<div style="font-family: 'Georgia', serif; max-width: 820px; margin: 0 auto; background: #FAFAF8; color: #1C1C1C;">

<!-- Top accent bar -->

<div style="height: 4px; background: linear-gradient(90deg, #1B6CA8 50%, #E8A020 50%);"></div>

<!-- HEADER BLOCK -->

<div style="padding: 44px 48px 32px 48px; background: #FFFFFF; border-bottom: 1px solid #E4E4DC;">

<div style="display: flex; gap: 10px; margin-bottom: 20px; flex-wrap: wrap;">

<span style="display: inline-block; background: #EAF3FB; border: 1px solid #1B6CA8; color: #1B6CA8; font-family: 'Georgia', serif; font-size: 11px; font-weight: bold; letter-spacing: 2px; text-transform: uppercase; padding: 5px 16px; border-radius: 20px;">Attack Surface Management · Threat Intelligence</span>

<span style="display: inline-block; background: #FEF5E7; border: 1px solid #E8A020; color: #B87A10; font-family: 'Georgia', serif; font-size: 11px; font-weight: bold; letter-spacing: 2px; text-transform: uppercase; padding: 5px 16px; border-radius: 20px;">2026 Research Report</span>

</div>

<h1 style="font-family: 'Georgia', serif; font-size: 38px; line-height: 1.25; color: #0F3D6B; margin: 0 0 20px 0; font-weight: bold; max-width: 700px;">

1 in 4 Organisations Expose MySQL Databases to the Internet — Intruder's 2026 Attack Surface Management Index Reveals a Remediation Crisis

</h1>

<div style="font-family: 'Georgia', serif; font-size: 13px; color: #888; display: flex; align-items: center; gap: 10px; flex-wrap: wrap; margin-bottom: 28px;">

<span style="color: #1B6CA8; font-weight: bold;">iTech360Hub</span>

<span style="color: #CCC;">|</span>

<span>5 min read</span>

<span style="color: #CCC;">|</span>

<span style="background: #FEF5E7; border: 1px solid #E8A020; color: #B87A10; padding: 3px 12px; border-radius: 20px; font-size: 11px; letter-spacing: 1px; text-transform: uppercase;">3,000 Organisations Analysed</span>

</div>

<div style="height: 2px; background: #1B6CA8; width: 60px; border-radius: 2px;"></div>

</div>

<!-- BODY -->

<div style="padding: 40px 48px; background: #FFFFFF;">

<!-- Intro -->

<p style="font-family: 'Georgia', serif; font-size: 18px; line-height: 1.9; color: #2C2C2C; margin: 0 0 20px 0;">

Security teams have spent years focused on the vulnerability management problem — patching known CVEs before adversaries can exploit them. That focus has been largely justified. But new research suggests that organisations are systematically overlooking a more fundamental risk: the services, databases, and administrative panels that should never have been internet-facing in the first place. <a href="https://www.intruder.io" style="color: #1B6CA8; text-decoration: underline;">Intruder</a>, a leader in exposure management, has released the <a href="https://www.intruder.io/blog/attack-surface-exposures" style="color: #1B6CA8; text-decoration: underline;"><strong style="color: #0F3D6B;">2026 Attack Surface Management Index</strong></a> — based on anonymised data from 3,000 customers collected over the twelve months ending March 2026 — with findings that should serve as an urgent wake-up call for security leaders at organisations of every size.

</p>

<p style="font-family: 'Georgia', serif; font-size: 18px; line-height: 1.9; color: #2C2C2C; margin: 0 0 36px 0;">

Over a quarter of organisations — <strong style="color: #0F3D6B;">26%</strong> — have MySQL databases exposed to the public internet. One in six expose Postgres databases. More than one in seven expose sensitive API documentation. Nearly half expose risky ports and services. And the organisations that face the greatest exposure are not necessarily the ones closing gaps fastest: midmarket firms averaging 5,000–10,000 employees take <strong style="color: #0F3D6B;">56 days</strong> to remediate exposures — nearly four times slower than their smaller counterparts — while the emergence of autonomous AI models has compressed the time between vulnerability discovery and exploitation to a single day. The arithmetic of that gap is alarming.

