{"id":8505,"date":"2025-08-19T08:14:21","date_gmt":"2025-08-19T06:14:21","guid":{"rendered":"https:\/\/aboveit.fi\/attack-paths-and-attack-surface\/"},"modified":"2025-11-26T15:53:34","modified_gmt":"2025-11-26T13:53:34","slug":"attack-paths-and-attack-surface","status":"publish","type":"post","link":"https:\/\/aboveit.fi\/en\/attack-paths-and-attack-surface\/","title":{"rendered":"Attack Paths and Attack Surface"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"8505\" class=\"elementor elementor-8505 elementor-7493\" data-elementor-post-type=\"post\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-2e2f329 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"2e2f329\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-6731a88\" data-id=\"6731a88\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-0b2cc1b elementor-widget elementor-widget-text-editor\" data-id=\"0b2cc1b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><em>Cybersecurity is more important today than ever before, and one of the key concepts in this context are attack paths and attack surface. But what do these terms actually mean and why is understanding them essential for every organization? <a href=\"https:\/\/aboveit.fi\/author\/matias-haapaniemiaboveit-fi\/\">Matias Haapaniemi<\/a> explains these basics in his blog post this time.  <\/em><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-78f4937 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"78f4937\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-2f55e10\" data-id=\"2f55e10\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-0dbc53f elementor-widget elementor-widget-heading\" data-id=\"0dbc53f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Attack Paths and Attack Surface<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-d9eb2a1 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"d9eb2a1\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-b0b090c\" data-id=\"b0b090c\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-7b004e3 elementor-widget elementor-widget-text-editor\" data-id=\"7b004e3\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>In cybersecurity, you often hear two terms: attack surface and attack paths. They sound technical, but there&#8217;s a simple idea behind them. <\/p>\n<p>The <strong>attack surface<\/strong> includes all the points that an outsider can &#8220;touch&#8221;. Think of your organization as a house: doors, windows, mail slots are part of the attack surface. <\/p>\n<p>In the digital world, the attack surface includes, for example:<\/p>\n<ul>\n<li>Public web services and websites<\/li>\n<li>Employee usernames and passwords<\/li>\n<li>Cloud services, integrations between public services, and interfaces<\/li>\n<li>Laptops, phones, and servers<\/li>\n<li>Third-party add-ons and services<\/li>\n<\/ul>\n<p>The more &#8220;openings&#8221; your organization has, the larger the attack surface and consequently, more opportunities for misuse.<\/p>\n<p>An <strong>attack path<\/strong> is the route an attacker takes from the starting point to their goal.<\/p>\n<ul>\n<li>In the house example, an attack path could be:<br>Mail slot \u2192 Entrance hall \u2192 Living room \u2192 Safe<br><br><\/li>\n<li>A digital attack path could be:<br>Phishing email \u2192 Single user account \u2192 VPN access to internal network \u2192 Server with unpatched vulnerabilities \u2192 File server with valuable data<br><br><\/li>\n<\/ul>\n<p>It&#8217;s important to understand that a single &#8220;opening&#8221; doesn&#8217;t always bring down the whole house. The situation becomes dangerous when small weaknesses combine into a smooth path. <\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-31d3cf3 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"31d3cf3\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-6694fe5\" data-id=\"6694fe5\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-7f89ef9 elementor-widget elementor-widget-heading\" data-id=\"7f89ef9\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">From Basics to Practice<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-cedcb0c elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"cedcb0c\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-734fe18\" data-id=\"734fe18\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-b1425c6 elementor-widget elementor-widget-text-editor\" data-id=\"b1425c6\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Why does all this matter? Simply put, you should care about attack paths and attack surface because: <\/p>\n<ul>\n<li>Reducing the attack surface decreases opportunities to initiate an attack<\/li>\n<li>Breaking attack paths prevents the progression of an attack, even if the initial breach is successful<\/li>\n<\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-2209bf0 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"2209bf0\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-19ad0a1\" data-id=\"19ad0a1\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-afa54fe elementor-widget elementor-widget-text-editor\" data-id=\"afa54fe\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>How should organization&#8217;s IT departments act in practice?