Skip to content
atlas

Don't confuse these

Attack surface vs Threat landscape

Why they differ

The attack surface is your own ways in; the threat landscape is who and what is out there trying them.

Attack surface

Application security

The sum of all the places where an outsider could try to get into a system, send data into it or pull data out.

Formal

The set of all points at which a system can be reached or acted on from outside its trust boundary - open ports, web pages and APIs, user accounts, stored data, the people who run it and the suppliers it depends on.

In plain English

Like counting every door, window, hatch and mail slot in a house - each one is a place a burglar could try, whether or not it is locked.

In practice

An IT operations manager at a water utility checks what it exposes to the internet and finds an old test website, a forgotten file server and three admin accounts nobody uses; shutting them down shrinks the attack surface.

Why it matters

Every extra way in is one more thing to watch and patch, and attackers need to find only the one that was missed; a smaller surface leaves fewer places for weaknesses to hide.

Threat landscape

Risk management

A picture of the kinds of threats a company could face right now, and who or what is behind them.

Formal

The current picture of which threats are active against an organisation, its sector or country, including the likely attackers, their methods and how these are changing.

In plain English

Like a weather forecast for danger, telling you whether to expect rain, storms or a heat wave in the weeks ahead.

In practice

Before the yearly risk review, the IT lead at a small manufacturer reads the latest threat assessment from the Danish Resilience Agency (SAMSIK) and brings the threats it rates highest into the review.

Why it matters

Risks can only be judged against the threats that actually exist, so an outdated picture leads to protecting against yesterday's attacks.

Atlas is in beta.