Speaker
Description
An organisation’s external attack surface comprises all its online (Internet-facing) assets: domains, subdomains and IP addresses, and respective websites, ports and services, components, DNS records and certificates.
Using .ac.uk domain data, Jisc conducted a scanning project of the entire .ac.uk namespace in 2024 and again in 2025. This has produced a national picture of risk of the education and research sectors. It also illuminated the range and extent of technologies deployed across the sectors.
Iain Brown, Jisc's Chief Security Architect, will present an overview of this sector-wide attack surface management (ASM) scans and its insights into its surprising findings. Gain insight into how institutional infrastructure is viewed externally and why inviting open doors and windows could and should be closed and locked. This session explores how this work is helping Jisc, universities and colleges identify risks, reduce exposure, and strengthen collective resilience.
Iain will explain the benefits of passive attack surface discovery and testing. He will give an insight how building a comprehensive view of the UK education and research sectors' exposed assets and potential vulnerabilities has been developed into a rich and valuable data resource. And he will talk about plans for this year's scanning efforts.