Attack surface: penetration tests & PTaaS
Starting point
External attack surface grows with every release; web apps, APIs and cloud configuration are tested only episodically.
Consequence if unaddressed
Consequence: vulnerabilities stay open for months, prioritization follows gut feeling instead of CVSS, and evidence is missing.