Skip to main content
Use case · Group and holding-company visibility

You cannot consolidate an inventory nobody ever finished.

“Twelve operating companies, each with their own IT. I cannot answer what we own, let alone what is exposed.”

A group is not one estate with twelve owners. It is twelve estates, each with its own registrar, its own cloud accounts and its own idea of what belongs on a register. ShadowMap starts at the parent apex domain and works outward through the public registration, naming and certificate record to the operating companies underneath it — so what you get is assembled from what answers, not from what each entity was willing, or able, to declare.

One apex domain
The entire input — no seed list from any operating company
Zero
Cooperation required from the entity that owns the estate
CERT-In
Empanelled auditor since 2008 — Security Brigade
Eleven days

To answer one group-wide question by asking every entity in turn

From the anonymised multinational group set out further down this page. A widely exploited flaw in a common web content-management platform was published, and the group security lead needed to know which brands and subsidiaries were running it. The question went out to local IT teams. Eleven days later the answer came back as partially completed spreadsheets at different levels of confidence — and it was stale before it was collated. That is not a vulnerability-management problem. It is an inventory problem wearing a vulnerability-management costume.

The problem underneath

Twelve partial inventories do not add up to one

The instinct is to ask each operating company for its asset register and merge them. That produces a longer register, not a truer one — because the gap in each is the same gap, and merging preserves it.

Each register is a record of intent, maintained by whoever remembered, accurate at the moment of provisioning and decaying from that moment. The centre has no instrument that reaches past it. Group security holds a policy and a quarterly return; it does not hold administrative access to a subsidiary in another jurisdiction, and in most groups it does not hold read access either. So the honest description of the position is not that the group inventory is out of date. It is that the group inventory has never existed, and the exercise that would produce it depends on the cooperation of twelve teams whose own records have the same defect. Acquisitions make it structural rather than occasional: a newly bought brand arrives with an estate nobody at the centre has ever seen, on domains nobody at the centre registered, behind certificates nobody at the centre issued — and the security migration queues behind the finance, ERP and identity migrations, sometimes for years. Divestitures leave the mirror image, where a business you sold still resolves through your DNS delegation and still presents a certificate with your organisation on it. Meanwhile the attacker enumerating your group asks nobody for anything. Their view is assembled from the public record, it is already assembled, and it does not stop at the boundary of the entities that answered your survey. Outside-in discovery is simply the decision to read the same record they read, from the same side. It needs no cooperation from the asset owner — which is the whole point when the asset owner is a subsidiary you acquired last year and whose IT director does not report to you.

What sits under the parent

Five kinds of estate, and what each one actually needs

A group is not one problem repeated twelve times. The entity types below differ in what the centre can require of them, in what the public record gives up about them, and therefore in which capability answers them. The right-hand column links to how each is done.

What sits under the parentWhat the centre can actually requireWhat outside-in discovery returnsAnswered by
A subsidiary or an acquired brand running its own infrastructure A policy, a quarterly return, and whatever the local team chooses to put in it. No administrative standing, no agent to deploy, and no realistic way to audit the answer. Every hostname that answers under the entity apex, on its original domains and its original certificates, whether or not a migration has begun. The entity is not asked, because nothing in the method requires asking. Attack Surface Management
The acquisition case is the hard one, and it is hard for a scheduling reason rather than a technical one. Security migration queues behind finance, ERP and identity, so for as long as that queue takes, the entity keeps answering on its own domains, its own certificates and its own cloud accounts. Outside-in discovery does not wait for the queue, because nothing in it depends on the entity having been onboarded first.
A platform an operating company outsourced to a supplier A contract signed by a subsidiary, on terms the centre did not negotiate, with a security schedule the centre has never read. Systems that answer for the operating company but resolve to a supplier’s infrastructure — surfaced as observed, never as tested, because authorisation over a supplier estate is not the group’s to give. Third-Party Risk Management
This is the row most group programmes discover late. Concentration is a group-level fact and cannot be seen from inside any single operating company: two subsidiaries that each chose a supplier independently, and chose the same one, have made a decision nobody in the group took.
Regional sites, campaigns and executive identity nobody registered centrally A brand guideline. Local marketing commissions through a local agency, and the agency is not in anybody’s asset register. Properties and profiles carrying the group brand across domains, social platforms and app stores, separated into the ones you published and the ones you did not — ending in removal rather than in an alert. Brand Protection
Domains a local team bought, and the look-alikes bought against them A central registrar account that roughly half the group uses. The other half pays by local card and renews by calendar reminder. The registered estate reconstructed from the public record rather than from the registrar account, alongside permutation and look-alike registrations scored for intent as they appear. Domain Monitoring
A group is a larger permutation space than a single company, and a convincing look-alike does not have to imitate the parent. It only has to imitate the smallest brand in the portfolio, which is the one with no security function of its own.
Staff credentials from an entity whose endpoints you cannot see A password policy the subsidiary attests to annually. No telemetry from their devices, and no standing to demand any. Credential and session material attributed to the entity’s domains from stealer-log and breach sources, assembled per compromised device rather than as rows, with each credential carrying an explicit state. Dark Web Monitoring

A subsidiary or an acquired brand running its own infrastructure

What the centre can actually require
A policy, a quarterly return, and whatever the local team chooses to put in it. No administrative standing, no agent to deploy, and no realistic way to audit the answer.
What outside-in discovery returns
Every hostname that answers under the entity apex, on its original domains and its original certificates, whether or not a migration has begun. The entity is not asked, because nothing in the method requires asking.

