The Art of Attack Surface Defense
Key Takeaways
- Manual attack surface discovery is time-consuming and incomplete—many organizations spend over 80 hours just identifying assets, often missing up to 20% of their exposure.
- Automated tools like Recorded Future’s Attack Surface Intelligence streamline visibility and help prioritize risks based on threat relevance and business context.
- Effective attack surface defense requires more than visibility—it demands clear workflows, risk reduction strategies, and alignment with business objectives.
How to Defend Your Attack Surface
In today’s digital-first world, organizations are rapidly expanding their online footprint—spinning up cloud instances, deploying web apps, and enabling remote access across global teams. While this digital transformation fuels innovation and growth, it also introduces a complex and constantly shifting attack surface—the totality of internet-facing assets that could be exploited by cyber attackers.
Managing your attack surface is the practice of continuously identifying, monitoring, and reducing exposure to these potential entry points. Without full visibility into what assets exist (and where), security teams risk missing critical vulnerabilities—especially as assets appear, change, or disappear faster than traditional inventory systems can track. Modern attack surface defense strategies go beyond manual scanning and static asset lists. They require dynamic, automated tools that integrate with cyber threat intelligence to help prioritize what truly matters—like exposed admin panels, misconfigured cloud environments, and assets targeted by active threat actors.
In the following interview, Matt Bittick, Head of the Attack Surface Risk Management program at Cummins, shares how his team transitioned from labor-intensive asset discovery to a scalable, intelligence-driven approach using Recorded Future. He explains why visibility is only the beginning, and how effective attack surface management helps reduce real-world risk in measurable ways.
あらゆる業種や組織にわたるデジタルトランスフォーメーションの取り組みにより、インターネットに接続する資産の複雑さと量が増加しています。こうした変化を受け、セキュリティチームには、目に見えない、あるいは存在すら知らない資産を中心にプロセスをどう構築すべきかという疑問が生じます。
Cumminsのアタックサーフェスリスク管理プログラムの責任者であるMatt Bittick氏との対談で、拡大するデジタル攻撃対象領域を保護するための戦略と方法論、そしてRecorded Futureを活用することが優先順位付けとリスク軽減にどう役立つかについて話し合いました。
(Recorded Future)Recorded Futureを使用する前は攻撃対象領域をどのように保護されていましたか?
(Matt)かなり苦労していました。オープンソースツールを使用するのがある意味最も簡単な方法ですね。当社では、インベントリ管理システムで企業が知っていることすべてを引き出そうと努めています。実のところ大した情報は得られないのですが、そこから作業を進めていきます。Nmap、Kali Linux、組み込みツールも多数ありますが、偵察して、どんなインベントリであるかを把握し、すべてを見つけようとします。非常に労働集約的でした。
多くの組織では、攻撃対象領域の検出に80時間以上かかると言います。実感としてはいかがですか?
本当にそうですね。当社でも平均で約80時間を費やしていることがわかりました。諜報機関の古い格言で、諜報活動はタイムリーでも実用的でもない場合には、それは単なるニュースに過ぎず、しかも古くなったニュースだというのがありますが、まさにそれで、攻撃対象領域のような動的な空間で何かを見つけるために長い時間を費やすのは理想的ではありません。
Enjoying what you’re reading so far? Watch the full fireside chat video!
After implementing Recorded Future Attack Surface Intelligence, how has that helped improve your visibility and efficiency?
大幅に改善しました。効率性の部分と、インベントリとマッピングのためだけに投入される労力についての話がありましたが、これは非常に重要なことだと思います。導入後はそうした労力が不要になり、今では朝出社するとすべて準備が整っています。攻撃対象領域の調査は完了しているので、把握もできており、すぐに業務に入れます。アセットを見つけるためだけにコマンドラインインターフェイスで一日中作業する必要はありません。
手作業で行っていた頃と比べると大きな違いが1つあり、今では組織を偵察する能力にかなり自信を持っていますが、それでも攻撃対象領域の約20%のデルタが特定の日に見つからなかったことがわかりました。
これには複数の理由がありますが、外部の組織を悪用してサイバー犯罪を行うことのプロは、私よりも上手なのだろうと確信しています。 したがって、できる限り最高のイメージを作りたいと考えており、それが製品から得られる価値として非常に大きいと考えています。
アタックサーフェスリスク管理プログラムを成功させるには何が必要ですか?
You know it's a really great question, and I think visibility, asset inventory, and the mapping is the start of your journey. We believe that you need workflows, you need processes, and you need ways of handling that. So to be successful, you need to not only know what your problems are, but also how to deal with them.
こうした攻撃対象領域の問題を検討する際、主に次の2つの問題が挙げられます。
- デジタルアタックサーフェス(攻撃対象領域)とは何か?
- それをどのように保護すべきか?
また、修復か低減かを問わず、実行できるアクションにもいくつかあります。私たちが好きなのは削減で、インターネット上にあるべきでないものは、絶対にオフラインにすべきです。
デジタル攻撃対象領域を保護することの重要性と、その保護においてRecorded Futureが果たす役割について、どのように説明されますか?
I think there's kind of a three-pronged approach when you're showing the importance of an attack surface program to your CISO. First, I always try to paint a picture for the CISO. The organization is their castle, right? And they're sitting there defending it. I think the best way to even pitch the idea of attack surface to a CISO is to show what it is and come prepared with the measurement of this is how much of your castle is just open. Is there a big old hole in the wall? If 50% of the castle's penetrable or just has an open door, there's not much point to the castle.