</p>

<!-- Stat strip -->

<div style="display: grid; grid-template-columns: repeat(3, 1fr); gap: 16px; margin: 0 0 44px 0;">

<div style="background: #EAF3FB; border: 1px solid #BDD8F0; border-top: 3px solid #1B6CA8; border-radius: 6px; padding: 22px 16px; text-align: center;">

<div style="font-family: 'Georgia', serif; font-size: 28px; font-weight: bold; color: #0F3D6B; margin-bottom: 6px;">26%</div>

<div style="font-family: 'Georgia', serif; font-size: 13px; color: #555; line-height: 1.5;">Of organisations expose MySQL databases to the internet — a known target for database ransomware and data extortion, requiring no CVE to exploit via brute force or credential stuffing</div>

</div>

<div style="background: #FEF5E7; border: 1px solid #F5D98A; border-top: 3px solid #E8A020; border-radius: 6px; padding: 22px 16px; text-align: center;">

<div style="font-family: 'Georgia', serif; font-size: 28px; font-weight: bold; color: #7A4F00; margin-bottom: 6px;">56 Days</div>

<div style="font-family: 'Georgia', serif; font-size: 13px; color: #555; line-height: 1.5;">Average remediation time for midmarket organisations (5,000–10,000 employees) — nearly 4× slower than small enterprises, creating a dangerous window as AI-driven exploitation accelerates</div>

</div>

<div style="background: #EAF3FB; border: 1px solid #BDD8F0; border-top: 3px solid #0F3D6B; border-radius: 6px; padding: 22px 16px; text-align: center;">

<div style="font-family: 'Georgia', serif; font-size: 28px; font-weight: bold; color: #0F3D6B; margin-bottom: 6px;">1 Day</div>

<div style="font-family: 'Georgia', serif; font-size: 13px; color: #555; line-height: 1.5;">Time-to-exploit for newly discovered vulnerabilities in AI-era threat landscape — making 56-day remediation windows an indefensible gap between exposure and compromise</div>

</div>

</div>

<!-- CEO Quote -->

<blockquote style="margin: 0 0 44px 0; padding: 26px 30px; background: #F7F9FC; border-left: 4px solid #1B6CA8; border-radius: 0 6px 6px 0;">

<p style="font-family: 'Georgia', serif; font-style: italic; font-size: 19px; line-height: 1.75; color: #2C2C2C; margin: 0 0 14px 0;">

"The emergence of autonomous AI models like Mythos has fundamentally shifted the cybersecurity landscape. The security industry is seeing a major compression in the time between vulnerability discovery and exploitation. In this high-speed era, leaving a MySQL database or private API documentation exposed to the internet is an open invitation for automated, high-speed extortion. Many of the exposures we examined don't even need a CVE to be exploited. An exposed database or admin panel can be compromised through brute force or credential stuffing alone."

</p>

<cite style="font-family: 'Georgia', serif; font-style: normal; font-size: 13px; color: #1B6CA8; font-weight: bold; text-transform: uppercase; letter-spacing: 1px;">— Chris Wallis, CEO &amp; Founder, <a href="https://www.intruder.io" style="color: #1B6CA8; text-decoration: underline;">Intruder</a></cite>

</blockquote>

<!-- H2 -->

<h2 style="font-family: 'Georgia', serif; font-size: 26px; color: #0F3D6B; margin: 0 0 14px 0; padding-left: 16px; border-left: 4px solid #E8A020; line-height: 1.3;">

The Top Ten Exposures — What Organisations Are Leaving Open on the Internet

</h2>

<p style="font-family: 'Georgia', serif; font-size: 18px; line-height: 1.9; color: #2C2C2C; margin: 0 0 20px 0;">

The <a href="https://www.intruder.io/blog/attack-surface-exposures" style="color: #1B6CA8; text-decoration: underline;">2026 ASM Index</a> categorises exposures across HTTP panels, ports and services, databases, files and information. Exposed databases dominate the top rankings — and what makes them particularly dangerous is that many do not require a known vulnerability to exploit. A MySQL database accessible from the public internet can be compromised through brute-force credential attacks or credential stuffing using previously breached passwords, with no CVE required. The 2020 PLEASE_READ_ME ransomware campaign compromised over 250,000 MySQL databases this way alone.

