(This page has no text content)
Praise for Attack Surface Management In today’s cybersecurity landscape, professionals are inundated with guidance and recommendations but receive very little in the way of practical advice that can be executed to minimize risk and defend against threats. Attack Surface Management provides a pragmatic and practical approach to identifying, classifying, and protecting an organization’s most critical assets in a way that aligns with and augments published best practices and risk management frameworks. This is an ideal methodology for transitioning from “checking the boxes” to implementing security practices that actually provide value. —Jeremy Faircloth, Sr., CyberSecurity Consultant/Architect
Everyone who deals with security learns that it’s a Sisyphean task: every day we work to make our systems stronger and safer, but every day there are new challenges that undermine our efforts. Attack Surface Management provides a framework for reevaluating the landscape so that anyone with a job that involves information security, which seems to be all of us these days, can approach the work in a sustainable and effective way. I’ve already put ideas from this book into practice with my own work, and I look forward to seeing this approach to cybersecurity spread more widely in the future. —Chris Devers, Technical Lead of Sustaining Engineering, EditShare
Attack surface management is a term often heard but rarely comprehensively explained to people new to the subject. Ron and MJ have done an incredible job of building foundational knowledge of ASM, and they progress readers to a level of understanding that allows them to leverage the knowledge in the field. I wish I had this book ten years ago; it would have saved me an incredible amount of time and effort. —Dane Grace, Sr., Cybersecurity Product Manager You can’t protect what you don’t know about. This book delivers a practical framework to help you identify and understand your attack surface. A must-read for those serious about understanding how to minimize and protect their exposed edge. —Steve Winterfeld, Advisory CISO, Cyber Vigilance Advice
Attack Surface Management Strategies and Techniques for Safeguarding Your Digital Assets Ron Eddings and MJ Kaufmann
Attack Surface Management by Ron Eddings and MJ Kaufmann Copyright © 2025 Ronald Eddings, Melody Ann Jones “MJ” Kaufmann. All rights reserved. Printed in the United States of America. Published by O’Reilly Media, Inc., 1005 Gravenstein Highway North, Sebastopol, CA 95472. O’Reilly books may be purchased for educational, business, or sales promotional use. Online editions are also available for most titles (http://oreilly.com). For more information, contact our corporate/institutional sales department: 800-998-9938 or corporate@oreilly.com. Acquisitions Editor: Simina Calin Development Editor: Jill Leonard Production Editor: Beth Kelly Copyeditor: J.M. Olejarz Proofreader: Dwight Ramsey Indexer: BIM Creatives, LLC
Interior Designer: David Futato Cover Designer: Karen Montgomery Illustrator: Kate Dullea May 2025: First Edition Revision History for the First Edition 2025-05-19: First Release See http://oreilly.com/catalog/errata.csp?isbn=9781098165086 for release details. The O’Reilly logo is a registered trademark of O’Reilly Media, Inc. Attack Surface Management, the cover image, and related trade dress are trademarks of O’Reilly Media, Inc. The views expressed in this work are those of the authors and do not represent the publisher’s views. While the publisher and the authors have used good faith efforts to ensure that the information and instructions contained in this work are accurate, the publisher and the authors disclaim all responsibility for errors or omissions, including without limitation responsibility for damages resulting from the use of
or reliance on this work. Use of the information and instructions contained in this work is at your own risk. If any code samples or other technology this work contains or describes is subject to open source licenses or the intellectual property rights of others, it is your responsibility to ensure that your use thereof complies with such licenses and/or rights. 978-1-098-16508-6 [LSI]
Preface Cybersecurity is a never-ending race—one where the finish line keeps moving. Every time we think we’ve secured our systems, attackers find new ways in. Every innovation, convenience, cloud service, or connected device we adopt opens up new opportunities—not just for businesses but also for adversaries. This is where attack surface management (ASM) comes in. ASM isn’t just another security buzzword; it’s a fundamental shift in how organizations approach cybersecurity. In a world where digital transformation is happening at breakneck speed, the old ways of securing networks and endpoints are no longer enough. Our attack surfaces have evolved from a handful of well-defined servers and firewalls to a sprawling, interconnected ecosystem of cloud environments, third-party SaaS applications, APIs, IoT devices, remote workforces, and supply chain dependencies. The modern attack surface is vast, fragmented, and constantly changing. Everything that it encompasses is a prime target for cybercriminals looking for gaps in our defenses. But the challenge isn’t just about scale—it’s about visibility. Security teams are drowning in alerts and vulnerabilities,
trying to protect assets that in some cases they don’t even know exist. ASM provides the strategic framework to cut through the noise, helping organizations discover, analyze, and manage their exposure before attackers can exploit it. By understanding and actively managing your attack surface, you’re not just reacting to threats but anticipating them. You’re reducing risk before it becomes an incident, securing what you know and what you didn’t realize was exposed. This book is about taking control—helping security professionals, IT teams, and business leaders confidently navigate the ever-expanding digital frontier. The game has changed. ASM is how we stay ahead. Who Should Read This Book Cybersecurity is no longer confined to a single department or a specialized team locked away in a security operations center. The responsibility of securing an organization’s assets is now shared across IT, security, DevOps, compliance, and even business leadership. If you’re reading this, chances are you play a role in protecting your organization’s digital footprint— whether you realize it or not.
