Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security What should security teams do first when they…
Cyber Security

What should security teams do first when they suspect SolarWinds Orion login endpoints are exposed on the internet?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 18, 2026 Domain: Cyber Security

Start by identifying whether the Orion login portal is externally reachable, then confirm where it appears inside the environment. Use known endpoint patterns such as the login path, page title, and favicon hash to narrow the search. From there, validate exposure across internet-facing assets and internal domains so the team can scope monitoring, containment, and remediation without assuming the product is only used behind the firewall.

How to scope exposure without assuming Orion is internal-only

The first task is to prove where the login endpoint is actually reachable, because Orion deployments are often reachable from both the public internet and internal networks. Use endpoint patterns that are stable enough for discovery, such as the login path, page title, and favicon hash, then cross-check those indicators against internet-facing assets and internal domains. That gives you a reliable scope before you start containment or remediation.

Once you have a candidate set, treat each match as a visibility and exposure problem, not just a web search result. An externally reachable login page can indicate a management interface that was published intentionally, left exposed by mistake, or mirrored across environments in ways that are easy to miss if you only inspect one perimeter.

Why endpoint verification is the right first control move

Endpoint verification matters because it separates “we think Orion is internal” from “we can show exactly where Orion can be reached.” That distinction changes the response: an exposed management portal needs immediate asset scoping, log review, and access-path review, while an internal-only instance usually shifts attention to segmentation, inventory, and administrative reachability. The goal is to identify every live exposure path before assumptions harden into blind spots.

Use the same discovery logic across the estate, including DNS, reverse proxies, load balancers, and any asset inventory that may map the application to multiple hostnames. If the portal appears under an unexpected domain or in an environment that was not supposed to host it, that is a signal to widen the investigation rather than narrow it.

Helpful references for this kind of validation include The 52 NHI breaches Report, which shows how exposed access points and stolen credentials often combine into broader compromise paths, and OWASP Non-Human Identity Top 10, which is useful when the exposed portal is part of a wider access and privilege surface.

What security teams should verify next

After you confirm reachability, verify whether the instance is internet-facing by design, whether it is covered by monitoring, and whether the same login interface exists in other business units, regions, or hosted environments. The point is not to find one exposed host and stop. It is to build a complete exposure picture that supports containment decisions, credential review, and notification scoping.

  • Confirm the external hostname, internal hostname, and any alternate virtual hostnames that resolve to the same Orion login surface.
  • Check whether the portal sits behind VPN, IP allowlisting, or a reverse proxy, and whether those controls are actually enforcing the intended boundary.
  • Review whether administrative access, service access, or integration accounts touch the portal or adjacent Orion components.
  • Preserve evidence of exposure, since a portal that is now closed may still require historical investigation and log correlation.

For control mapping and incident response discipline, FIRST is useful for incident coordination practice, while NIST Cybersecurity Framework 2.0 helps teams connect discovery, protection, detection, response, and recovery once exposure has been confirmed.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS 1 — Inventory and Control of Enterprise AssetsFind exposed Orion endpoints by inventorying internet-facing assets and hostnames.
Recommendation — Inventory all Orion-hosting assets and remove any unintended public exposure paths.
NIST CSF 2.0ID.AM — Asset ManagementExposure scoping depends on knowing where the portal exists across the environment.
PR.AC — Access ControlExternally reachable login endpoints require boundary and access-path validation.
DE.CM — Continuous MonitoringDiscovery and validation of exposed login surfaces relies on monitoring and detection coverage.
Recommendation — Maintain an accurate asset inventory that maps Orion instances to external and internal reachability. Enforce and verify the access controls that should prevent public reachability of administrative portals. Monitor for unexpected external exposure of management interfaces and login endpoints.

Practitioner Guidance

What to prioritise: Treat discovery as a containment input, not a reconnaissance exercise. If Orion is externally reachable, prioritise scoping all exposed instances and adjacent administrative paths before debating whether the exposure was intentional.

What to verify: Verify that the same login page signature does not exist on unmanaged domains, test environments, or proxy layers that inventory systems missed. A single exposed portal often signals broader inconsistencies in asset tracking and boundary enforcement.

Common mistake: Teams often stop after finding one public hostname and assume the rest of the environment is equivalent. In practice, Orion exposure can vary by region, business unit, and routing layer, so one confirmed match should trigger a full estate-wide validation.

Practitioner takeaway: The important first decision is not whether Orion should have been public, it is whether you can prove every place it is reachable before you choose monitoring, containment, or remediation.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 18, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org