In this episode of The Security Strategist podcast, host Richard Stiennon, industry analyst and author, speaks to Craig Roberts, Principal Software Engineer at Rapid7, about digital exposure and the increasing challenges of Attack Surface Management (ASM).
The conversation peels back the layers of hidden vulnerabilities and misconfigurations that plague today’s digital world. The speakers offer expert advice into how businesses can better understand, prioritise, and manage their expanding attack surfaces.
Attack Surface Goes Beyond External Scans
Also the Co-founder of Noetic (acquired by Rapid7), Roberts’ journey into attack surface management began from a practical observation. He found that many cybersecurity incidents came from overlooked assets. Such incidents could be unmonitored servers or lack of Endpoint Detection and Response (EDR).
Emphasising the diverse nature of attack vectors, Roberts adds that a single misstep or vulnerability across any of these areas can allow an attacker to achieve their objective.
Holistic Exposure Management
Looking ahead, Roberts recommends CISO’s to focus on having all enterprise data and understanding their environment across all assets. These assets are – cloud, users, and traditional infrastructure.