Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security & Compliance Glossary

Attack Surface

An attack surface is the full set of points where an unauthorized user could try to enter or extract data from a system. It includes every exposed endpoint, API, port, service, credential, and human path an attacker might target. Reducing the attack surface means eliminating unnecessary exposure to lower risk.

In practice

Attack surface grows quietly: a forgotten subdomain, an exposed admin panel, a stale API key, a third-party integration. Attackers inventory these continuously, so defenders need to as well.

Attack surface management is the ongoing discipline of discovering, monitoring, and shrinking that exposure. The fastest risk reduction is usually removing things you no longer need rather than adding new defenses.

// how traztech helps

traztech delivers attack surface mapping and reduction for startups and growth-stage companies, led by a published security researcher.

Book a call

For a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.

Where it comes up

Attack surface becomes concrete during a first assessment, when somebody inventories what is actually exposed and finds staging environments, forgotten subdomains and an admin interface that was never meant to be public.

It is also the thing that grows quietly. Every new integration, subdomain and third-party script adds to it, which is why inventory is a recurring control rather than a one-time exercise.

Attack Surface: common questions

How do we reduce attack surface?

Retire what is unused, put authentication in front of anything internal, restrict network exposure to what is required, and keep an inventory so new exposure is noticed rather than discovered.

Is attack surface the same as an asset inventory?

Related but not identical. The inventory is what you own. The attack surface is the subset that an outsider can reach and interact with.

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.

Before you go

Want the practical version by email?

Definitions only get you so far. I send a few short notes on how this plays out in practice. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.