spot_img

Date:

Share:

From two doors to a dozen: The exponential expansion of the enterprise attack surface

The risk to the business has grown significantly thanks to the widening footprint of the enterprise attack surface, says Richard Frost, Head of Technology Solutions and Consulting at Armata Cyber Security.

The enterprise risk footprint has grown exponentially. Until recently, companies were wrestling with protecting the business from two fronts: a malicious email or an external hack. Employees were trained to detect phishing emails and unexpected threats, while security teams prioritised endpoints and access points with technologies designed to deflect the threats before they made it past the first wall. Today, the threat now sits inside the perimeter, carried by employees, contractors, AI copilots and even ghost employees, and it has become, increasingly, a business resilience challenge that requires companies to coordinate security across multiple fronts.

Information itself has become one of these fronts. Where data resides is also a point from which it can leak, and this data resides on every laptop and server, and on every device able to reach the data. AI has added its own layer of risk, changing the meaning of user awareness entirely. The old worry was that someone would open a malicious email or click on a link, entering information into a spoof site and providing hackers with access to the enterprise. The new worry is what that same person pastes into a chatbot, because confidential information dropped into a public model can leave the business and enter the wrong hands without attackers having to even lift so much as a finger.

AI has changed how people share and access information within the business as well. Employees are taking advantage of AI tools that sit outside the company’s established security remit and using them to manipulate data, share insights and so much more. The growing threat of shadow AI is something that current security teams and technologies were never built to manage or monitor. As PwC points out in its Insider Risk: Client Survey Insights 2026, precisely 0% of companies feel that they are prepared for the ‘AI-driven insider risk’.

Cloud has contributed to the threat sprawl as well because it has made almost everything external by default. Email sits in Microsoft 365 or Gmail, records are stored in platforms that are built and hosted by someone else, and each of these platforms and systems is another way into the business. And, then, another access point that has become increasingly prevalent in 2026, is the third-party service provider. The supply chain is dangerous because the security weakness may not be yours – a compromised invoice or email can be sent through a trusted third party into your business. The third party didn’t know they were hacked or that they were the hacker’s route into your organisation.

Every integration compounds your exposure to threats. An API, a shared record in a hosted customer relationship management (CRM) platform – these are channels that can run both ways, and when the data lives in a platform you do not own, you lose a measure of control over how you can secure it and its access. This threat has gained momentum because identity is under constant attack, with usernames, passwords, personal details and key information scraped from social media and used to enter the organisation through the front door. The third-party supplier, the employee, the C-suite, everyone is hackable, and every identity is usable.

While the human layer is the easiest for hackers to work with, scraping information from an executive’s open LinkedIn profile, for example, and gathering up all the raw material needed for a social engineering attack, devices are a growing problem. They listen, wake on keywords in unrelated meetings, and can be used as an access point for hackers to gain information. Finally, there are physical access points that companies may not realise are a problem, such as a sign-in register anyone can photograph and use to engineer their way into the building or inserting a USB drive into an unattended machine. These are not the outlying threats that you read about in the news headlines; they are clever and insidious approaches that have been refined and perfected by criminals.

Protecting this sprawling layer of access and risk feels increasingly daunting for the modern enterprise. Where do you start? Is it armed guards at reception? A ban on all devices in meeting rooms? Right now, most companies are figuring it out one risk, threat, and vulnerability at a time, but there are ways to build a more resilient and intelligent security framework that’s more likely to catch and deflect the threats. Added to this, users are invertedly allowing threat actors in straight through the front door. It comes down to multi-layered defence, awareness, strict governance and policies, using AI as a persistent security guard, and working with companies that understand exactly what your attack surface looks like and how you need to approach securing it.

spot_img
spot_img

━ More like this

South African businesses are building with AI faster than they can secure it

AI is making it possible for small and medium-sized enterprises (SMEs) to build customer-facing software without a traditional development team. As more business owners...

The hidden cost of a fragmented contingent workforce

For many organisations, using contractors and temporary workers has become a practical response to a labour market defined by skills shortages, shifting demand and...

Digital finance for AI-driven economies: Africa’s role in the next phase of cross-border commerce

Africa’s relevance to the evolution of global finance is significant. The continent’s experience, particularly in cross-border payments, provides a glimpse into what tomorrow’s increasingly...

Systems of record are becoming systems of action in the era of AI-first intelligence

Craig Fidler, Lead Business Consultant at Braintree, talks about Microsoft's move to AI-first and how this helps organisations extract more value from existing systems...

Cracking the Africa code: 54 countries, 54 opportunities for global brands to succeed

Kabelo Makwane is Google South Africa’s country director and works to drive growth and innovation in tech and digital transformation across enterprise, consumer, and...
spot_img
spot_img