HWS Logo

Attack Surface Management: Why SMEs Need to Know What Attackers Know About Them

The BSI published the findings in black and white in 2025: Around 80 percent of ransomware attacks in Germany target small and medium-sized enterprises. The reason is not a lack of malicious intent on the part of the attackers—but pragmatism. Attackers seek the path of least resistance. And that usually leads straight through systems that no one had on their radar anymore.

This is precisely where the real problem lies: not a lack of security technology, but a lack of visibility. If you don’t know what you’re exposing to the outside world, you can’t protect it. Attack Surface Management—ASM for short—addresses exactly this gap. What it entails, why it is no longer a niche topic for small and medium-sized businesses today, and what concrete steps can be taken.

What is a company’s attack surface?

An organization’s attack surface is the sum of all exposed IT resources, regardless of whether they are secure or vulnerable, known or unknown, or actively used or not. (Source: Computer Weekly)

That sounds abstract, but it quickly becomes tangible: A forgotten subdomain that still points to an old server. A VPN gateway that hasn’t received an update in two years. An API endpoint that was once opened for a service provider whose contract has since ended. A cloud instance that a developer spun up for testing—and never took down.

With every step toward digitalization, cloud usage, remote work, IoT integration, or networking, not only does the functional benefit increase, but so does the attack surface. In small and medium-sized businesses, where IT teams are often small and many projects run in parallel, this creates a digital gray area over the years—assets that exist but are no longer actively managed by anyone.

Why the BSI 2025 Report Issues an Explicit Warning

The BSI Situation Report 2025 notes that the trend away from large, complex attacks toward many small, easily executed ones continues. This is no coincidence. During the reporting period from July 2024 to June 2025, an average of 119 new vulnerabilities were discovered per day—a 24 percent increase over the previous year. (Source: BSI Situation Report 2025)

119 new vulnerabilities every day. In a company with a modest IT department, this means that manual testing is no longer a realistic option. Anyone who lacks a systematic overview of their exposed assets is inevitably setting themselves up for failure.

The BSI explicitly identifies attack surface management as the critical task for 2026—not as a nice-to-have, but as a fundamental prerequisite for a resilient IT security strategy.

What Attack Surface Management Specifically Means

Attack Surface Management follows a clear process: identification of all externally accessible assets—domains, subdomains, cloud instances, certificates, APIs, mobile and connected devices—then assessment based on risk level, followed by targeted reduction, and permanent, continuous monitoring. (Source: IT-Management.today)

Key questions to consider during the assessment:

  • Which services are accessible from the internet—and do they need to be?
  • Which configurations are insecure by default?
  • Are there any expired certificates in use?
  • Are there systems that are no longer officially in use but are still accessible?

The last point is particularly critical. Identifying and removing redundant or duplicate applications and services is one of the simplest ways to reduce the attack surface. It sounds trivial—but in practice, it is systematically underestimated.

The difference between reactive and proactive

Traditional IT security models operate reactively: an incident occurs, the SIEM triggers an alert, and the team responds. ASM flips this principle on its head. Managed ASM continuously evaluates the attack surface and identifies vulnerabilities before they can be exploited—this preventive approach shortens the dwell time, limits potential damage, and strengthens overall resilience. (Source: Integrity360)

This is particularly relevant for small and medium-sized businesses: Smaller IT teams lack the capacity for extensive incident response processes. Preventing attacks from occurring in the first place makes more economic sense than dealing with them at great expense—not to mention the reputational damage and business disruptions.

ASM and the Cloud: A Unique Challenge

Cloud environments make attack surface management more complex than ever before. In hybrid environments combining cloud, on-premises, and SaaS, security teams often juggle isolated tools that yield disjointed results—leaving them without a complete, unified view of their risk exposure from the start. (Source: Wiz)

Those running Azure and AWS in parallel must keep track of both environments—including all automatically provisioned resources, access rights, and network configurations. A single misconfigured storage bucket or an open security group can be enough to expose sensitive data or entry points into the internal network.

Internal link: Optimizing Cloud Costs with AWS and Azure

What You Can Do Specifically

A comprehensive ASM program doesn’t have to be in place overnight. A structured approach makes more sense:

Build an asset inventory: Which systems, services, and domains are accessible from the internet? Many companies are surprised by how long this list actually is.

Take an external perspective: Tools like Shodan, Censys, or specialized ASM platforms scan your own infrastructure from an attacker’s perspective. What would someone find if they were specifically looking for entry points?

Prioritize instead of alarming: Not every vulnerability found is equally significant. The key question is: How high is the risk if this specific vulnerability is exploited? Critical systems, publicly exposed services, and outdated components take priority.

Ensure continuity: One-time scans are not enough. The attack surface changes daily—due to new systems, updates, configuration changes, and new cloud resources. Continuous monitoring is not optional; it is mandatory.

Internal link: More about IT Security Services

Conclusion

Attack surface management is not an exotic enterprise topic. It is a logical consequence of what the BSI Situation Report 2025 soberly describes: Attackers are opportunistic, vulnerabilities grow daily, and SMEs are preferred targets—precisely because they often have less transparency regarding their own IT exposure than large corporations. If you don’t know what you’re exposing, you can’t protect it. It’s that simple.

Optimize Your Cloud Costs!

Discover strategies for optimizing existing cloud models in our white paper!

IT Projects

Find out about our IT projects and customer success stories up close now.

HWS is looking for you

We are always looking for motivated talents who want to help shape our company. With us, you can expect challenging work in IT and a dynamic, inclusive corporate culture.

HWS AT A GLANCE

Find out who we are and what drives us. Immerse yourself and discover our passion for technology, innovation and excellence, made in Franconia