Field notes

The asset you forgot is the one they found: a field note on shadow surface

Across a year of exposure assessments, the systems that mattered most were rarely the ones on the inventory. They were the staging clone, the acquired subsidiary's mail relay, and the portal a departed team stood up in 2021.

There is a specific kind of asset that shows up in almost every assessment. It resolves to your organisation. It was built for a real reason. The person who built it has left. Nobody has logged into it in two years, and it is still serving traffic.

Where it comes from

Shadow surface is not usually shadow IT in the rebellious sense. It is ordinary work that outlived its owner. A staging environment that was convenient to expose during a launch. A subsidiary acquired with its own DNS. A vendor portal set up for one project in 2021.

Why inventories miss it

Because inventories are written by people who know what they built. Discovery has to work from the outside in: registrars, certificate transparency, passive DNS, cloud control planes. If your inventory is a spreadsheet maintained by the people who remember, it is a record of institutional memory, not of reality.

  • Certificate transparency finds names nobody registered in your CMDB.
  • Cloud control planes find resources created outside your pipeline.
  • Identity providers find application registrations for apps that no longer exist.
  • Mail authentication records find relays from acquisitions you forgot to integrate.

What to do on the day you find it

Resist the urge to switch it off immediately. Something is usually still calling it. Establish what talks to it, who benefits, and whether it holds data. Then retire it on a date, with a named owner, like any other change.

The fastest way to cause an outage is to delete a forgotten system on the same afternoon you find it.

Then stop it happening again

Ownership resolution at discovery time is the durable fix. Every new asset gets a proposed owner within a day of appearing, and a human confirms it. That is a small, boring process, and it is the difference between an inventory that decays and one that does not.


Every company, figure and quotation in this article is fictional sample content written for the template.

Next step

See your own surface the way an attacker reads it

A four-week proof of value connects one cloud account, your DNS and your identity provider, and ends with a written readout of what was found.

Book a walkthroughOpen the console demo

Illustrative product data. Nothing on this site performs a live scan.