</p>

<!-- Top exposure cards -->

<div style="display: flex; flex-direction: column; gap: 14px; margin: 0 0 44px 0;">

<div style="background: #FAFAF8; border: 1px solid #E4E4DC; border-left: 4px solid #1B6CA8; border-radius: 0 6px 6px 0; padding: 22px 26px;">

<h3 style="font-family: 'Georgia', serif; font-size: 18px; color: #1B6CA8; margin: 0 0 10px 0;">Databases — MySQL (26%) and Postgres (16%): Ransomware's Favourite Targets</h3>

<p style="font-family: 'Georgia', serif; font-size: 17px; line-height: 1.8; color: #2C2C2C; margin: 0;">Exposed databases take the top two spots in the Index. More than a quarter of organisations expose MySQL — a known target for database ransomware and data extortion campaigns — and one in six expose Postgres. Internet-facing databases have been a consistent target for opportunistic attackers for years, and the emergence of AI-driven autonomous exploitation has made the risk of leaving them exposed categorically more severe. When a new vulnerability drops, anything exposed to the internet is immediately at risk — and at AI-driven exploitation speed, the window to patch before active attacks begin has collapsed to hours or less.</p>

</div>

<div style="background: #FAFAF8; border: 1px solid #E4E4DC; border-left: 4px solid #E8A020; border-radius: 0 6px 6px 0; padding: 22px 26px;">

<h3 style="font-family: 'Georgia', serif; font-size: 18px; color: #B87A10; margin: 0 0 10px 0;">API Documentation — 1 in 7 Organisations Expose Sensitive Endpoint Intelligence</h3>

<p style="font-family: 'Georgia', serif; font-size: 17px; line-height: 1.8; color: #2C2C2C; margin: 0;">More than one in seven organisations expose API documentation publicly — a finding that ranks ahead of Remote Desktop in the Index's severity assessment. Exposed API documentation is not simply an information disclosure issue — it provides adversaries with a detailed map of endpoints, authentication parameters, data structures, and integration patterns that dramatically lowers the effort required to identify exploitable weaknesses. For adversaries using AI to automate vulnerability discovery, a publicly accessible API specification is the equivalent of a detailed blueprint of the building before the attack.</p>

</div>

<div style="background: #FAFAF8; border: 1px solid #E4E4DC; border-left: 4px solid #1B6CA8; border-radius: 0 6px 6px 0; padding: 22px 26px;">

<h3 style="font-family: 'Georgia', serif; font-size: 18px; color: #1B6CA8; margin: 0 0 10px 0;">Remote Desktop and Risky Ports — 49% of Organisations Expose High-Risk Services</h3>

<p style="font-family: 'Georgia', serif; font-size: 17px; line-height: 1.8; color: #2C2C2C; margin: 0;">Nearly half of all organisations in the dataset expose risky ports and services — with Remote Desktop Protocol (RDP) as the most commonly exposed service, ranked as the poster child of services that should never face the public internet. RDP was the entry vector for some of the most damaging ransomware campaigns in recent years, and its continued exposure across 49% of organisations reflects a persistent failure to enforce basic network hygiene. Legacy services including SNMP (9%), UPnP (8%), NTP, and RPC complete the top ten — all services designed for internal networks that were never intended to be internet-facing.</p>

</div>

<div style="background: #FAFAF8; border: 1px solid #E4E4DC; border-left: 4px solid #E8A020; border-radius: 0 6px 6px 0; padding: 22px 26px;">

<h3 style="font-family: 'Georgia', serif; font-size: 18px; color: #B87A10; margin: 0 0 10px 0;">Admin Panels — WordPress Admin (15%) and phpMyAdmin (8%) Left Internet-Facing</h3>

<p style="font-family: 'Georgia', serif; font-size: 17px; line-height: 1.8; color: #2C2C2C; margin: 0;">Administrative interfaces that provide direct control over websites and databases — WordPress Admin (15% of organisations) and phpMyAdmin (8%) — are among the most consequential exposures because they provide attackers with privileged access pathways that bypass the normal application security stack. A brute-forced admin panel credential does not trigger a CVE alert and may not be caught by vulnerability scanners that focus on known software vulnerabilities. These exposures represent exactly the category of risk the Index highlights: not a vulnerability in code, but a fundamental question of whether a service should be publicly reachable at all.</p>