The acquisition case is the hard one, and it is hard for a scheduling reason rather than a technical one. Security migration queues behind finance, ERP and identity, so for as long as that queue takes, the entity keeps answering on its own domains, its own certificates and its own cloud accounts. Outside-in discovery does not wait for the queue, because nothing in it depends on the entity having been onboarded first.

A platform an operating company outsourced to a supplier

What the centre can actually require
A contract signed by a subsidiary, on terms the centre did not negotiate, with a security schedule the centre has never read.
What outside-in discovery returns
Systems that answer for the operating company but resolve to a supplier’s infrastructure — surfaced as observed, never as tested, because authorisation over a supplier estate is not the group’s to give.

This is the row most group programmes discover late. Concentration is a group-level fact and cannot be seen from inside any single operating company: two subsidiaries that each chose a supplier independently, and chose the same one, have made a decision nobody in the group took.

Regional sites, campaigns and executive identity nobody registered centrally

What the centre can actually require
A brand guideline. Local marketing commissions through a local agency, and the agency is not in anybody’s asset register.
What outside-in discovery returns
Properties and profiles carrying the group brand across domains, social platforms and app stores, separated into the ones you published and the ones you did not — ending in removal rather than in an alert.
Answered by
Brand Protection

Domains a local team bought, and the look-alikes bought against them

What the centre can actually require
A central registrar account that roughly half the group uses. The other half pays by local card and renews by calendar reminder.
What outside-in discovery returns
The registered estate reconstructed from the public record rather than from the registrar account, alongside permutation and look-alike registrations scored for intent as they appear.
Answered by
Domain Monitoring

A group is a larger permutation space than a single company, and a convincing look-alike does not have to imitate the parent. It only has to imitate the smallest brand in the portfolio, which is the one with no security function of its own.

Staff credentials from an entity whose endpoints you cannot see

What the centre can actually require
A password policy the subsidiary attests to annually. No telemetry from their devices, and no standing to demand any.
What outside-in discovery returns
Credential and session material attributed to the entity’s domains from stealer-log and breach sources, assembled per compromised device rather than as rows, with each credential carrying an explicit state.
Answered by
Dark Web Monitoring

The walk

From one parent domain to every estate underneath it

Each step is only possible because of the one before it. Nothing here is a lookup against a pre-built list of companies — the group structure is reconstructed from records that were already public, which is precisely why no operating company has to agree to it.

Sourcing the number

Where "eleven days" comes from, and the number we are not going to give you

A figure with no derivation behind it is worth nothing to a group security function that has to defend it internally. Here is the one on this page — and the reason the obvious companion figure is missing rather than estimated.

The last time the question was answered by asking As of Anonymised multinational manufacturing group, 2026
  • The group ran dozens of subsidiary legal entities across several continents with decentralised IT, and a group security function carrying responsibility for the whole estate and authority over almost none of it.
  • The trigger was ordinary. A widely exploited flaw in a common web content-management platform was published, and the question was which brands, subsidiaries and applications across the group were running the affected technology.
  • There was no instrument that answered it, so the question was posted to local IT teams. Eleven days is the interval from asking to holding a set of partially completed spreadsheets returned at different levels of confidence — and by then the estate had moved underneath them.
  • The group did run a configuration database. It was accurate for everything that had been enrolled in it and silent about everything else, and in a group that had absorbed several acquisitions, everything else was the substantial part.

Deliberately excluded

  • It is not our number. Eleven days measures what asking cost that group, not what any method of ours took. It sits on this page because it is the honest description of the alternative, not because it flatters us.
  • We are not publishing the figure that replaced it. Outside-in, the same question stops being a request to every operating company and becomes a query against an estate already discovered and fingerprinted. Naming an interval for that would mean quoting you somebody else’s group as though it were a forecast of yours, which is the failure the eleven days above is an argument against.
  • It is not a forecast for your group. A portfolio held under one registrant and one certificate authority resolves differently from one where every operating company buys its own; the shape of your registration record sets what a first pass costs, and we have not seen it yet.
  • It is not an assessment. Port and service enumeration, technology fingerprinting and exposure analysis run against the discovered estate afterwards, and they take considerably longer than the discovery pass does.
  • It does not adjudicate ownership. An estate that references the group is surfaced and labelled as such. Whether it belongs to you is a judgement the group makes, and we do not make it on your behalf.

What arrives in the report

Every estate declares how it got there

A group total is only defensible if each entry says how it was established. These are the states an estate can hold, and the two that matter most to a group are the ones that say the estate is not yours to act on alone.