2番目に、そうした状況に対してどのように行動を起こすか、構築しようとしているプロセスとその実行方法を示します。本来の攻撃対象領域を示すだけでなく、ソリューション自体がもたらす価値の面でも、Recorded Futureが役に立つと思います。個人的に本当に重要だと思うのは、Recorded Future Attack Surface Intelligenceが統合されているだけでなく、サイバー脅威インテリジェンスプラットフォームの一部であるため、リスク評価を次のレベルに引き上げることができるということです。
CVSSスコアではどちらも重大な可能性のある2つの異なる脆弱性を調べている場合、どちらがより重要かをどう判断すればよいでしょうか。おそらく、自社組織や業界に興味を持っているAPTがTTPの一部であったり、 脅威の状況で積極的に使用されているものの方でしょう。まずはそれを追いかけるべきです。リソースに制約のある環境で、優先順位を積み重ねる必要があることを示すことができれば、それが鍵だと思います。聴衆の皆さんの中に十分なリソースがあると感じておられる方はいないはずですから。
3番目に、それが組織にもたらす価値を示します。これらのプロセスをオンラインにするときに、攻撃対象領域をマッピングし、それを測定し、その規模を把握し、その中に存在する問題を測定すれば、全体的な攻撃対象領域の縮小のもつ価値を提示することができます。私の役割の本質がリスク低減にある理由はそこにあります。攻撃対象領域は拡大していても、リスクプロファイルは縮小している可能性があることを示しているからです。そして、まさにここで、攻撃対象領域ツールと攻撃対象領域プログラムの価値が現れ始めます。
この3点を1回のプレゼンテーションですべて示す必要はないと思います。それは時間とともに進化します。当社にとっては確実にそうでした。当社に入社したときの課題は、「攻撃対象領域があるんだけどそれが何なのかは分からず、どうしたらいいのかもわからない」というものでしたから。こうした点に到達するまでにはかなりの努力が必要でした。そして、CISOとの接点を維持し、リスクが何であるか、何もしなければ何が起こりうるかを理解してもらえる限り、そのリスクを低減することはできると思います。
公開された管理パネルが攻撃対象領域に大きなリスクをもたらすのはなぜでしょうか?
管理パネルが公開されているというのは興味深い状況ですが、管理パネルとは、そのソフトウェアプラットフォームへの直接のインターフェースになるわけですよね。さまざまな種類のApache、Drupal、場合によってはファイアウォールの管理パネルが表示されることがあります。これが問題となる理由は、構成が購入時からまったく変更されていない可能性が常にあるからです。デフォルトの認証情報がそのままになっているとしたら、ファイアウォールを導入する意味はありません。これは常に重要なリスクですが、プロセスがもっと成熟していて、誰かがヘマをしていない場合であっても、問題は起こるものです。時には、どんなに熟練した人でも間違いを犯すことがあります。その日はたまたま眠気に勝てなかったのかもしれません。
さらに、ブルートフォースの危険もあります。そもそも外部に見せる必要のないものをオープンにする理由はないはずです。VPNがあり、リモート管理もあります。最近では、これらのログインをブルートフォース攻撃に利用する代わりに、自宅から内部環境に入り、管理パネルを操作することができます。これは大きな問題ですが、「ちょっとこのパネルを中へ移動させましょう」と一言言うだけで軽減できるリスクです。
攻撃対象領域をうまく保護するとは、どのようなことでしょうか?これで最終形態と呼べるような状態はありますか?
それは、当社がこの問題を検討し始めた際に、当社CISOから最初に尋ねられた質問ですね。答えは、攻撃対象領域があまりにも動的であるため、最終状態として目標にはできないというものです。 個人的には、経営陣が許容できるレベルに到達するには目標が必要だと考えています。リスク領域では、リスクがゼロになることはなく、常にリスクは残ります。そして、たとえゼロになったとしても、状況は常に変化し続けます。
残念ながら、いや、世界にとっては幸運なことですが、クラウドが存在します。クラウドは素晴らしいビジネスツールですが、ご存知のとおり、オンとオフを繰り返すものです。状況は極めて動的で頻繁に変化するため、クラウドでは攻撃対象領域が非常に急速に拡大する柔軟性があります。この点が非常に重要です。したがって、最終状態に到達するとしても、ゴールポストは決して静止したままにはなりません。常に次のものを追いかけてリスクの波を抑えていくことになりますが、サイバーセキュリティ組織とビジネスの両方が許容できる範囲内でリスクを抑えることは可能だと信じています。
よくある質問
What is attack surface defense, and why is it important?
Attack surface defense refers to the ongoing process of identifying, monitoring, and minimizing an organization’s exposed digital assets. It's essential because unknown or unmanaged assets—like exposed admin panels or forgotten cloud instances—can be prime targets for cyberattacks.
How does attack surface management differ from traditional vulnerability management?
While traditional vulnerability management focuses on patching known issues in documented systems, attack surface management continuously discovers internet-facing assets—including those not in inventory—and prioritizes risks based on real-time threat intelligence.
What are common challenges in securing a digital attack surface?
Common challenges include shadow IT, dynamic cloud environments, lack of visibility, outdated inventory systems, and resource constraints. These factors can lead to missed vulnerabilities and slow incident response.
How does Recorded Future support attack surface defense?
Recorded Future’s Attack Surface Intelligence automates asset discovery, enriches findings with threat intelligence, and helps security teams prioritize risks that matter most—based on threat actor activity, CVSS scores, and real-world exploitability.
Cumminsで同氏とチームが組織の攻撃対象領域を保護している方法を詳しく知りたいですか?