A recent report found that 74% of organizations have suffered security incidents tied to unknown or unmanaged assets. If that number surprisesprises you, it shouldn't. As businesses grow, migrate to the cloud, acquire other companies, and cycle through development projects, their digital footprint expands in ways that IT teams rarely track completely. The assets left behind do not disappear.
Managing a sprawling attack surface is difficult, and the assets most likely to be forgotten are often the ones that were never added to an inventory in the first place. Subdomains spun up for a product launch, staging environments left running after a deployment, or configuration files accidentally pushed to a public repository are all classic examples. They were never meant to be permanent, but things happen. After a while employees change jobs, taking siloed knowledge of derelict assets along with them.
How Abandoned Assets Become Liabilities
When a company migrates infrastructure or completes a merger, the checklist tends to focus on what needs to move, not on what should be decommissioned. A subdomain like legacy-portal.example.com might have served a purpose three years ago, but if the DNS record still resolves and the underlying application is no longer patched or monitored, it becomes an open door. Attackers routinely scan for exactly this kind of exposure, and they do it at scale using automated tools that map the internet continuously.
Subdomain takeover is one of the more well-documented risks in this category. If a subdomain points to a third-party service (a cloud storage bucket, a hosting platform, or a SaaS tool) that has since been deprovisioned, an attacker can often claim that service and serve content from the trusted domain. This technique has been used to steal session cookies, host phishing pages, and distribute malware to unsuspecting users who have no reason to distrust a URL bearing a company's own name.
Exposed configuration files and open ports present a different but equally serious problem. A misconfigured S3 bucket containing environment variables, an .env file accessible from a forgotten development server, or a database port left open after a cloud migration can hand an attacker credentials, API keys, or direct database access without requiring any exploitation of a vulnerability. These are not sophisticated attacks. They are the result of routine oversights that compound over time.
Real breaches have started this way. The 2019 Capital One breach, one of the most significant data incidents in U.S. financial history, originated through a misconfigured web application firewall on a cloud-hosted server. The Microsoft Power Apps exposure in 2021 resulted in tens of millions of records being publicly accessible due to default configuration settings that organizations had not reviewed. While the specifics differ, both incidents share a common thread: an asset that did not receive the same scrutiny as production systems became the weakest link.
Why Traditional Cybersecurity Tools Don't Help
Most organizations have some form of vulnerability scanning in place, but those scans typically target known assets on a defined scope. If an asset is not in the inventory, it is not being scanned. This is the core of the problem. Security tools are only as comprehensive as the asset list they operate against, and that list almost always lags behind reality.
Mergers and acquisitions make this significantly worse. When an organization absorbs another company's infrastructure, it inherits every forgotten subdomain, every unmaintained application, and every misconfiguration that came with it. Security teams often do not have full visibility into what they have acquired for months, and attackers are not waiting for the integration to be complete.
External attack surface monitoring addresses this gap directly. Tools like NordStellar continuously scan the open internet for assets associated with an organization, including subdomains, IP ranges, exposed services, and leaked credentials, whether or not those assets appear in any internal inventory. When a new exposure is discovered or an existing asset changes in a way that introduces risk, the platform flags it automatically. This gives security teams the visibility to act before an attacker does, rather than discovering the problem during an incident investigation.
Interested in learning more about the tools we use to stop attacks before they happen? Register for a live demo of NordStellar and learn how we pinpoint threats before they evolve into incidents.