<\/p>\n<ol>\n<li>Map &#8211; you can&#8217;t protect services you&#8217;re not aware of<\/li>\n<li>Trim &#8211; remove unnecessary servers, accounts, devices, and services<\/li>\n<li>Strengthen &#8211; activate MFA, add security hardening, <a href=\"https:\/\/aboveit.fi\/holistinen-tietoturva-webinaari\/\">implement Endpoint Detection &amp; Response (EDR)<\/a> and configure device firewalls<\/li>\n<li>Break attack chains &#8211; does a workstation need to allow RDP connections to another workstation? Does a printer need to allow RDP connections to the Domain Controller? <\/li>\n<li>Audit &#8211; are the firewall settings working as they should? Are there new devices in the network that haven&#8217;t been accounted for? <\/li>\n<\/ol>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-d30c18f elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"d30c18f\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-cdeab92\" data-id=\"cdeab92\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-9393f92 elementor-widget elementor-widget-text-editor\" data-id=\"9393f92\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<blockquote>\n<p><em>Come to <a href=\"https:\/\/aboveit.fi\/en\/?page_id=8052\">Above IT&#8217;s Afterwork event<\/a> and learn how Microsoft Defender solutions manage the attack surface and break attack paths. We&#8217;ll share best practices to get more out of products you already have, while significantly reducing manual work. <\/em><\/p>\n<\/blockquote>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Cybersecurity is more important today than ever before, and one of the key concepts in this context are attack paths and attack surface. But what do these terms actually mean and why is understanding them essential for every organization? Matias Haapaniemi explains these basics in his blog post this time. Attack Paths and Attack Surface [&hellip;]<\/p>\n","protected":false},"author":9,"featured_media":8507,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"content-type":"","inline_featured_image":false,"footnotes":""},"categories":[303,218,236],"tags":[305,306,304,219,237],"class_list":["post-8505","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-azure","category-cybersecurity","category-microsoft-365","tag-attack-paths","tag-attack-surface","tag-azure","tag-cybersecurity","tag-microsoft365"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Attack Paths and Attack Surface - Above IT Oy<\/title>\n<meta name=\"description\" content=\"Attack paths and attack surface are aspects that need to be considered in today&#039;s cybersecurity. Matias wrote a blog about this!\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/aboveit.fi\/en\/attack-paths-and-attack-surface\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Attack Paths and Attack Surface - Above IT Oy\" \/>\n<meta property=\"og:description\" content=\"Attack paths and attack surface are aspects that need to be considered in today&#039;s cybersecurity. Matias wrote a blog about this!\" \/>\n<meta property=\"og:url\" content=\"https:\/\/aboveit.fi\/en\/attack-paths-and-attack-surface\/\" \/>\n<meta property=\"og:site_name\" content=\"Above IT Oy\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/aboveitfi\" \/>\n<meta property=\"article:published_time\" content=\"2025-08-19T06:14:21+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-11-26T13:53:34+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/aboveit.fi\/wp-content\/uploads\/2025\/08\/AboveIT-Matias-3-e1755584112487.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"1280\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Matias Haapaniemi\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Matias Haapaniemi\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/aboveit.fi\\\/en\\\/attack-paths-and-attack-surface\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/aboveit.fi\\\/en\\\/attack-paths-and-attack-surface\\\/\"},\"author\":{\"name\":\"Matias Haapaniemi\",\"@id\":\"https:\\\/\\\/aboveit.fi\\\/en\\\/#\\\/schema\\\/person\\\/d4a53cbdd8698810ce4da0615fac49f0\"},\"headline\":\"Attack Paths and Attack Surface\",\"datePublished\":\"2025-08-19T06:14:21+00:00\",\"dateModified\":\"2025-11-26T13:53:34+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/aboveit.fi\\\/en\\\/attack-paths-and-attack-surface\\\/\"},\"wordCount\":434,\"publisher\":{\"@id\":\"https:\\\/\\\/aboveit.fi\\\/en\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/aboveit.fi\\\/en\\\/attack-paths-and-attack-surface\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/aboveit.fi\\\/wp-content\\\/uploads\\\/2025\\\/08\\\/AboveIT-Matias-3-e1755584112487.jpg\",\"keywords\":[\"attack paths\",\"attack