props":848,"children":849},{},[850],{"type":33,"tag":41,"props":851,"children":852},{},[853],{"type":38,"value":854},"Default configurations",{"type":33,"tag":151,"props":856,"children":857},{},[858],{"type":33,"tag":41,"props":859,"children":860},{},[861],{"type":38,"value":862},"Weak encryption",{"type":33,"tag":151,"props":864,"children":865},{},[866],{"type":33,"tag":41,"props":867,"children":868},{},[869],{"type":38,"value":870},"Vulnerable firmware",{"type":33,"tag":151,"props":872,"children":873},{},[874],{"type":33,"tag":41,"props":875,"children":876},{},[877],{"type":38,"value":878},"Credential attacks",{"type":33,"tag":151,"props":880,"children":881},{},[882],{"type":33,"tag":41,"props":883,"children":884},{},[885],{"type":38,"value":886},"Authentication bypass vulnerabilities",{"type":33,"tag":34,"props":888,"children":889},{},[890],{"type":38,"value":891},"Because VPNs often provide direct access into internal networks, a successful compromise can dramatically reduce the effort required to move laterally throughout an organization.",{"type":33,"tag":34,"props":893,"children":894},{},[895],{"type":33,"tag":41,"props":896,"children":897},{},[898],{"type":38,"value":899},"In recent years, both firewalls and VPNs themselves have experienced extremely dangerous vulnerabilities that compromise the very security of the networks they were supposed to protect.",{"type":33,"tag":34,"props":901,"children":902},{},[903],{"type":38,"value":904},"It's important to understand that firewalls and VPNs can themselves pose a threat to a company's security posture and must be included in the risk assessment.",{"type":33,"tag":115,"props":906,"children":908},{"id":907},"what-does-your-company-look-like-to-an-attacker",[909],{"type":38,"value":910},"What Does Your Company Look Like to an Attacker?",{"type":33,"tag":34,"props":912,"children":913},{},[914],{"type":38,"value":915},"Most organizations think they understand what is exposed to the Internet.",{"type":33,"tag":34,"props":917,"children":918},{},[919,924],{"type":33,"tag":41,"props":920,"children":921},{},[922],{"type":38,"value":923},"In reality, Internet-facing infrastructure changes continuously.",{"type":38,"value":925}," Cloud resources appear and disappear, development teams deploy new services, vendors create integrations, acquisitions introduce new assets, and forgotten systems remain online long after they are needed.",{"type":33,"tag":34,"props":927,"children":928},{},[929],{"type":38,"value":930},"Attackers exploit this lack of visibility.",{"type":33,"tag":34,"props":932,"children":933},{},[934],{"type":33,"tag":41,"props":935,"children":936},{},[937],{"type":38,"value":938},"Attackers may understand your Internet-facing infrastructure better than you do.",{"type":33,"tag":34,"props":940,"children":941},{},[942],{"type":38,"value":943},"Understanding your Internet and network attack surface is therefore not simply an IT exercise. It is a business risk management discipline that enables executives to answer one fundamental question:",{"type":33,"tag":34,"props":945,"children":946},{},[947],{"type":33,"tag":41,"props":948,"children":949},{},[950],{"type":38,"value":951},"What do I look like to an attacker?",{"type":33,"tag":115,"props":953,"children":955},{"id":954},"coming-in-part-three",[956],{"type":38,"value":957},"Coming in Part Three",{"type":33,"tag":34,"props":959,"children":960},{},[961,963,968],{"type":38,"value":962},"The next frontier of cybersecurity is ",{"type":33,"tag":41,"props":964,"children":965},{},[966],{"type":38,"value":967},"no longer simply protecting systems; it's protecting identities.",{"type":38,"value":969}," In Part Three, we'll examine how attackers increasingly bypass technical defenses altogether by logging in with stolen credentials, abusing privileged accounts, and exploiting trust relationships throughout modern cloud environments.",{"title":7,"searchDepth":971,"depth":971,"links":972},2,[973,974,975,976,977,978,979,980,981],{"id":117,"depth":971,"text":120},{"id":278,"depth":971,"text":281},{"id":356,"depth":971,"text":359},{"id":496,"depth":971,"text":499},{"id":654,"depth":971,"text":428},{"id":698,"depth":971,"text":701},{"id":753,"depth":971,"text":756},{"id":907,"depth":971,"text":910},{"id":954,"depth":971,"text":957},"markdown","content:blog:understanding-your-true-attack-surface-part-two.md","content","blog\u002Funderstanding-your-true-attack-surface-part-two.md","blog\u002Funderstanding-your-true-attack-surface-part-two","md",[989,991,1001,1012,1022,1030,1042,1053],{"_path":4,"title":8,"description":9,"cardTitle":10,"publishedAt":19,"tags":990,"coverImage":24,"coverAlt":25,"featured":6},[21,22,23],{"_path":992,"title":993,"description":994,"publishedAt":995,"tags":996,"coverImage":999,"coverAlt":1000,"featured":6},"\u002Fblog\u002Ftop-cyber-threats-facing-businesses-in-2026","Top