Overview
Direct Answer
An attack vector is a specific technique, pathway, or vulnerability that an adversary exploits to breach a system's security controls and gain unauthorised access. It represents the methodological choice an attacker makes based on identified weaknesses in people, processes, or technology.
How It Works
An attacker first conducts reconnaissance to identify potential weaknesses—such as unpatched software, phishing susceptibility, or misconfigured cloud storage—then selects the most feasible method to exploit that weakness. The chosen vector becomes the operational channel through which malicious activity is delivered, whether through social engineering, network exploitation, or physical access, ultimately compromising confidentiality, integrity, or availability.
Why It Matters
Organisations must identify and prioritise remediation of attack vectors to reduce their overall risk exposure and comply with security standards. Understanding which vectors pose the greatest threat enables security teams to allocate limited resources effectively, reduce breach probability and associated financial and reputational costs.
Common Applications
In financial services, phishing remains a primary vector targeting employee credentials; in healthcare, ransomware leverages unpatched systems; cloud-native environments face misconfigured access controls as a principal vector. Threat modelling exercises systematically enumerate possible vectors for a given application architecture.
Key Considerations
Not all vectors present equal risk; likelihood and impact must be weighted together. An organisation's threat model and risk appetite determine which vectors warrant immediate mitigation versus monitoring or acceptance.
More in Cybersecurity
Information Security
Security GovernanceThe practice of protecting information by mitigating information risks including unauthorised access, use, and disruption.
Endpoint Detection and Response
Defensive SecuritySecurity technology that monitors endpoint devices to detect, investigate, and respond to cyber threats.
AI Security
Offensive SecurityThe discipline of protecting AI systems from adversarial attacks, data poisoning, model theft, and prompt injection while ensuring the secure deployment of AI in production environments.
Man-in-the-Middle Attack
Offensive SecurityAn attack where the attacker secretly relays and potentially alters communication between two parties.
Security Orchestration, Automation and Response
Defensive SecurityA technology stack that integrates security tools and automates incident response workflows, enabling faster triage, investigation, and remediation of security alerts.
Biometric Authentication
Identity & AccessUsing unique biological characteristics like fingerprints, facial features, or iris patterns to verify identity.
Zero-Day Vulnerability
Offensive SecurityA software security flaw unknown to the vendor that can be exploited before a patch is available.
Attack Surface
Offensive SecurityThe total number of points where an unauthorised user can try to enter or extract data from a system.