Attack Surface Reduction (ASR)
1-minute read
What it is
Attack Surface Reduction (ASR) is the practice of removing or minimizing exposed entry points attackers can use across endpoints, cloud services, web apps, identities, and network services. This includes reducing open ports, disabling unnecessary services, tightening configurations, limiting permissions, and removing unused assets.
Why it matters
Most breaches start with easy wins like exposed admin panels, forgotten subdomains, weak configurations, and unpatched services. ASR reduces the number of doors attackers can try, lowering the likelihood of compromise and making security monitoring more effective.
How to reduce risk
- Maintain an asset inventory that includes external-facing systems and subdomains.
- Remove unused services, close unnecessary ports, and enforce secure defaults.
- Apply hardening baselines and continuous patching.
- Implement least privilege and reduce standing admin access.
- Continuously monitor for new exposures such as new subdomains, misconfigurations, or leaked credentials.
Related terms
- Attack Surface
- Attack Surface Discovery
- Network Exposure Mapping
- Hardening Baselines
- Vulnerability Scanning