The danger of sprawling digital infrastructures and expanding device fleets is clearer than ever, with new research revealing that 70% of UK organisations have fallen victim to security incidents caused by overlooked or unmanaged assets.
Cybersecurity firm Trend Micro’s latest report, AI is accelerating Cyber Risk Exposure, found that unmanaged IT assets present a hidden danger, as 38% of UK security leaders believe that the proliferation of shadow IT is creating blind spots, with ‘unknown’ assets serving as the trigger for security incidents.
Third-party services are also proving to be a pain point, with Trend Micro’s survey finding that almost all (96%) of respondents point to employees’ use of third-party AI tools as an area of concern that’s widening attack surfaces.
However, the study did find that 56% of UK cybersecurity leaders regularly assess and monitor third-party vendors for security vulnerabilities and factor security into vendor onboarding, although that still leaves nearly half of firms exposed.
Despite that, 82% said their current resources are adequate for addressing attack surface challenges and reducing business risk, with Trend Micro finding that, on average, 29% of their budgets are allocated to attack surface management.
Taken together, the findings reveal a gap between security leaders’ confidence and the reality of a growing number of breaches linked to unidentified or unmanaged IT assets.
Digging deeper, the data reveals that a misaligned view of attack surface management could also be due to how proactive teams are in discovering what the real risk is.
More than a quarter (28%) of organisations said that they address security issues on a reactive basis, with only 43% proactively leveraging dedicated attack surface management tools.
Added to that, 52% of UK cybersecurity leaders only carry out periodic audits or third-party assessments to manage risk, with fewer than half (48%) regularly updating and patching software and systems.
According to Trend Micro, addressing cybersecurity issues on a reactive basis makes it inevitable that organisations will be on the back foot in the event of a compromise via unmanaged or unknown IT assets.
Even for those claiming to respond proactively, a lack of auditing and regular updates amounts to blind spots that can still catch organisations by surprise.
One bright spot, however, is a growing recognition of the cyber risks lurking in supply chains.
Almost all (89%) of security leaders are pen testing or conducting vulnerability assessments monthly, with 38% doing so weekly, strengthening their efforts to manage cyber risks posed by third parties.
Recommended reading
- 87% of Firms Hit By AI Cyber-attacks
- Cyber-Attack Surface “Impossible to Control”
- Machine Identities Now Outnumber Humans 40,000 to 1
“Attack surfaces are expanding through both authorised and unauthorised uses of IT,” said Bharat Mistry, field CTO at Trend Micro.
“A proactive strategy leveraging techniques that anticipate and limit cyber threats before they cause damage is the only answer.
“Our study shows real progress that’s being made in managing growth in attack surfaces via third-party suppliers, but also food for thought on where our industry can go further to establish truly proactive defences that tackle new AI-based threats as well as attack surface blind spots that act as an entry point for attackers.”





