TL;DR: Attack surface management treats every internet-reachable asset as a potential foothold, and Intruder’s 2026 index says 60% of organisations expose HTTP panels, more than a quarter expose MySQL, and 11% leave Remote Desktop open. The lesson for IAM and security teams is that exposure control, not just vulnerability scanning, is now part of identity and access governance.
NHIMG editorial — based on content published by Intruder: LLMjacking and attack surface management analysis
By the numbers:
- 60% of organizations have an exposed HTTP panel, over a quarter have a publicly-facing MySQL database, and 11% have Remote Desktop exposed to the internet.
- 17 minutes., edentials are exposed publicly, attackers attempt access within an average of 17 minutes.
Questions worth separating out
Q: What breaks when internet-facing admin panels are left exposed?
A: Exposed admin panels reduce the distance between scanning and compromise.
Q: Why do exposed services complicate IAM and PAM governance?
A: Because identity controls only work cleanly when the access boundary is clear.
Q: How do you know if attack surface management is actually working?
A: Look for fewer unknown internet-facing assets, faster detection of newly exposed services, and clearer ownership for public endpoints.
Practitioner guidance
- Map and remove unnecessary public exposure Inventory internet-facing admin panels, databases, remote access services, and login endpoints, then take anything nonessential off the internet before addressing patch backlog.
- Tie exposure discovery to identity and asset lifecycle Link ASM outputs to account ownership, third-party onboarding, offboarding, and service retirement so forgotten assets do not outlive their business purpose.
- Prioritise credential abuse on exposed services Assume exposed interfaces will be probed for password reuse and guessed credentials, and harden them with unique secrets, strong authentication, and network restrictions.
What's in the full article
Intruder's full guide covers the operational detail this post intentionally leaves for the source:
- Continuous monitoring and change-triggered scanning mechanics for internet-facing assets
- How the connector model maps cloud services to exposed IPs, subdomains, and login pages
- Prioritisation logic that ranks exposed services by exploitability and business risk
- Examples of how new high-impact vulnerabilities trigger immediate re-scans
👉 Read Intruder's guide to attack surface management and exposed infrastructure →
Attack surface management and exposed infrastructure: are your controls keeping up?
Explore further