# Sociotechnical Attack Surface
**Entity class:** Adversarial-systems concept
## Definition
A **sociotechnical attack surface** is the full set of exploitable conditions across people, organizations, software, identities, finance, transportation, communications, buildings, procedures, supply chains, beliefs, and institutional boundaries. Modern attacks can chain several layers into one path.
The human layer is literal security architecture. A person may be a [[wiki/Threat Source|threat source]], an [[wiki/Attack Vector|attack vector]], an authorized [[wiki/Insider Threat|insider]], or a [[wiki/Human Vulnerability Node|vulnerability-bearing node]] whose placement and access make other assets reachable. In this sense, a [[wiki/Human CVE|human CVE]] is not a software record applied to a person; it is the functional recognition that biology, cognition, trust, credentials, and social position can form an exploitable condition inside the system being protected.
## Relevance to this collection
It is the shared object of [[wiki/Counterterrorism-Cybersecurity Convergence|Counterterrorism–Cybersecurity Convergence]], [[wiki/Attack Surface|Attack Surface]], [[wiki/Novel Attack Chain|Novel Attack Chain]], [[wiki/Adversarial Adaptation|Adversarial Adaptation]], and [[wiki/Dangerous Individual|Dangerous Individual]].
## Relationships
- **master collection:** [[collections/Terrorism, Counterterrorism, and the Intelligence Environment|Terrorism, Counterterrorism, and the Intelligence Environment]].
- **convergence:** [[wiki/Counterterrorism-Cybersecurity Convergence|Counterterrorism–Cybersecurity Convergence]].
## Sources / Provenance
- [FBI, “Keeping America Secure in the New Age of Terror,” April 26, 2016](https://www.fbi.gov/news/speeches-and-testimony/keeping-america-secure-in-the-new-age-of-terror).
**As of:** 2026-09-23