</div>

</div>

<!-- H2 -->

<h2 style="font-family: 'Georgia', serif; font-size: 26px; color: #0F3D6B; margin: 0 0 14px 0; padding-left: 16px; border-left: 4px solid #E8A020; line-height: 1.3;">

The Midmarket Bottleneck — Scale Without Security Maturity

</h2>

<p style="font-family: 'Georgia', serif; font-size: 18px; line-height: 1.9; color: #2C2C2C; margin: 0 0 20px 0;">

One of the most commercially significant findings in the Index is the inverse relationship between organisation size and remediation speed in the midmarket range. Small enterprises — those with 51 to 250 employees — remediate exposures in an average of 14 to 18 days. As organisations scale into the 5,000–10,000 employee range, that average rises to 56 days — nearly four times slower. The Index identifies this as the <strong style="color: #0F3D6B;">midmarket bottleneck</strong>: organisations with 251 to 5,000 employees are managing enterprise-level attack surface complexity without the headcount, budget, or tooling maturity that large enterprises have built to manage it.

</p>

<p style="font-family: 'Georgia', serif; font-size: 18px; line-height: 1.9; color: #2C2C2C; margin: 0 0 20px 0;">

The scale of this challenge is illustrated by the asset data: organisations with 1,000–5,000 employees manage an average of 748 external assets — more than five times as many as organisations in the 251–1,000 range, and nearly 35 times more than small enterprises. Each additional asset is a potential exposure point, and each additional exposure point is a potential entry vector for an adversary who, in the AI era, can enumerate and probe those surfaces at machine speed. The combination of large attack surfaces, slow remediation cycles, and AI-compressed exploitation timelines creates a structural risk profile that the midmarket is currently failing to address.

</p>

<!-- Sector grid -->

<div style="display: grid; grid-template-columns: repeat(3, 1fr); gap: 14px; margin: 0 0 44px 0;">

<div style="background: #FAFAF8; border: 1px solid #E4E4DC; border-top: 3px solid #1B6CA8; border-radius: 6px; padding: 20px 18px; text-align: center;">

<div style="font-family: 'Georgia', serif; font-size: 22px; font-weight: bold; color: #0F3D6B; margin-bottom: 6px;">11 Days</div>

<div style="font-family: 'Georgia', serif; font-size: 15px; font-weight: bold; color: #0F3D6B; margin-bottom: 8px;">Banking</div>

<p style="font-family: 'Georgia', serif; font-size: 14px; line-height: 1.65; color: #555; margin: 0;">The fastest-remediating sector — banks close exposures in an average of 11 days, reflecting the regulatory pressure and security investment that financial services organisations maintain as baseline requirements.</p>

</div>

<div style="background: #FAFAF8; border: 1px solid #E4E4DC; border-top: 3px solid #E8A020; border-radius: 6px; padding: 20px 18px; text-align: center;">

<div style="font-family: 'Georgia', serif; font-size: 22px; font-weight: bold; color: #7A4F00; margin-bottom: 6px;">10 Days</div>

<div style="font-family: 'Georgia', serif; font-size: 15px; font-weight: bold; color: #0F3D6B; margin-bottom: 8px;">Retail</div>

<p style="font-family: 'Georgia', serif; font-size: 14px; line-height: 1.65; color: #555; margin: 0;">Retail organisations remediate in an average of ten days — the fastest alongside banking — likely driven by high-volume customer data exposure risk and the acute commercial consequence of breaches.</p>

</div>

<div style="background: #FAFAF8; border: 1px solid #E4E4DC; border-top: 3px solid #1B6CA8; border-radius: 6px; padding: 20px 18px; text-align: center;">

<div style="font-family: 'Georgia', serif; font-size: 22px; font-weight: bold; color: #0F3D6B; margin-bottom: 6px;">40+ Days</div>

<div style="font-family: 'Georgia', serif; font-size: 15px; font-weight: bold; color: #0F3D6B; margin-bottom: 8px;">Insurance &amp; Pharma</div>