Cyber Threats Facing Businesses in 2026","Businesses face AI-assisted hacking, interception-proxy phishing, dark web breach data, and API attacks in 2026.","2026-06-26",[997,998,23],"cyber threats","business security","\u002Fblog\u002Ftop-cyber-threats-facing-businesses-in-2026\u002Fcover.jpg","A city skyline beneath a massive storm cloud embedded with cybersecurity symbols and lightning",{"_path":1002,"title":1003,"description":1004,"publishedAt":1005,"tags":1006,"coverImage":1010,"coverAlt":1011,"featured":6},"\u002Fblog\u002Fchallenges-facing-ai-frontier-models-part-two","Challenges Facing AI Frontier Models Part Two","Frontier AI models must overcome constraints in context, agent design, data quality, energy, and open-source competition.","2026-06-25",[1007,1008,1009],"artificial intelligence","frontier models","AI safety","\u002Fblog\u002Fchallenges-facing-ai-frontier-models-part-two\u002Fcover.jpg","A humanoid robot ascending a snowy mountain ridge toward the sunset",{"_path":1013,"title":1014,"description":1015,"cardTitle":1016,"publishedAt":1017,"tags":1018,"coverImage":1020,"coverAlt":1021,"featured":6},"\u002Fblog\u002Funderstanding-your-true-attack-surface-part-one","Understanding Your True Attack Surface: Part One","The modern attack surface extends far beyond the corporate firewall.","Understanding Your True Attack Surface Part One","2026-06-21",[21,1019,23],"network security","\u002Fblog\u002Funderstanding-your-true-attack-surface-part-one\u002Fcover.jpg","Security leader reviewing an enterprise attack surface dashboard spanning cloud, applications, remote offices, devices, patching, identities, and internet exposure",{"_path":1023,"title":1024,"description":1025,"publishedAt":1026,"tags":1027,"coverImage":1028,"coverAlt":1029,"featured":6},"\u002Fblog\u002Fchallenges-facing-ai-frontier-models","Challenges Facing AI Frontier Models Part One","Frontier AI models face a series of challenges that threaten their viability","2026-06-12",[1007,1008,1009],"\u002Fblog\u002Fchallenges-facing-ai-frontier-models\u002Fcover.jpg","A humanoid robot standing among clouds beneath a blue sky",{"_path":1031,"title":1032,"description":1033,"cardTitle":1034,"publishedAt":1035,"tags":1036,"coverImage":1040,"coverAlt":1041,"featured":6},"\u002Fblog\u002Fexecutive-operational-security-opsec-part-one-setting-the-foundation","Executive Operational Security Part One: Setting the Foundation","Executive OPSEC protects senior leaders, privileged access, sensitive information, communications, travel, and personal activity from targeted threats.","Executive Operational Security Part One","2026-06-10",[1037,1038,1039],"executive security","OPSEC","risk management","\u002Fblog\u002Fexecutive-operational-security-opsec-part-one-setting-the-foundation\u002Fcover.jpg","Executive reviewing his phone beside a laptop in a private office",{"_path":1043,"title":1044,"description":1045,"publishedAt":1046,"tags":1047,"coverImage":1051,"coverAlt":1052,"featured":6},"\u002Fblog\u002Fevaluating-identity-before-attackers-do","Evaluating Identity Before Attackers Do","An IAM assessment evaluates authentication, access controls, user behavior, and identity resilience before attackers can exploit them.","2026-06-07",[1048,1049,1050],"identity security","IAM assessment","access management","\u002Fblog\u002Fevaluating-identity-before-attackers-do\u002Fcover.jpg","Open cyber vault displaying identity security controls and authentication monitoring",{"_path":1054,"title":1055,"description":1056,"publishedAt":1057,"tags":1058,"coverImage":1061,"coverAlt":1062,"featured":6},"\u002Fblog\u002Fthe-necessity-of-an-enterprise-risk-assessment","The Necessity of an Enterprise Risk Assessment","Effective Cybersecurity is both a Technical and Procedural Endeavor","2026-05-26",[1059,1039,1060],"enterprise risk assessment","cybersecurity governance","\u002Fblog\u002Fthe-necessity-of-an-enterprise-risk-assessment\u002Fcover.jpg","CISO in an aircraft cockpit overlooking clouds with technical and procedural cybersecurity displays",1785277054700]