Skip to main content
Industry · Manufacturing and industrial groups

A manufacturing group is not one estate. It is every estate it has ever acquired.

ShadowMap rebuilds the external estate of each operating company, plant and acquired brand from outside — starting from an apex domain rather than from a list somebody has to compile — and attributes every finding to the entity that owns it. The same outside-in methodology runs across the supplier base, so a group with more suppliers than it could ever send a questionnaire to still has a dated read on the ones that matter.

“Dozens of plants and acquired entities, each with their own IT, most of them invisible from the centre.”

No agent
Nothing installed on a plant network or an OT segment
Seedless
Discovery starts from an apex domain, not a site inventory
CERT-In
Empanelled security auditor since 2008 — Security Brigade

The shape of the problem

A group estate is a set of estates joined by a balance sheet

Nothing about a manufacturing group's exposure is exotic. What is different is that no function has ever been able to see all of it at once, and the reason is structural rather than negligent.

Each plant was commissioned in its own decade, with its own local connectivity, a site domain somebody in facilities registered, and a maintenance interface the machine builder made a condition of the warranty. Each acquisition arrived with its own IT function, its own domains and certificates, and its own working definition of decommissioned — and the integration programme reached the ERP years before it reached a marketing subdomain nobody in the acquiring company had ever heard of. Around all of it sits a supplier base large enough that a questionnaire programme covers a fraction of it, and everybody involved knows which fraction. The answer to that is not another inventory project. An inventory that plant IT has to populate is usually the thing that has already been attempted, and it fails for the same reason each time: it asks the people with the least capacity to describe the estate that the centre cannot see. Outside-in discovery inverts the request. Nobody is asked what they own; the estate is asked what answers, and the register is built from the replies.

Scope

What “the estate” means when the estate includes a plant

Outside-in discovery has a hard edge, and in manufacturing it is the first thing a buyer needs stated rather than the last. Every asset falls into one of four classes. Three of them are ours, and the fourth row is where we say what we do not touch.

What “the estate” means when the estate includes a plant
StateWhat it meansWhat follows
Attributed to a group entity A host, service, certificate, cloud container or mobile binary answering from the public internet that discovery has resolved to one of your operating companies, plants or acquired brands. Monitored continuously, and tested where it is safe and authorised. This is the queue that moves first.
Reachable, and not yours A system carrying your plant, brand or product names that resolves to an integrator, a machine builder or a logistics partner — published from their infrastructure, under their control. Surfaced with the third party named and the date attached, and routed to them as a confirm-and-fix. Nothing is probed: we hold no authorisation over another company's estate and do not assume one.
A remote-access path into a site The vendor support portal opened for a machine builder, the site VPN concentrator, the gateway in front of an engineering workstation, the maintenance interface published so a technician could reach it from home. External by definition, because it has to be. In scope, and the class that most often changes a plan. What sits behind the door is a separate question we do not answer by walking through it.
The plant floor itself Controllers, operator interfaces, historians and anything else on a segment that does not answer from the public internet. Out of scope, deliberately — nothing is installed, no industrial protocol is spoken and no plant traffic is observed. Not covered, and stated as not covered. The exception is worth reading twice: an operator interface that does answer from the public internet is not on this row. It is on the first one, and it is a finding.
Key
  • In scope, tested where authorised
  • Observed, routed to the supplier
  • Outside what we do
  • External, and usually decisive

A worked example

Two thousand repositories, and the two hundred that reached an analyst

One anonymised customer estate, as of August 2026, scoped to code-repository monitoring alone and published as a representative example rather than as a platform average. It is not a figure to expect, and it is never averaged with the other example we publish. What travels between groups is the shape of the funnel, not the numbers at either end of it — and it is not an accuracy claim, because we publish no such figure.

Anonymised customer estate, manufacturing

Code-repository monitoring across a multi-plant group

What the group believed its code footprint was
Close to nothing. Software arrived with the machine builders, the systems integrators and the contract engineering firms who supplied it, so the group did not consider itself to have a public code presence at all.
What the first pass across public sources returned
Roughly two thousand public repositories mentioning the group or one of the brands and subsidiaries beneath it. Handed to a security function of the size a manufacturing group actually runs, that is not a queue — it is a reason to stop looking, which is exactly what raw scanner output is for.
What reached an analyst once AI Review had ordered the queue
Roughly two hundred actionable repositories: a ten-to-one reduction, and what survived is mostly genuine contractor and integration code, published under accounts no control inside the group administers. That is the manufacturing shape of this funnel rather than the platform average — a group whose matches are largely real supplier code has a higher signal density to begin with, so more of it survives review than in an estate whose name simply collides with a lot of unrelated public code. Neither ratio is offered as a prediction of what a first pass across yours would return.

How a group programme is stood up

Entities first, assets second, and nobody is asked for a list

The order matters here in a way it does not in a single-entity estate. Each step is bounded by the one before it, and a step taken out of sequence produces findings that nobody in the group is accountable for.

Where each question lands

Five questions a group security function is actually asked

None of this is a manufacturing-specific product. What changes by sector is which question arrives first, and where the evidence for the answer already sits. The right-hand columns are the pages that carry it.

