Security assessments often give us a list of things that could go wrong.
An exposed service. A vulnerable application. A weak process. A phishing risk. An overly privileged account.
But an attacker does not experience an organization as a list.
They experience it as a path.
They are not asking, “How many vulnerabilities does this organization have?” They are asking: Where can I get in, what can I reach from there, and what should I target next?
That distinction is at the heart of Mapping Your Attack Surface, the second session of The Ceiba Protocol.
The session takes the adversarial perspective introduced in The Attacker’s Methodology and turns it into collective practice. Rather than analyzing vulnerabilities independently, participants work together through a realistic organizational scenario, staying deliberately in the attacker’s seat.
The goal is to make adversarial thinking less theoretical and more instinctive.
An attack surface is more than technology
When we talk about an organization's attack surface, it is easy to think exclusively about technology.
Servers. Applications. APIs. Cloud infrastructure. Devices.
Those matter, but they are only part of the picture.
An attacker may also find openings through people and processes.
A procedure that creates unnecessary access. A business process that exposes sensitive information. A trusted relationship that can be manipulated. A human behavior that makes a technical control easier to bypass.
This is why the exercise deliberately looks across three dimensions: human, procedural and technical.
The interesting part is what happens at their intersection.
A technical vulnerability may not appear particularly significant in isolation. But combine it with a particular user privilege, an organizational process, or another weakness, and it may become part of a viable attack path.
That is what an adversarial assessment is designed to uncover.
Stop looking at vulnerabilities in isolation
One of the most common traps in security is treating vulnerabilities as individual problems. We identify them, assign severity, prioritize them, and move on.
An attacker is less interested in the severity score than in what the weakness allows them to do.
The more useful question becomes: what happens next?
- If an attacker compromises this account, where can they go?
- If they gain access to this system, what does it connect to?
- If they manipulate this process, what information becomes available?
- If they compromise this employee, what legitimate access can they inherit?
This is where mapping becomes powerful.
Instead of creating a catalogue of vulnerabilities, participants build a picture of how those vulnerabilities could connect into a sequence.
Thinking in sequences
Attackers operate sequentially.
Reconnaissance leads to a potential entry point. An entry point can create access. Access can reveal additional opportunities. Those opportunities can lead closer to the attacker's objective.
The sequence matters.
A vulnerability that seems low priority when viewed independently may become highly relevant if it provides the next step in an otherwise plausible attack path.
During Mapping Your Attack Surface, participants are asked to anticipate that sequence collectively.
- Where would the attacker start?
- What would they target first?
- What would they discover once inside?
- What would give them the next opportunity?
The exercise keeps participants in that mindset rather than allowing them to immediately return to the defender's perspective. That distinction is intentional.
If we move too quickly into “How would we stop this?”, we can lose the more uncomfortable question:
“How would someone actually try to exploit us?”
The value of doing it together
This session is deliberately collaborative.
Participants do not each complete an assessment independently and compare answers afterward. The group co-creates an adversarial assessment of a realistic organizational scenario.
That changes the exercise.
Different professional perspectives reveal different assumptions.
A security leader may notice a technical pathway. Someone with legal or privacy responsibility may recognize a procedural exposure. An executive may identify an organizational dependency that changes the significance of the attack.
Together, the group builds a more complete picture of the organization as an attacker might experience it.
The objective is not to find one “correct” attack path. It is to develop the ability to sustain an adversarial perspective across the organization.
From technical thinking to strategic thinking
For senior leaders, this perspective has value well beyond penetration testing.
The ability to think through an attack path can change how security exposure is communicated at the executive and board level.
Instead of presenting isolated findings, a security leader can explain how seemingly separate weaknesses could combine into a meaningful organizational exposure. That creates a much more useful conversation about priorities.
It also connects directly to the first component of the decision instrument developed throughout The Ceiba Protocol: Threat Exposure Assessment, which asks participants to read organizational vulnerability through an adversarial lens.
The objective is ultimately not to produce a better vulnerability list. It is to develop a better way of reasoning about exposure.
Why this matters for senior leaders
Mapping Your Attack Surface is particularly relevant for leaders who are responsible for organizational risk but cannot afford to view cybersecurity exclusively through their own professional lens.
For security leaders, it strengthens the ability to anticipate how an attacker might move through an environment.
For technology executives, it provides a way to think about infrastructure and systems as interconnected pathways rather than isolated assets.
For legal, privacy, risk, and executive leaders, it provides context for understanding why a seemingly technical weakness may have consequences far beyond the system where it was discovered.
Most importantly, it creates a shared language.
An organization becomes easier to defend when the people responsible for its decisions can recognize the same exposure and understand how the pieces connect.
Making the attacker mindset instinctive
The real objective of the session is captured in its simplest idea:
Don't just know how an attacker thinks. Practice thinking like one.
The more deliberately that perspective is practiced, the easier it becomes to recognize patterns before an incident forces the organization to confront them.
Mapping Your Attack Surface takes that first step by putting participants in the attacker's seat and keeping them there long enough to see the organization differently.
- Not as a collection of systems.
- Not as a list of controls.
- But as an environment with openings, connections, dependencies, and paths.
Because the most useful attack surface map is not the one that tells you what exists. It is the one that helps you see what an attacker could do with it.
This is one session within The Ceiba Protocol.