This book is for security professionals—CISOs, security engineers, SOC analysts, and AppSec teams who are constantly fighting to reduce risk, respond to threats, and improve security posture across an increasingly complex digital environment. If your job involves monitoring security alerts, managing vulnerabilities, investigating breaches, or designing security policies, this book will give you the tools to approach ASM in a structured, proactive way. It’s also for IT administrators who manage infrastructure, endpoints, and cloud environments. You’re responsible for keeping systems running smoothly, ensuring they are secure, and managing configurations. However, with shadow IT, third- party SaaS applications, and evolving cloud services, staying ahead of security gaps can feel impossible. ASM provides a framework for visibility, automation, and control—helping IT teams eliminate blind spots before they turn into security incidents. DevOps teams will also find this book invaluable. Modern application development moves too fast for traditional security models to keep up. Continuous integration and continuous deployment (CI/CD) pipelines, containerized applications, and API-driven architectures have expanded attack surfaces in ways most security teams struggle to manage. This book will
help DevOps teams embed security into their workflows, ensuring that security is not an afterthought but an integrated part of software development. For compliance officers and risk managers, ASM provides a way to map security efforts to regulatory frameworks such as GDPR, HIPAA, PCI DSS, and NIST. Understanding where sensitive data lives, who has access to it, and what external dependencies exist is crucial for maintaining compliance. This book will help compliance professionals work alongside security and IT teams to operationalize security controls and maintain regulatory alignment. Finally, this book is for anyone involved in cybersecurity strategy—business leaders, product managers, and technology decision-makers who need a clear understanding of attack surfaces, digital risk, and security investments. ASM is not just a technical challenge; it’s a business imperative. Leaders who understand the importance of ASM can drive smarter security investments, improve incident response, and align security efforts with business objectives.
What You Need to Know This book assumes a basic understanding of security principles, network architecture, and risk management concepts. You’ll find it easy to follow along if you’re familiar with common security frameworks, basic networking, and how applications interact in cloud environments. However, we’ve structured this book to be practical, accessible, and actionable, ensuring that even those new to ASM can grasp and apply the key concepts effectively. Regardless of your role, one thing is certain: the attack surface is growing, and managing it is no longer optional. Whether you’re securing infrastructure, developing software, monitoring threats, or ensuring compliance, this book will help you turn ASM from a reactive burden into a proactive advantage. Why We Wrote This Book Every cybersecurity professional knows that securing an organization is a constant battle. Attackers innovate as fast—if not faster—than defenders, and keeping up feels like running on a treadmill set to full speed. As digital transformation accelerates, organizations are expanding their IT environments
across cloud platforms, SaaS applications, APIs, and mobile devices—yet many struggle to answer a fundamental question: What, exactly, are we trying to protect? This is the challenge of ASM. Organizations know they need it, and security teams understand the risks of unmanaged, unknown, or misconfigured assets. Yet, when faced with the question of “Where do we even begin?” most don’t have an answer. That’s why we wrote this book. What You’ll Learn Despite the increasing importance of ASM, there isn’t a go-to resource that security teams can turn to for practical guidance. Some organizations think they’re doing ASM, but they’re just running vulnerability scans or cataloging assets without a true strategy. Others know they need ASM but get overwhelmed by the complexity and don’t know how to start. This book is meant to fill that gap—to provide both the high-level strategy and the day-to-day tactics that make ASM actionable. The book offers: Real-world use cases and industry best practices
ASM is more than just theory. Throughout this book, you’ll find examples of how organizations manage their attack surfaces, what works, and what doesn’t. A balance of strategic and tactical guidance This book provides a clear, structured road map for implementing ASM, whether you’re starting from scratch or looking to improve an existing program. A framework for integrating ASM into security operations ASM isn’t just a security tool or a one-time project—it’s a process that must be embedded into incident response, vulnerability management, DevOps, and compliance efforts. This book shows you how. The goal of the book is to help security teams make the shift from reacting to threats to getting ahead of them. By the time you finish reading, you’ll have a clear understanding of ASM, a practical framework for implementation, and the confidence to take control of your attack surface—before attackers do. Navigating This Book ASM is a journey, not a single destination. It requires a strategic foundation, practical execution, and continuous adaptation to