surface\",\"Azure\",\"cybersecurity\",\"microsoft365\"],\"articleSection\":[\"Azure\",\"Cybersecurity\",\"Microsoft 365\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/aboveit.fi\\\/en\\\/attack-paths-and-attack-surface\\\/\",\"url\":\"https:\\\/\\\/aboveit.fi\\\/en\\\/attack-paths-and-attack-surface\\\/\",\"name\":\"Attack Paths and Attack Surface - Above IT Oy\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/aboveit.fi\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/aboveit.fi\\\/en\\\/attack-paths-and-attack-surface\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/aboveit.fi\\\/en\\\/attack-paths-and-attack-surface\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/aboveit.fi\\\/wp-content\\\/uploads\\\/2025\\\/08\\\/AboveIT-Matias-3-e1755584112487.jpg\",\"datePublished\":\"2025-08-19T06:14:21+00:00\",\"dateModified\":\"2025-11-26T13:53:34+00:00\",\"description\":\"Attack paths and attack surface are aspects that need to be considered in today's cybersecurity. Matias wrote a blog about this!\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/aboveit.fi\\\/en\\\/attack-paths-and-attack-surface\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/aboveit.fi\\\/en\\\/attack-paths-and-attack-surface\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/aboveit.fi\\\/en\\\/attack-paths-and-attack-surface\\\/#primaryimage\",\"url\":\"https:\\\/\\\/aboveit.fi\\\/wp-content\\\/uploads\\\/2025\\\/08\\\/AboveIT-Matias-3-e1755584112487.jpg\",\"contentUrl\":\"https:\\\/\\\/aboveit.fi\\\/wp-content\\\/uploads\\\/2025\\\/08\\\/AboveIT-Matias-3-e1755584112487.jpg\",\"width\":1280,\"height\":1280},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/aboveit.fi\\\/en\\\/attack-paths-and-attack-surface\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Etusivu\",\"item\":\"https:\\\/\\\/aboveit.fi\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Attack Paths and Attack Surface\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/aboveit.fi\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/aboveit.fi\\\/en\\\/\",\"name\":\"We Are Above IT\",\"description\":\"Tietohallinnon voimavarakumppani\",\"publisher\":{\"@id\":\"https:\\\/\\\/aboveit.fi\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/aboveit.fi\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/aboveit.fi\\\/en\\\/#organization\",\"name\":\"Above IT Oy\",\"url\":\"https:\\\/\\\/aboveit.fi\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/aboveit.fi\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/aboveit.fi\\\/wp-content\\\/uploads\\\/2024\\\/10\\\/aboveIT-logo.png\",\"contentUrl\":\"https:\\\/\\\/aboveit.fi\\\/wp-content\\\/uploads\\\/2024\\\/10\\\/aboveIT-logo.png\",\"width\":1613,\"height\":383,\"caption\":\"Above IT Oy\"},\"image\":{\"@id\":\"https:\\\/\\\/aboveit.fi\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/aboveitfi\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/aboveitfi\",\"https:\\\/\\\/instagram.com\\\/aboveitfi\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/aboveit.fi\\\/en\\\/#\\\/schema\\\/person\\\/d4a53cbdd8698810ce4da0615fac49f0\",\"name\":\"Matias Haapaniemi\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/62a88c40ff59fa65af0446f9fed83102baf125a315973ea874297af43da02528?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/62a88c40ff59fa65af0446f9fed83102baf125a315973ea874297af43da02528?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/62a88c40ff59fa65af0446f9fed83102baf125a315973ea874297af43da02528?s=96&d=mm&r=g\",\"caption\":\"Matias Haapaniemi\"},\"sameAs\":[\"https:\\\/\\\/aboveit.fi\"],\"url\":\"https:\\\/\\\/aboveit.fi\\\/en\\\/author\\\/matias-haapaniemiaboveit-fi\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Attack Paths and Attack Surface - Above IT Oy","description":"Attack paths and attack surface are aspects that need to be considered in today's cybersecurity. Matias wrote a blog about this!","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/aboveit.fi\/en\/attack-paths-and-attack-surface\/","og_locale":"en_US","og_type":"article","og_title":"Attack Paths and Attack Surface - Above IT Oy","og_description":"Attack paths and attack surface are aspects that need to be considered in today's cybersecurity. Matias wrote a blog about this!","og_url":"https:\/\/aboveit.fi\/en\/attack-paths-and-attack-surface\/","og_site_name":"Above IT Oy","article_publisher":"https:\/\/www.facebook.com\/aboveitfi","article_published_time":"2025-08-19T06:14:21+00:00","article_modified_time":"2025-11-26T13:53:34+00:00","og_image":[{"width":1280,"height":1280,"url":"https:\/\/aboveit.fi\/wp-content\/uploads\/2025\/08\/AboveIT-Matias-3-e1755584112487.jpg","type":"image\/jpeg"}],"author":"Matias Haapaniemi","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Matias Haapaniemi","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/aboveit.fi\/en\/attack-paths-and-attack-surface\/#article","isPartOf":{"@id":"https:\/\/aboveit.fi\/en\/attack-paths-and-attack-surface\/"},"author":{"name":"Matias