Attack surface reduction removes paths instead of adding alerts
Turning something off is worth more than watching it closely.
Every service removed, port closed and account deleted is a path that no longer needs monitoring, patching or defending. The industry's instinct is to add detection, because that is what gets sold, and reduction is the cheaper and more permanent answer where it is available. Nothing you have removed can be exploited.
More on Attack surface management
- The Internet sees what you expose, not what your CMDB remembersCounted three. Answering six
- A new subdomain can create a new perimeterThe fence just got longer
- Shadow IT becomes shadow attack surfaceDoors around the back
- Acquisitions merge attack surfaces before inventoriesThe wire arrives first
- Internet exposure is a property that changesThe tide does not read your map
- A forgotten test system can be a production entry pointThe shed is still joined to the house