keep pace with evolving threats. This book is structured to take you through that journey step by step, from understanding what an attack surface is to implementing a scalable, proactive ASM program. We’ve divided the book into four key parts, each focusing on a critical phase of ASM. Whether you’re new to the concept or refining an existing approach, you can follow along in sequence or jump to the sections that align with your immediate needs. Part I: Foundations of ASM Before you can manage your attack surface, you need to understand what it is and why it matters. This section establishes the core concepts of ASM, setting the stage for everything that follows. Chapter 1 lays the groundwork, defining attack surface management and explaining how the digital landscape has changed, why traditional security approaches no longer suffice, and why ASM has become essential for modern cybersecurity. Chapter 2 explores the different types of attack surfaces, from traditional IT assets to cloud environments, SaaS applications, APIs, IoT, and third-party dependencies. Understanding the scope of exposure is the first step in securing it.
Chapter 3 connects ASM to risk management, outlining how organizations should prioritize threats based on real-world impact rather than blindly chasing every vulnerability. By the end of Part I, you’ll have a strong strategic understanding of ASM and why it must be an integral part of security operations. Part II: Identification and Classification Once you understand the scope of your attack surface, the next step is to find and classify everything that needs protection. This part focuses on visibility—because you can’t protect what you don’t know exists. Chapter 4 covers asset discovery—how organizations identify all their digital assets, whether in on-premises infrastructure, the cloud, or shadow IT. Chapter 5 dives into automation and classification, showing how organizations can move beyond manual asset inventories to scalable, real-time attack surface monitoring. By the end of Part II, you’ll know how to map your attack surface comprehensively and categorize assets based on risk, business impact, and exposure.
Part III: Prioritization and Remediation Discovery is just the beginning—not every asset carries the same level of risk. Part III focuses on prioritizing vulnerabilities and exposures so that organizations can focus resources where they matter most. Chapter 6 introduces prioritization frameworks, including crown jewel analysis and business context mapping. Instead of treating every vulnerability equally, organizations must focus on what attackers are most likely to target. Chapter 7 provides methods for measuring attack surface exposure, showing how security teams can quantify and track changes over time. Chapter 8 covers remediation strategies, from proactive risk reduction to reactive incident response. It also explains how to validate remediation efforts to ensure security fixes are effective. By the end of Part III, you’ll have a systematic approach to reducing risk efficiently—without getting lost in alert fatigue or low-priority issues.
Part IV: Adapting and Monitoring Attack surfaces aren’t static. They expand, contract, and evolve as organizations grow, adopt new technologies, and integrate third-party services. Part IV focuses on long-term attack surface management—how to continuously monitor, adapt, and improve security posture. Chapter 9 examines strategies for minimizing the attack surface —how organizations can design their environments to reduce unnecessary exposure and limit attacker opportunities. Chapter 10 explores continuous monitoring, automation, and AI-driven security strategies. It explains how organizations can set alert thresholds, integrate ASM with incident response, and automate security operations to keep up with ever-changing threats. By the end of Part IV, you’ll understand how to sustain an ASM program over time, making it an ongoing part of security operations rather than a one-time effort. Looking Ahead Cybersecurity never stands still, and neither does ASM. Chapter 11 looks toward the future of attack surface
management—how emerging technologies like AI, automation, and predictive analytics will shape the next evolution of ASM. It also explores how security teams can stay ahead of evolving attacker tactics. How to Use This Book This book is designed to be a structured guide and a practical reference. If you’re new to ASM, we recommend reading Parts I and II first to build a strong foundation before diving into the technical details. If you’re already familiar with ASM and need help operationalizing it, you might find Parts III and IV most useful. No matter where you start, one thing is certain: the attack surface is always growing, shifting, and under threat. By implementing the principles in this book, you can take control of your organization’s exposure, reduce risk, and stay ahead of attackers—today and in the future. Conventions Used in This Book The following typographical conventions are used in this book: Italic
Loading comments...
Reply to Comment
Edit Comment