Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› How should security teams centralise attack surface management…
Governance, Ownership & Risk

How should security teams centralise attack surface management when digital assets are spread across departments and shadow IT?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 28, 2026 Domain: Governance, Ownership & Risk

Security teams should start by building a single inventory that covers domains, subdomains, IPs, applications, landing pages, portals, and forms, then continuously reconcile it against what is actually internet-facing. The practical goal is not just discovery, but ownership and change control. Without that baseline, shadow IT, exposed services, and forgotten assets remain invisible to monitoring and remediation efforts.

Why centralised attack surface management depends on a trustworthy asset inventory

Centralisation works only when security teams treat the inventory as the control plane, not as a reporting output. If different departments manage their own domains, apps, or landing pages, the first job is to normalise naming, ownership, and business purpose so every asset can be tied back to a responsible team. That creates the basis for change control, remediation routing, and exception handling.

For internet-facing assets, the inventory must be continuously reconciled against what is actually live, because shadow IT often appears first as an unmanaged subdomain, a forgotten portal, or a form exposed by a third party. A central list that is not verified against live exposure will drift quickly and give a false sense of coverage.

What needs to be included when assets are spread across departments

The practical scope is broader than classic host or application discovery. To centralise attack surface management effectively, the catalogue should include domains, subdomains, IPs, applications, landing pages, portals, and forms, along with the owner, environment, and change path for each. That scope matters because attackers do not care which department created the asset, only whether it is reachable, misconfigured, or forgotten.

A useful central model also distinguishes between assets that are intentionally public and those that became public by accident. That distinction helps security teams decide whether a finding belongs in remediation, exception management, or decommissioning. It also prevents teams from wasting effort on assets that are expected to be exposed but still need controls, such as authentication, logging, or monitoring.

How to keep ownership and remediation from breaking down

Centralisation fails when discovery is separated from accountability. The inventory should therefore carry a clear owner, a support contact, and a documented path for approving changes, because remediation is slower and less reliable when findings have to be manually routed after the fact. The 52 NHI Breaches Report reinforces the broader lesson that unmanaged access paths and forgotten credentials turn visibility gaps into compromise opportunities.

Teams should also define a rule for who can create internet-facing assets and who can approve them. Without that control, shadow IT will keep reappearing in new namespaces, temporary campaigns, and third-party hosted forms, even if the security team keeps finding and removing the old ones. Centralisation is therefore as much a governance process as a discovery process.

Risk and Threat Considerations

When attack surface management is fragmented, the main risk is not just incomplete inventory, but delayed response to exposed assets that nobody owns. Untracked services create silent exposure for attackers, because forgotten portals, stale DNS records, and unmanaged forms often remain reachable long after the business thinks they are retired.

Failure mechanism: Ownership gaps break the link between detection and remediation, so discovered assets do not get fixed, retired, or monitored consistently. As shadow IT accumulates, the organisation loses confidence in its view of what is externally exposed.

Impact: The result is a larger and less governable internet-facing footprint, higher likelihood of misconfiguration or abandoned access paths, and slower containment when an exposed asset is abused.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5, CSA Cloud Controls Matrix and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0ID.AM-01 — Physical Devices and Systems InventoryCentralised attack surface management depends on a complete asset inventory.
GV.OC-01 — Organizational ContextOwnership and business purpose determine who can approve and remediate assets.
PR.AA-01 — Identities and Credentials Issued, Managed, Verified, Revoked, and AuditedShadow IT often becomes risky when unmanaged assets lack controlled access paths.
Recommendation — Maintain a continuously reconciled inventory of externally exposed assets. Assign business ownership for every internet-facing asset. Verify access paths and revoke any unapproved exposure promptly.
NIST SP 800-53 Rev 5CM-8 — System Component InventoryThe question is fundamentally about building a trustworthy enterprise inventory.
CM-3 — Configuration Change ControlOwnership and change control are central to preventing unmanaged exposure.
Recommendation — Catalog all internet-facing components and keep the inventory current. Require approved change control for new or modified public assets.
ISO/IEC 27001:2022A.5.9 — Inventory of information and other associated assetsCentralisation requires a governed asset inventory across departments.
Recommendation — Keep an authoritative inventory of all externally reachable assets.
CSA Cloud Controls MatrixIAM — Identity and Access ManagementOwnership, approval, and controlled exposure are core governance needs.
Recommendation — Tie each exposed asset to a clear owner and approval path.
CIS Controls v8CIS-1 — Inventory and Control of Enterprise AssetsThe subject is enterprise asset discovery and control across departments.
Recommendation — Inventory every internet-facing asset and remove unknown entries.

Practitioner Guidance

What to prioritise: Start with anything that is both internet-facing and hard to explain, such as unknown subdomains, unowned portals, and externally hosted forms. Those are the assets most likely to be missed by normal change processes and the ones most likely to produce immediate exposure.

What to verify: For each asset, verify an owner, a business purpose, a deployment or change source, and whether the asset is expected to be public. If any of those fields are missing, treat the record as incomplete until the team that created or operates it confirms the details.

Practitioner takeaway: Centralised attack surface management succeeds when the inventory is treated as an operational control with ownership, change control, and continuous reconciliation, not as a one-time discovery exercise.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 28, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org