<p style="font-family: 'Georgia', serif; font-size: 14px; line-height: 1.65; color: #555; margin: 0;">Insurance and pharmaceutical firms average over 40 days to remediate — a striking contrast with banking that suggests their regulatory regimes are creating compliance overhead without the operational security velocity that healthcare and financial data sensitivity demands.</p>

</div>

</div>

<!-- H2 -->

<h2 style="font-family: 'Georgia', serif; font-size: 26px; color: #0F3D6B; margin: 0 0 14px 0; padding-left: 16px; border-left: 4px solid #E8A020; line-height: 1.3;">

The AI Acceleration Factor — Why Exposure Reduction Must Come Before Patching

</h2>

<p style="font-family: 'Georgia', serif; font-size: 18px; line-height: 1.9; color: #2C2C2C; margin: 0 0 20px 0;">

The Index's data takes on a different character when placed against the AI threat acceleration context that Chris Wallis highlights. Autonomous AI models are now capable of discovering zero-day vulnerabilities and initiating exploitation within a single day of discovery. The MongoBleed example (CVE-2025-14847) illustrates the scale of the risk: when it was disclosed, more than 87,000 databases were publicly exposed and immediately at risk. For most teams, the instinct is to patch — but the Index makes the case that patching is the wrong first response when the real question is whether the service should be internet-facing at all.

</p>

<p style="font-family: 'Georgia', serif; font-size: 18px; line-height: 1.9; color: #2C2C2C; margin: 0 0 20px 0;">

Attack surface reduction — removing services from internet exposure entirely — is a more durable and less resource-intensive defence than continuous patching. A MySQL database that is not internet-facing cannot be brute-forced from the public internet, regardless of whether its credentials are strong or its software is patched. The Index's central argument is that the security industry's focus on vulnerability patching has allowed a parallel and arguably more fundamental risk to grow unchecked: the question of what should be on the internet in the first place.

</p>

<p style="font-family: 'Georgia', serif; font-size: 18px; line-height: 1.9; color: #2C2C2C; margin: 0 0 44px 0;">

Since 2015, <a href="https://www.intruder.io" style="color: #1B6CA8; text-decoration: underline;">Intruder</a> has helped its customers take more than <strong style="color: #0F3D6B;">133,000 exposures off the internet</strong> — a statistic that represents not vulnerabilities patched, but services removed from attacker reach entirely.

</p>

<!-- Capability pills -->

<div style="margin: 0 0 44px 0;">

<div style="font-family: 'Georgia', serif; font-size: 12px; color: #1B6CA8; text-transform: uppercase; letter-spacing: 2px; font-weight: bold; margin-bottom: 14px;">Intruder Exposure Management Platform Capabilities</div>

<div style="display: flex; flex-wrap: wrap; gap: 8px;">

<span style="background: #EAF3FB; border: 1px solid #1B6CA8; color: #0F3D6B; font-family: 'Georgia', serif; font-size: 13px; padding: 6px 16px; border-radius: 20px;">Attack Surface Management</span>

<span style="background: #FEF5E7; border: 1px solid #E8A020; color: #7A4F00; font-family: 'Georgia', serif; font-size: 13px; padding: 6px 16px; border-radius: 20px;">AI Penetration Testing</span>

<span style="background: #EAF3FB; border: 1px solid #1B6CA8; color: #0F3D6B; font-family: 'Georgia', serif; font-size: 13px; padding: 6px 16px; border-radius: 20px;">Continuous Vulnerability Management</span>

<span style="background: #FEF5E7; border: 1px solid #E8A020; color: #7A4F00; font-family: 'Georgia', serif; font-size: 13px; padding: 6px 16px; border-radius: 20px;">Cloud Security</span>

<span style="background: #EAF3FB; border: 1px solid #1B6CA8; color: #0F3D6B; font-family: 'Georgia', serif; font-size: 13px; padding: 6px 16px; border-radius: 20px;">Exposure Prioritisation</span>

<span style="background: #FEF5E7; border: 1px solid #E8A020; color: #7A4F00; font-family: 'Georgia', serif; font-size: 13px; padding: 6px 16px; border-radius: 20px;">Database Exposure Detection</span>

<span style="background: #EAF3FB; border: 1px solid #1B6CA8; color: #0F3D6B; font-family: 'Georgia', serif; font-size: 13px; padding: 6px 16px; border-radius: 20px;">1,000+ Exposure Signatures</span>

