surable

Attack surface

In one sentence

The full set of ways an attacker could try to get in: every account, device, app, and internet-facing service.

Your attack surface is the sum of all entry points exposed to potential attackers. Reducing it (closing unused services, retiring old systems, limiting internet exposure) is a core defensive goal.

How the Readiness Check scores it

The free Check asks the same question a carrier will. Here it is, why it's asked, and the fix if today's honest answer is no. The full application question list has the rest.

MFA & identity

Is MFA required for remote access (VPN, remote desktop) and administrator accounts?

Why carriers ask: Stolen credentials are the most common way attackers get in. Nearly every carrier now requires MFA on email, remote access, and admin accounts as a condition of coverage.

If the answer is no: Inventory every remote entry point (VPN, RDP, remote-support tools) and privileged account; enforce MFA on each or shut it off.

Patching & vulnerabilities

How are security updates applied to your systems and software?

Why carriers ask: Unpatched, internet-facing software is now a leading initial-access vector. Applications ask about patch cadence and end-of-life systems specifically.

If the answer is no: Have whoever manages IT produce a list of what's patched automatically vs. manually. That list becomes your patch-management policy's appendix.

The written evidence carriers accept

A “yes” on the application needs a document behind it. In the Readiness Pack, those documents are:

Related terms

Would you pass this question today?

The free Readiness Check scores you across the ten control domains carriers probe, in five minutes, no email required for the score.

← All terms