Haapaniemi","@id":"https:\/\/aboveit.fi\/en\/#\/schema\/person\/d4a53cbdd8698810ce4da0615fac49f0"},"headline":"Attack Paths and Attack Surface","datePublished":"2025-08-19T06:14:21+00:00","dateModified":"2025-11-26T13:53:34+00:00","mainEntityOfPage":{"@id":"https:\/\/aboveit.fi\/en\/attack-paths-and-attack-surface\/"},"wordCount":434,"publisher":{"@id":"https:\/\/aboveit.fi\/en\/#organization"},"image":{"@id":"https:\/\/aboveit.fi\/en\/attack-paths-and-attack-surface\/#primaryimage"},"thumbnailUrl":"https:\/\/aboveit.fi\/wp-content\/uploads\/2025\/08\/AboveIT-Matias-3-e1755584112487.jpg","keywords":["attack paths","attack surface","Azure","cybersecurity","microsoft365"],"articleSection":["Azure","Cybersecurity","Microsoft 365"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/aboveit.fi\/en\/attack-paths-and-attack-surface\/","url":"https:\/\/aboveit.fi\/en\/attack-paths-and-attack-surface\/","name":"Attack Paths and Attack Surface - Above IT Oy","isPartOf":{"@id":"https:\/\/aboveit.fi\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/aboveit.fi\/en\/attack-paths-and-attack-surface\/#primaryimage"},"image":{"@id":"https:\/\/aboveit.fi\/en\/attack-paths-and-attack-surface\/#primaryimage"},"thumbnailUrl":"https:\/\/aboveit.fi\/wp-content\/uploads\/2025\/08\/AboveIT-Matias-3-e1755584112487.jpg","datePublished":"2025-08-19T06:14:21+00:00","dateModified":"2025-11-26T13:53:34+00:00","description":"Attack paths and attack surface are aspects that need to be considered in today's cybersecurity. Matias wrote a blog about this!","breadcrumb":{"@id":"https:\/\/aboveit.fi\/en\/attack-paths-and-attack-surface\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/aboveit.fi\/en\/attack-paths-and-attack-surface\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/aboveit.fi\/en\/attack-paths-and-attack-surface\/#primaryimage","url":"https:\/\/aboveit.fi\/wp-content\/uploads\/2025\/08\/AboveIT-Matias-3-e1755584112487.jpg","contentUrl":"https:\/\/aboveit.fi\/wp-content\/uploads\/2025\/08\/AboveIT-Matias-3-e1755584112487.jpg","width":1280,"height":1280},{"@type":"BreadcrumbList","@id":"https:\/\/aboveit.fi\/en\/attack-paths-and-attack-surface\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Etusivu","item":"https:\/\/aboveit.fi\/en\/"},{"@type":"ListItem","position":2,"name":"Attack Paths and Attack Surface"}]},{"@type":"WebSite","@id":"https:\/\/aboveit.fi\/en\/#website","url":"https:\/\/aboveit.fi\/en\/","name":"We Are Above IT","description":"Tietohallinnon voimavarakumppani","publisher":{"@id":"https:\/\/aboveit.fi\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/aboveit.fi\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/aboveit.fi\/en\/#organization","name":"Above IT Oy","url":"https:\/\/aboveit.fi\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/aboveit.fi\/en\/#\/schema\/logo\/image\/","url":"https:\/\/aboveit.fi\/wp-content\/uploads\/2024\/10\/aboveIT-logo.png","contentUrl":"https:\/\/aboveit.fi\/wp-content\/uploads\/2024\/10\/aboveIT-logo.png","width":1613,"height":383,"caption":"Above IT Oy"},"image":{"@id":"https:\/\/aboveit.fi\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/aboveitfi","https:\/\/www.linkedin.com\/company\/aboveitfi","https:\/\/instagram.com\/aboveitfi"]},{"@type":"Person","@id":"https:\/\/aboveit.fi\/en\/#\/schema\/person\/d4a53cbdd8698810ce4da0615fac49f0","name":"Matias Haapaniemi","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/62a88c40ff59fa65af0446f9fed83102baf125a315973ea874297af43da02528?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/62a88c40ff59fa65af0446f9fed83102baf125a315973ea874297af43da02528?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/62a88c40ff59fa65af0446f9fed83102baf125a315973ea874297af43da02528?s=96&d=mm&r=g","caption":"Matias Haapaniemi"},"sameAs":["https:\/\/aboveit.fi"],"url":"https:\/\/aboveit.fi\/en\/author\/matias-haapaniemiaboveit-fi\/"}]}},"_links":{"self":[{"href":"https:\/\/aboveit.fi\/en\/wp-json\/wp\/v2\/posts\/8505","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/aboveit.fi\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/aboveit.fi\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/aboveit.fi\/en\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/aboveit.fi\/en\/wp-json\/wp\/v2\/comments?post=8505"}],"version-history":[{"count":1,"href":"https:\/\/aboveit.fi\/en\/wp-json\/wp\/v2\/posts\/8505\/revisions"}],"predecessor-version":[{"id":8509,"href":"https:\/\/aboveit.fi\/en\/wp-json\/wp\/v2\/posts\/8505\/revisions\/8509"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/aboveit.fi\/en\/wp-json\/wp\/v2\/media\/8507"}],"wp:attachment":[{"href":"https:\/\/aboveit.fi\/en\/wp-json\/wp\/v2\/media?parent=8505"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/aboveit.fi\/en\/wp-json\/wp\/v2\/categories?post=8505"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/aboveit.fi\/en\/wp-json\/wp\/v2\/tags?post=8505"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}