<span style="background: #FEF5E7; border: 1px solid #E8A020; color: #7A4F00; font-family: 'Georgia', serif; font-size: 13px; padding: 6px 16px; border-radius: 20px;">Lean Security Team Support</span>

</div>

</div>

<!-- KEY TAKEAWAYS -->

<div style="margin: 0 0 36px 0; background: #F0F6FC; border: 1px solid #BDD8F0; border-top: 3px solid #1B6CA8; border-radius: 0 0 6px 6px; padding: 30px 32px;">

<h3 style="font-family: 'Georgia', serif; font-size: 14px; color: #1B6CA8; text-transform: uppercase; letter-spacing: 2px; margin: 0 0 20px 0; font-weight: bold;">Key Takeaways</h3>

<div style="display: flex; flex-direction: column; gap: 14px;">

<div style="display: flex; gap: 14px; align-items: flex-start;">

<span style="display: inline-block; min-width: 22px; height: 22px; background: #1B6CA8; color: #fff; border-radius: 50%; text-align: center; line-height: 22px; font-family: 'Georgia', serif; font-size: 12px; font-weight: bold; flex-shrink: 0; margin-top: 2px;">1</span>

<p style="font-family: 'Georgia', serif; font-size: 16px; line-height: 1.75; color: #2C2C2C; margin: 0;"><a href="https://www.intruder.io/blog/attack-surface-exposures" style="color: #1B6CA8; text-decoration: underline;">Intruder's 2026 ASM Index</a>, based on 3,000 organisations over twelve months, finds that <strong style="color: #0F3D6B;">26% expose MySQL databases, 16% expose Postgres, 1 in 7 expose API documentation, and 49% expose risky ports and services</strong> — none of which require a CVE to exploit, relying instead on brute force, credential stuffing, or default credentials.</p>

</div>

<div style="display: flex; gap: 14px; align-items: flex-start;">

<span style="display: inline-block; min-width: 22px; height: 22px; background: #E8A020; color: #fff; border-radius: 50%; text-align: center; line-height: 22px; font-family: 'Georgia', serif; font-size: 12px; font-weight: bold; flex-shrink: 0; margin-top: 2px;">2</span>

<p style="font-family: 'Georgia', serif; font-size: 16px; line-height: 1.75; color: #2C2C2C; margin: 0;">Midmarket organisations (5,000–10,000 employees) take an average of <strong style="color: #0F3D6B;">56 days to remediate exposures</strong> — nearly four times slower than small enterprises at 14–18 days — while managing attack surfaces up to 35× larger than smaller peers, creating the defining security risk profile of the current threat environment.</p>

</div>

<div style="display: flex; gap: 14px; align-items: flex-start;">

<span style="display: inline-block; min-width: 22px; height: 22px; background: #1B6CA8; color: #fff; border-radius: 50%; text-align: center; line-height: 22px; font-family: 'Georgia', serif; font-size: 12px; font-weight: bold; flex-shrink: 0; margin-top: 2px;">3</span>

<p style="font-family: 'Georgia', serif; font-size: 16px; line-height: 1.75; color: #2C2C2C; margin: 0;">A stark sector gap exists: <strong style="color: #0F3D6B;">banks remediate in 11 days, retail in 10</strong> — while insurance and pharmaceutical firms average over 40 days, creating materially different risk profiles between sectors that regulators and boards increasingly need to account for as autonomous AI exploitation compresses the time-to-attack to a single day.</p>

</div>

<div style="display: flex; gap: 14px; align-items: flex-start;">

<span style="display: inline-block; min-width: 22px; height: 22px; background: #E8A020; color: #fff; border-radius: 50%; text-align: center; line-height: 22px; font-family: 'Georgia', serif; font-size: 12px; font-weight: bold; flex-shrink: 0; margin-top: 2px;">4</span>

