Definition · External Attack Surface Management
What is Attack Surface Reduction?
Attack surface reduction is the deliberate shrinking of an attack surface: fewer exposed services, fewer reachable interfaces, fewer accounts and fewer paths in. It differs from vulnerability remediation in what it targets. Remediation fixes a known flaw in something you have decided to keep; reduction questions whether the thing needs to be reachable at all. A service that is not exposed cannot be exploited by a zero-day you have not heard of yet.
What reduction looks like externally
- Closing TCP ports that no longer serve a purpose, and restricting the rest by source address
- Moving management access — RDP, SSH, admin panels — behind a gateway or allowlist instead of the open internet
- Decommissioning dead hosts and retiring the subdomains that pointed at them, which also removes dangling DNS records and the risk of subdomain takeover
- Turning off features that were never used: directory listing, unused HTTP methods, debug endpoints, GraphQL introspection in production
- Consolidating duplicated services so one hardened instance replaces several partially maintained ones
The term also has a vendor-specific meaning: Microsoft Defender uses “attack surface reduction rules” for a particular set of endpoint hardening policies. That is a narrower, endpoint-focused use of the same principle.
Why it is the cheaper control
Every exposed service carries ongoing cost — patching, monitoring, certificate renewal, configuration review — and that cost recurs indefinitely. Removing the service removes the cost and the risk permanently. The obstacle is almost never technical; it is not knowing what is exposed or who depends on it, which is why asset discovery has to come first.
Related concepts
Reduction pairs with defence in depth for what remains, and with least privilege and network segmentation for limiting what a compromise reaches. It is the practical goal of external attack surface management.