An attack vector is the concrete route an attacker takes into a system – an exposed interface, unpatched software, a convincing email or a stolen password. The sum of all attack vectors makes up an organisation's attack surface.
At a glance
An attack vector is the route in, not the target.
The sum of all vectors is the attack surface.
The most common vector is still a person, not a machine.
An attack vector describes the way in, not the target. Knowing your own vectors lets you close them one by one; not knowing them means defending blind.
Technology, people, supply chain
Technical vectors come from software, configuration and exposed services. Human vectors exploit trust, time pressure and routine. The third route runs through partners and suppliers – an entry the organisation does not control itself.
Real-world examples
- An unpatched VPN gateway allows entry without the victim clicking anything at all.
- A compromised library in the supply chain carries malicious code into your own application.
Common misconception
Myth “We have a firewall, so the vectors are closed.”
Reality A firewall closes network vectors. Phishing, the supply chain and misconfiguration walk straight past it.
Frequently asked questions
What is the difference between an attack vector and an attack surface?
An attack vector is a single route in; the attack surface is the sum of all such routes. ENISA maintains an overview of typical vectors.
Can every attack vector be closed?
No. The goal is to reduce the number of vectors and monitor what remains – which is how the BSI IT-Grundschutz frames it too.