<p style="font-family: 'Georgia', serif; font-size: 16px; line-height: 1.75; color: #2C2C2C; margin: 0;"><a href="https://www.intruder.io" style="color: #1B6CA8; text-decoration: underline;">Intruder</a>'s central recommendation is that <strong style="color: #0F3D6B;">attack surface reduction must precede patching</strong> as the primary security discipline — removing services from internet exposure entirely rather than racing to patch them after AI-powered adversaries have already begun automated scanning. Since 2015, Intruder has helped customers remove over 133,000 exposures. Access the full report at <a href="https://www.intruder.io/blog/attack-surface-exposures" style="color: #1B6CA8; text-decoration: underline;">intruder.io</a>.</p>

</div>

</div>

</div>

<!-- Closing -->

<p style="font-family: 'Georgia', serif; font-size: 18px; line-height: 1.9; color: #2C2C2C; margin: 0 0 16px 0;">

The <a href="https://www.intruder.io/blog/attack-surface-exposures" style="color: #1B6CA8; text-decoration: underline;">2026 Attack Surface Management Index</a> challenges a foundational assumption in enterprise security: that the primary question is "what vulnerabilities exist?" rather than "what should not be internet-facing at all?" In an environment where autonomous AI models can discover and exploit vulnerabilities in a single day, and where a quarter of organisations are leaving databases exposed that require no CVE to compromise, the remediation-focused model of security is not keeping pace with the threat. The organisations that will manage exposure risk most effectively are those that treat attack surface reduction — removing services from the internet entirely — as a first-order security discipline rather than an afterthought to the vulnerability management programme.

</p>

<p style="font-family: 'Georgia', serif; font-size: 18px; line-height: 1.9; color: #2C2C2C; margin: 0;">

To read the full 2026 Attack Surface Management Index and benchmark your organisation's exposure profile, visit <a href="https://www.intruder.io" style="color: #1B6CA8; text-decoration: underline;">intruder.io</a>.

</p>

</div>

<!-- TAGS FOOTER -->

<div style="padding: 26px 48px 32px 48px; background: #F7F7F4; border-top: 1px solid #E4E4DC;">

<div style="font-family: 'Georgia', serif; font-size: 11px; color: #999; text-transform: uppercase; letter-spacing: 2px; margin-bottom: 14px;">Tags</div>

<div style="display: flex; flex-wrap: wrap; gap: 8px;">

<span style="display: inline-block; border: 1px solid #1B6CA8; color: #1B6CA8; font-family: 'Georgia', serif; font-size: 12px; padding: 5px 16px; border-radius: 20px; background: #EAF3FB;">Attack Surface Management</span>

<span style="display: inline-block; border: 1px solid #E8A020; color: #B87A10; font-family: 'Georgia', serif; font-size: 12px; padding: 5px 16px; border-radius: 20px; background: #FEF5E7;">MySQL Exposure</span>

<span style="display: inline-block; border: 1px solid #1B6CA8; color: #1B6CA8; font-family: 'Georgia', serif; font-size: 12px; padding: 5px 16px; border-radius: 20px; background: #EAF3FB;">Exposure Management</span>

<span style="display: inline-block; border: 1px solid #E8A020; color: #B87A10; font-family: 'Georgia', serif; font-size: 12px; padding: 5px 16px; border-radius: 20px; background: #FEF5E7;">Database Security</span>

<span style="display: inline-block; border: 1px solid #1B6CA8; color: #1B6CA8; font-family: 'Georgia', serif; font-size: 12px; padding: 5px 16px; border-radius: 20px; background: #EAF3FB;">Vulnerability Remediation</span>

<span style="display: inline-block; border: 1px solid #E8A020; color: #B87A10; font-family: 'Georgia', serif; font-size: 12px; padding: 5px 16px; border-radius: 20px; background: #FEF5E7;">AI-Driven Exploitation</span>

<span style="display: inline-block; border: 1px solid #1B6CA8; color: #1B6CA8; font-family: 'Georgia', serif; font-size: 12px; padding: 5px 16px; border-radius: 20px; background: #EAF3FB;">Midmarket Security</span>

<span style="display: inline-block; border: 1px solid #E8A020; color: #B87A10; font-family: 'Georgia', serif; font-size: 12px; padding: 5px 16px; border-radius: 20px; background: #FEF5E7;">Ransomware Prevention</span>

</div>

</div>

<!-- Bottom accent bar -->

<div style="height: 4px; background: linear-gradient(90deg, #E8A020 50%, #1B6CA8 50%);"></div>

</div>