Ten years ago, we could draw our attack surface on a whiteboard. Firewall here. Servers there. Laptops inside. It was a castle with a moat.
That castle doesn’t exist anymore.
Today your attack surface is everywhere your data goes, which is everywhere.
And the numbers prove it.
In Q2 2025, organisations faced an average of 1,984 cyberattacks per week, a 21% increase year-over-year and 58% higher than two years ago.
In Q1 2025, it was even more dramatic: 1,925 attacks per week, a 47% surge compared to the same period in 2024.
The World Economic Forum found that 72% of cybersecurity leaders reported a rise in organisational risk over the past year.
This isn’t just more of the same attacks. It’s a fundamentally larger area to defend.
From Perimeter to Everywhere
The classic term “attack surface” used to mean open ports and unpatched servers.
Now it means any digital asset where an attacker can try to get in, get data out, or disrupt you.
That includes:
• Every SaaS app your marketing team signed up for with a credit card
• Every API your developers exposed
• Every smart thermostat in your Athens office, every container in the cloud, every contractor’s personal iPad
• Every piece of data your employees pasted into a GenAI tool
We didn’t just expand the office.
We demolished the walls.
The Five Engines Driving the Expansion
I) Cloud Sprawl and Shadow IT
Multi-cloud was supposed to be strategic. In practice, it’s sprawl. One company runs production on AWS, analytics on Azure, and has three old GCP projects no one owns but are still billing. Each misconfigured S3 bucket, each overly permissive IAM role, is a door. Add shadow IT, the average enterprise now uses 300+ SaaS apps, 70% of which IT has never approved, and you have thousands of identities and data stores outside central visibility.
II) The IoT and OT Explosion
We went from 15 billion connected devices in 2020 to over 35 billion expected in 2026. Sensors, cameras, industrial PLCs, smart building systems, medical infusion pumps. Most were built for uptime, not security. They can’t be patched easily, they ship with default passwords, and they live on the same network as your crown jewels. Attackers know this. OT is now a bridge to IT.
III) The Remote Work Forever Effect
The pandemic ended, but hybrid didn’t. Your user is now a roaming perimeter. Home Wi-Fi with a vulnerable router, a coffee shop, a co-working space. The VPN is replaced by identity, and identity is under siege. Phishing, infostealer malware, session hijacking. When 48% of businesses report more frequent insider-driven incidents, it’s often not malice, but a legitimate user whose identity was compromised and is now operating from outside.
IV) The Supply Chain Domino
You are only as secure as the least secure vendor in your stack. The MOVEit, SolarWinds, and 2024-2025 wave of library hijacks taught us that. Cybersecurity Ventures predicts supply chain attacks will cost $138 billion globally by 2031, up from $60 billion in 2025. One compromised open-source package, one managed service provider, and the attacker gets 1,000 victims for the price of one. The vulnerability data shows the pressure: in 2024 there were about 113 new CVEs published daily, and in the first half of 2025 that number increased again. Over 30,000 new vulnerabilities were identified in 2024 alone, a 17% year-over-year increase. No team can patch everything, and attackers need just one.
V) Generative AI: The Ultimate Amplifier
GenAI is both a new target and a new weapon. On the target side: employees pasting source code, contracts, and customer data into public LLMs, creating massive data leakage risks. Check Point noted in late 2025 that expanded attack surfaces and growing exposure risks from GenAI tools are driving the steady escalation in attacks.
On the weapon side: phishing emails with perfect grammar, deepfake CFOs on video calls, and malware that rewrites itself to evade detection. Ransomware groups are weaponizing vulnerabilities within hours now, CVE-2025-55182, dubbed React2Shell, was exploited by state-linked groups within hours of disclosure.
The Cost Has Changed Too
It’s not just about more alerts. The nature of the payoff has changed. Ransomware is no longer just about encryption. In the first half of 2025, 40% of large cyber claims over €1M included data exfiltration, up from 25% in 2024.
It’s double extortion: pay to decrypt, and pay again not to leak.
And ransomware volume is accelerating. Cases are on track to increase 40% by end of 2026 compared to 2024, and 400% compared to 2020. One forecast puts us at one ransomware attack every 2 seconds by 2031.
Attackers are also getting faster.
In 2024, 0.91% of all CVEs were weaponized, a 10% increase year-over-year, the window between disclosure and exploitation is shrinking to hours.
So, How Do You Defend an Infinite Frontier?
You can’t shrink back to the castle. But you can make the frontier manageable.
α) Know what you have.
Continuously. You can’t protect what you can’t see.
Move from annual asset inventories to continuous attack surface management (ASM). External ASM tools that scan like an attacker, finding forgotten domains, exposed dev buckets, leaked credentials, are now table stakes.
β) From vulnerabilities to exploitability.
With 100+ CVEs a day, patching everything is fantasy.
Prioritize by exploitability
Is it in the KEV catalogue?
Is there active chatter?
Is it internet-facing and does it hold sensitive data?
Try fix those first.
γ) Identity is the new perimeter.
Treat it like one. Enforce phishing-resistant MFA everywhere, short-lived credentials, zero standing privileges. Assume breach of identity and monitor for impossible travel, token replay, and session hijacking.
δ) Shrink the blast radius.
Zero Trust isn’t a product, it’s architecture: micro-segment IoT/OT from IT, micro-segment cloud workloads, and assume your SaaS vendor will be breached.
Encrypt data, enforce least privilege, and have immutable backups.
ε) Manage your third parties like first parties.
Require SBOMs (Software Bill of Materials), monitor your critical vendors’ attack surface as if it were your own, and have an off-switch.
In Conclusion
The increase in attack surface is not a temporary spike. It is the structural result of digital transformation, hyper-connectivity, and AI adoption. Every new efficiency we gain, an API, a sensor, a chatbot, is a new potential entry point.
The good news?
Attackers are still constrained by economics. They go for the easiest, most exposed, most valuable target. In a world where everyone’s surface is growing, the organisation that makes its frontier smaller, clearer, and harder to cross wins.
Your attack surface will keep growing in 2026, this inevitable.
The question is whether your visibility & control will grow faster.
