Inventory what is supposed to be public
- Primary domains and subdomains
- Cloud-hosted applications and APIs
- VPN and remote access gateways
- Email and identity endpoints
- Vendor-hosted systems using your domain
Look for forgotten exposure
Development hosts, old DNS records, stale cloud services, temporary file shares, administrative interfaces, and acquired-company assets frequently survive longer than expected.
Review identity entry points
Understand where authentication is exposed, which systems allow password-only login, where legacy protocols exist, and how MFA is enforced.
Make ownership visible
Every public service should have a business owner, technical owner, expected purpose, and lifecycle decision.
Related next step
Use this resource as a starting point, then adapt it to the systems, business constraints, and threat model that actually apply to your organization.