Key Takeaways

  • Industry research found that 33% of monitored IT assets lacked at least one critical security control.
  • Remote-access services, unmanaged identities, cloud workloads, and third parties are widening enterprise exposure.
  • Effective attack surface management increasingly combines internal inventory, external discovery, and asset-level risk prioritization.

Enterprise attack surfaces are expanding faster than many security teams can inventory them, leaving gaps across remote-access systems, cloud workloads, SaaS connections, identities, legacy technology, and third-party services.

According to Arctic Wolf, its 2026 State of the Cybersecurity Attack Surface Report puts numbers around that visibility problem. Among monitored IT assets, 33% lacked at least one critical security control. Another 19% had reached end-of-life, while 17% were not visible to legacy vulnerability-management tools.

Those categories can overlap, but each represents a different operational problem. An asset without endpoint protection needs one response. An obsolete server that cannot be safely patched needs another. A system missing from the security team's inventory is more fundamental: defenders may not know it needs attention at all.

Attackers do not need a complete picture of an enterprise environment; they only need to find one useful opening.

Remote-access infrastructure illustrates the shift. The report found that remote-access services accounted for 65% of non-business-email-compromise incident-response cases in 2025, up from 24% three years earlier. These services often sit at the edge of the network, remain reachable from the internet, and provide a direct route into valuable systems. Weak credentials, outdated appliances, permissive configurations, and missing multifactor authentication can make them particularly attractive.

The pattern also aligns with Mandiant's 2025 M-Trends research. Exploits were the leading initial-access vector in 33% of investigated incidents, followed by stolen credentials at 16%. That combination matters because it connects two areas that organizations have often managed separately: vulnerability exposure and identity security.

A patched server can still be accessed with a compromised administrator account. Strong identity controls may not stop exploitation of an internet-facing device with a known vulnerability. Treating these as isolated workstreams can therefore hide the practical routes an attacker might assemble.

Attack surface management, or ASM, is evolving in response. External Attack Surface Management, commonly called EASM, looks for internet-facing domains, applications, cloud services, certificates, and infrastructure that an attacker could discover. Cyber Asset Attack Surface Management, or CAASM, pulls information from internal security and IT systems to create a broader asset inventory.

Neither approach solves the problem by itself. External discovery can identify an abandoned subdomain or exposed development environment, but it may lack business context. Internal aggregation can reveal ownership and control coverage, yet miss assets that were never entered into corporate systems. Used together, they can help teams compare what the organization believes it operates with what outsiders can actually see.

Demand is moving in that direction. The 2025 SANS Attack Surface Management Survey found that 55% of respondents wanted ASM to cover both internal and external assets. More strikingly, 89% expected risk quantification for every asset.

That expectation raises a harder question: what makes one exposed asset more urgent than another?

A useful answer goes beyond counting vulnerabilities. Security teams can consider internet accessibility, known exploitation activity, identity privileges, data sensitivity, business importance, control coverage, and the asset's relationship to other systems. A vulnerable test server with no sensitive data may be less pressing than a remote-access appliance connected to production, even if its technical severity score is lower.

Third parties complicate the calculation. Suppliers, managed service providers, SaaS applications, and software dependencies may introduce access paths that the customer does not directly administer. NIST SP 800-161 Rev. 1 treats supply-chain risk as an ongoing governance concern, while NIST SP 800-207 frames access around continuous verification rather than assumed trust based on network location.

For enterprises, the practical priority is not simply buying another discovery product. It is establishing ownership, connecting asset data across teams, and creating a process for retiring obsolete systems or applying compensating controls where replacement takes time. Products such as Arctic Wolf Aurora Exposure Management can support that work, but remediation still depends on coordination among security, infrastructure, procurement, application owners, and business leaders.

The attack surface will keep changing as companies add services and partners. The more realistic goal is a current, risk-ranked view that helps defenders notice consequential exposure before it becomes an attacker's easiest route in.