The terms attack vector and attack surface are often used interchangeably. But there are very clear differences between both terms. Understanding those differences can help your organization maintain a strong security posture. In this blog, we explore attack vectors vs. the attack surface and recommend strategies to account for both in your cybersecurity program.
The Difference Between Attack Vectors & Attack Surface
An attack vector is a method that a hacker uses to penetrate an attack surface. An attack vector takes many forms, including ransomware, compromised credentials, phishing, and malware.
An attack surface is the sum of organizational assets that a hacker can exploit to gain entry to a system or network. For many companies, the attack surface can be vast and includes physical, digital, and human assets.
Different Types of Attack Vectors
Now, let’s look at common attack vectors that can be used to breach your attack surface and how to defend against them.
Malware
Malware is a term for any form of software, including ransomware or a Trojan horse, that looks like a legitimate file but executes malicious code when the user opens or downloads it.
Ransomware
Ransomware is a form of malware that encrypts data on a victim’s computer and blocks the owner from accessing it in exchange for a ransom. Once payment is received, access to the data is restored.
Bitsight research suggests that poor security hygiene and the presence of vulnerabilities increase the likelihood of ransomware attacks. Learn more about the report’s findings and how you can lower the odds of being the next ransomware victim in our blog.
Misconfigured Systems
The misconfiguration of systems, particularly in the cloud, is a leading cause of data breaches and data loss. The massive Capital One data breach, for example, was the result of a misconfigured web application firewall.
There is also a direct correlation between misconfigured systems and ransomware attacks. For instance, Bitsight analysis found that organizations with a C grade or lower in TLS/SSL configurations are nearly four times more likely to be ransomware victims.
Unpatched Systems
New vulnerabilities arise every day and if you don’t monitor for unpatched systems or apply a patch expeditiously, hackers will easily exploit them. Indeed, Bitsight’s researchers found that organizations with a patching cadence of D or F were more than seven times more likely to experience a ransomware event compared to those with an A grade.
Compromised Credentials
Compromised usernames and passwords are widely available on the dark web and can give hackers unprecedented access to your network. Consider investing in tools that monitor for exposed credentials resulting from publicly disclosed breaches so that you can act quickly.
Phishing
Phishing is a form of social engineering that occurs when a bad actor impersonates a legitimate person or organization—typically via email—and asks the recipient to take an action that would give the phisher access to critical data or systems.