Every security team adds tools to reduce risk.
A new endpoint platform closes a visibility gap. A cloud security product addresses configuration drift. An identity tool improves access governance. Another dashboard gives executives a consolidated view of the environment.
Individually, each decision makes sense.
Collectively, those decisions can create a security program that is difficult to understand, expensive to operate, and nearly impossible to change safely.
Eventually, the tools intended to reduce risk become part of the risk.

Complexity Is an Attack Surface
We usually describe the attack surface in technical terms: exposed services, vulnerable applications, unmanaged devices, excessive privileges, and external dependencies.
But organizations also have an operational attack surface.
