There is a specific kind of asset that shows up in almost every assessment. It resolves to your organisation. It was built for a real reason. The person who built it has left. Nobody has logged into it in two years, and it is still serving traffic.
Where it comes from
Shadow surface is not usually shadow IT in the rebellious sense. It is ordinary work that outlived its owner. A staging environment that was convenient to expose during a launch. A subsidiary acquired with its own DNS. A vendor portal set up for one project in 2021.
Why inventories miss it
Because inventories are written by people who know what they built. Discovery has to work from the outside in: registrars, certificate transparency, passive DNS, cloud control planes. If your inventory is a spreadsheet maintained by the people who remember, it is a record of institutional memory, not of reality.
- Certificate transparency finds names nobody registered in your CMDB.
- Cloud control planes find resources created outside your pipeline.
- Identity providers find application registrations for apps that no longer exist.
- Mail authentication records find relays from acquisitions you forgot to integrate.
What to do on the day you find it
Resist the urge to switch it off immediately. Something is usually still calling it. Establish what talks to it, who benefits, and whether it holds data. Then retire it on a date, with a named owner, like any other change.
The fastest way to cause an outage is to delete a forgotten system on the same afternoon you find it.
Then stop it happening again
Ownership resolution at discovery time is the durable fix. Every new asset gets a proposed owner within a day of appearing, and a human confirms it. That is a small, boring process, and it is the difference between an inventory that decays and one that does not.
Every company, figure and quotation in this article is fictional sample content written for the template.