The questionWhat answers itWhere the job is written up
"What do we actually own, across every plant and every company we have bought?" Attack Surface Management Seeing every subsidiary from one place
The estate is rebuilt from outside every 24 hours, which is what makes the answer dated rather than remembered. An acquired brand still serving from its original domains and original certificates is a routine discovery finding, not an edge case.
"There are more suppliers than we could ever send a questionnaire to. Which of them could an attacker reach us through?" Third-Party Risk Management Onboarding a vendor without waiting on a questionnaire
The questionnaire programme stays. It answers things nothing outside-in can answer, and an attestation carries a signature that an observation cannot. What changes is that the tier being questionnaired is chosen from observed exposure rather than from contract value.
"We are buying a plant next quarter. What are we inheriting?" Attack Surface Management, run against the target Assessing a target before you sign
Nothing about this requires the target to take part, which is the only reason it is usable before a deal closes. It is also the cheapest moment to find an inherited estate — before it becomes yours to explain.
"Our integrators and contract engineers write our code. Where has it ended up?" Data Exposure Monitoring Responding to an exposed secret
Public sources only — no agent, no repository connection, nothing authenticated into. That boundary cuts both ways: a private repository made public is visible from the moment it is public, and not one minute before. The worked example above is this row.
"Which authority published something this quarter that changes what we have to evidence?" Regulatory Intelligence Programme context, and a dated monitoring record
In India the instrument most groups ask about is CERT-In's direction of 28 April 2022 and its six-hour reporting window; in the European Union it is NIS2, whose scope annexes name manufacturing sub-sectors directly. Whether either binds a given entity in your group is a determination for your compliance function and its advisers. What ShadowMap holds is the dated monitoring record underneath that determination — never the determination itself, and never a compliance opinion.

"What do we actually own, across every plant and every company we have bought?"

What answers it
Attack Surface Management
Where the job is written up
Seeing every subsidiary from one place

The estate is rebuilt from outside every 24 hours, which is what makes the answer dated rather than remembered. An acquired brand still serving from its original domains and original certificates is a routine discovery finding, not an edge case.

"There are more suppliers than we could ever send a questionnaire to. Which of them could an attacker reach us through?"

The questionnaire programme stays. It answers things nothing outside-in can answer, and an attestation carries a signature that an observation cannot. What changes is that the tier being questionnaired is chosen from observed exposure rather than from contract value.

"We are buying a plant next quarter. What are we inheriting?"

Where the job is written up
Assessing a target before you sign

Nothing about this requires the target to take part, which is the only reason it is usable before a deal closes. It is also the cheapest moment to find an inherited estate — before it becomes yours to explain.

"Our integrators and contract engineers write our code. Where has it ended up?"

What answers it
Data Exposure Monitoring
Where the job is written up
Responding to an exposed secret

Public sources only — no agent, no repository connection, nothing authenticated into. That boundary cuts both ways: a private repository made public is visible from the moment it is public, and not one minute before. The worked example above is this row.

"Which authority published something this quarter that changes what we have to evidence?"

What answers it
Regulatory Intelligence
Where the job is written up
Programme context, and a dated monitoring record

In India the instrument most groups ask about is CERT-In's direction of 28 April 2022 and its six-hour reporting window; in the European Union it is NIS2, whose scope annexes name manufacturing sub-sectors directly. Whether either binds a given entity in your group is a determination for your compliance function and its advisers. What ShadowMap holds is the dated monitoring record underneath that determination — never the determination itself, and never a compliance opinion.

Questions buyers actually ask

Before you evaluate this

Does any of this touch the plant floor?

No, and it is worth being exact about why. ShadowMap works from outside the perimeter: nothing is installed, no agent runs anywhere in your environment, no industrial protocol is spoken and no plant traffic is observed. A controller on a segment that does not answer from the public internet is invisible to us and stays that way. What is in scope is the part of a plant that faces the internet — the remote-support portal a machine builder asked you to open, the site VPN concentrator, the gateway in front of an engineering workstation, the maintenance interface somebody published so a technician could work from home. Those are external assets and they are discovered as such. The one line worth reading twice is on the ledger above: an operator interface that is answering from the public internet is not out of scope, it is a finding.

Our plants and subsidiaries will not hand over an asset list. Does that stop this?

It is the reason to run it. Discovery is seedless — it starts from an apex domain and works outward through domain and certificate records, address-range registration and what the public internet actually answers, so no cooperation from an entity's IT team is needed and no scope file has to be negotiated with anyone. In a group the reliable list is the register of legal entities rather than the register of assets, because the first one is maintained by a function with a reason to keep it accurate. Start from that, and let discovery produce the asset side of it.

We have thousands of suppliers. You are not going to monitor all of them.

Correct, and we would not propose it. Twenty vendors are included, and more can be added, but the count is rarely the interesting part of the conversation. The tier that matters is almost never the tier procurement built, because that one is ordered by spend and exposure is not: a machine builder with a remote-support tunnel into four plants outranks a far larger contract with no connectivity behind it. The first monitoring cycle usually reshapes that tier, and the concentration view — how many nominally independent suppliers resolve to the same hosting, the same upstream supplier, the same handful of data centres — tends to be the part a manufacturing board reacts to, because it is a continuity finding as much as a security one.

Why would code-repository monitoring matter to us? We do not write software.

Most manufacturing groups open with this, and most of them are describing the wrong boundary. You may employ no developers, but your machine builders, systems integrators and contract engineering firms do, and their work carries your network layout, credentials for the systems they were integrating and sometimes the configuration of the equipment itself. That code lands in public repositories under accounts you do not administer, which means no control inside your organisation reaches it — push protection governs the repositories you own, and a contractor's personal namespace is not one of them. The worked example on this page is precisely that shape: the group in it opened from the same position.

Start with the entity you know least about

One apex domain from one operating company, plant or acquired brand. Two business days, a written snapshot, no cooperation required from that entity and no call needed to get it.