← All terms

Attack Vector

An attack vector is the specific path an attacker uses to get in — an exploit, a stolen password, or, most often, a message aimed at a person.

An attack vector is the specific route an attacker uses to gain unauthorized access to a system or organization — the how of an intrusion. Vulnerability exploits, stolen credentials, malicious attachments, compromised vendors, and infected USB drives are all vectors. The sum of every vector an organization exposes is its attack surface, and the most consequential shift of the past decade is where that surface now concentrates: with the Verizon DBIR attributing 62% of breaches to the human element, the busiest routes now run through people rather than software.

How it works

Attackers pick vectors by cost and yield, and they enumerate before they strike. On the technical side that means scanning for exposed services and unpatched software. On the human side it means OSINT: harvesting names, roles, and email patterns from LinkedIn and press releases to work out who approves payments, who administers identity, and who joined last month. Each employee adds addressable entry points — an inbox, a phone number, MFA push prompts, help-desk tickets — and every unsanctioned tool they sign up for adds more (shadow IT is a set of vectors the security team cannot even see). Vectors also chain: a phishing email delivers a credential harvester, the stolen password enables an MFA-fatigue push flood, and a help-desk call finishes the job. The initial vector named in a breach report is usually just the first link.

How to defend against it

You cannot defend a vector you have not mapped, and most organizations map their machines far better than their people. Reduce the technical routes with patching, least privilege, and decommissioning what is unused. Then apply the same discipline to the human layer: inventory who holds risky permissions and money-moving authority, identify which roles are most targeted, and measure how they actually respond to the vectors attackers really use — through simulation across email, SMS, voice, and QR channels, not email tests alone. A quantified human risk score per team turns the human side of the map from an anecdote into a managed metric — the foundation of human risk management.

Related terms

Social EngineeringSocial engineering is the practice of manipulating people into giving up confidential information, access, or taking actions that compromise security.PhishingPhishing is a social engineering attack that uses fraudulent emails, websites, or messages to trick people into revealing sensitive information or installing malware.OSINT (Open-Source Intelligence)OSINT is intelligence gathered from publicly available sources. Attackers use it to research targets and build convincing social engineering pretexts.Shadow ITShadow IT is technology used without IT approval — unsanctioned apps, accounts, and AI tools that expand attack surface outside security's visibility.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo