| Is the provider’s internet-facing estate still what it was when we assessed it? | Every hostname answering from the public internet across the provider apex domains you nominate, resolved without the provider taking part — each carrying the date it entered scope and, where it has gone, the date it left. | Anything the provider runs that never answers from the internet. A private estate has no outside-in signature at all, and asking a monitoring record about it is asking the wrong instrument. | Attack Surface Management |
| Attribution is the load-bearing part, not discovery. A host tied to the wrong company puts a finding on a provider’s file that the provider can disprove in a meeting, and a monitoring record that has been shown to be wrong once is discounted wholesale afterwards. Each host carries the evidence that ties it to the provider rather than to a company with a similar name. |
| Has anything changed since the last review? | Movement in that estate as a dated finding: a host that appeared, a service that opened, a software version that moved, an administrative interface that stopped presenting a second factor, an estate that grew after an acquisition nobody announced. | Why it changed. The record states what became observable and on which date; the reason belongs to the provider and is something to ask for, never something to infer from outside. | Third-Party Risk Management |
| This is the row that answers “when did you know”, and it is the reason a change is published as a dated finding with an owner rather than as a movement in a score. A grade going from B to D is not a finding — it is only the reason somebody looked. |
| Who does the provider itself actually depend on? | The hosting, DNS, mail, certificate and authentication providers each monitored provider resolves to, compared across the whole monitored portfolio rather than read one file at a time — so a shared upstream becomes a dated, checkable fact. | The contractual subcontracting chain. A resolution path shows a technical dependency. It does not show who holds the contract, what that contract permits, or which of your functions is sitting on it. | Third-Party Risk Management |
| The dependency you have no contract with is still a dependency, and it is the one a disclosure list structurally cannot show you — a provider can only disclose the arrangements it holds directly. Concentration is worked further down this page. |
| Are credentials belonging to the provider circulating? | Credential records attributed to the provider’s domains in stealer-log and breach material, dated to when they entered the corpus rather than to when the underlying breach is said to have happened. | Whether the provider has rotated them, and whether they still open anything on the provider’s systems. Testing a third party’s estate needs authorisation from the party that owns it, which in a provider relationship is not yours to give. | Dark Web Monitoring |
| There is one narrow exception and it belongs beside the claim rather than in a footnote: where an exposed provider-staff identity maps to an account on your own systems — a contractor remote-access portal, a shared tenancy, a federated login — that account is your estate, and it is validated under the same audit trail as any first-party finding. |
| Did the monitoring actually run, over what scope, and what was done about what it found? | Per-provider detection timestamps and the attributed inventory each run covered, the disposition your team recorded against each finding with the assignee and the timestamps, and the privileged changes made to the monitoring configuration itself. | Any confirmation that the record satisfies an obligation. ShadowMap produces the artefact. Whether the artefact answers a particular clause is a judgement for your auditor and your own advisers, and this page is not that judgement. | Regulatory Intelligence |
| The record deliberately includes the occasions your own service levels were missed and the surfaces that were examined and returned nothing. A monitoring trail showing only the months that went well is not evidence — an examiner who cannot find a single miss in a year stops trusting the whole set. |
| Is the provider’s internal control environment sound? | Nothing — and this row matters more than the five above it. There is no outside-in signature for governance, segregation of duties, change management, personnel screening, backup and restore testing, or the resilience testing a provider runs on itself. | All of it. Attestations, audit reports, contractual audit and access rights, and the provider’s own testing carry this half of the question, and nothing on this page replaces them or reduces how much of the work they are. | — |
| Outside-in monitoring is evidence about the surface an attacker meets. It is not assurance about the controls behind that surface, and a programme that lets one stand in for the other has quietly swapped the thing for a proxy of it. Stating the boundary is what makes the rest of this table usable — a guide that blurs it is one question away from being unpicked in front of the people you least want to be unpicked in front of. |