Every estate declares how it got there
StateWhat it meansWhat follows
Attributed Resolved to a named operating company in the group. It carries an owner, it counts in the group total, and its clock starts at discovery rather than at triage. Route to the entity that owns it. This is the queue that moves first.
References the group, not attributed An asset that names or brands the group but resolves to infrastructure no entity in the group controls — a franchisee, a distributor, an agency, or an impersonation. Confirm ownership before acting. We surface it; we do not decide it for you.
Operated by a third party Answers for an operating company but sits on a supplier’s estate. Observed from outside and not probed, because authorisation over another company’s systems is not the group’s to grant. Route to the supplier through the entity that holds the contract, with the observation and its date attached.
Divested, still carrying your identity A business the group sold, still resolving through group DNS delegation or still presenting a certificate naming the group as the organisation. The fix is contractual and administrative before it is technical. Raised with both, and tracked until the identity is separated.
On the register, answering nowhere Carried by an entity register but no longer responding to anything. Recorded explicitly rather than dropped, because a register that counts dead systems is producing false assurance in the group total. A correction to hand back to the entity, and evidence the surface was examined.
Key
  • Group estate — owned, counted and clocked
  • Observed, not tested — somebody else’s estate
  • Contractual step before a technical one
  • Confirm ownership first
  • A correction, not a finding

Where this lands

The same job, three different shapes of group

The work is identical and what it turns up is not. How a group acquired its estate decides what the first pass finds, which is worth knowing before anyone reads a number out of context.

Group shapeWhat "group-wide" means thereWhat the first pass usually turns up
Manufacturing and industrial groups Plants, distributors and acquired entities across several countries, most of them predating any central IT function and some of them still running the network they were bought with. Remote-access and management interfaces published for a maintenance contract that ended, and acquired brands still serving customer-facing systems on their pre-acquisition domains.
Banking and financial services Regulated entities, lending and insurance subsidiaries and a shared-services company, where the group total has to hold up in an inspection rather than in a slide. Customer-facing properties operated by a subsidiary through a supplier the group never assessed, and credential material attributed to an entity with no security function of its own.
Technology and software Product companies acquired for their engineering teams, each with its own cloud tenancy, its own pipeline and its own release cadence, folded in faster than governance can follow. Short-lived environments that outlived their purpose, cloud accounts outside central enrolment, and repository and build infrastructure inherited rather than provisioned.

Manufacturing and industrial groups

What "group-wide" means there
Plants, distributors and acquired entities across several countries, most of them predating any central IT function and some of them still running the network they were bought with.
What the first pass usually turns up
Remote-access and management interfaces published for a maintenance contract that ended, and acquired brands still serving customer-facing systems on their pre-acquisition domains.

Banking and financial services

What "group-wide" means there
Regulated entities, lending and insurance subsidiaries and a shared-services company, where the group total has to hold up in an inspection rather than in a slide.
What the first pass usually turns up
Customer-facing properties operated by a subsidiary through a supplier the group never assessed, and credential material attributed to an entity with no security function of its own.

Technology and software

What "group-wide" means there
Product companies acquired for their engineering teams, each with its own cloud tenancy, its own pipeline and its own release cadence, folded in faster than governance can follow.
What the first pass usually turns up
Short-lived environments that outlived their purpose, cloud accounts outside central enrolment, and repository and build infrastructure inherited rather than provisioned.

Questions buyers actually ask

Before you evaluate this

Does a subsidiary have to agree to this before we can see their estate?

Not for discovery. Every input to the walk — corporate registration filings, DNS delegation, certificate transparency, registrar records, hosting neighbourhood — is a public record, so an operating company that would not return your survey is discovered on exactly the same terms as one that would. Testing is a different question and the boundary is real. Continuous Automated Red-Teaming runs only where it is safe and authorised, which in a group means the parent has to be in a position to authorise on the entity’s behalf. For a wholly-owned subsidiary that is usually straightforward. For a minority-held joint venture or a supplier-operated platform it usually is not, and those estates arrive observed and untested with a state on the finding that says so.

We already have a consolidation programme running. Does this replace it?

No, and it is worth more to that programme than as a replacement for it. A consolidation programme is a migration exercise with a plan, a sequence and a budget, and what it has never had is a denominator — a count of what is actually out there that was produced independently of the teams being consolidated. It is more useful as a sequencer than as a substitute: the entities whose observed estate disagrees most with what they reported are the ones to migrate first, and the ones already close to their own record can wait. It also gives the programme a way to show progress that is not self-reported, which is usually the harder half of the reporting problem.

How do you tell one operating company’s assets from another’s?

By what the estate itself shows rather than by which entity claimed it. Responding hosts are grouped into logical applications on served content, certificate subject, technology stack and hosting neighbourhood, and those groups are assigned to an entity from cloud resource tags where they exist and from the operating company that answers for the address where they do not. Two guards matter more than the mechanics. Anything that references the group without resolving to an entity is labelled for confirmation and never counted in a group total. And an estate can be reassigned as evidence changes, with the reasoning retained — so an attribution is something a subsidiary can argue with rather than something they have to accept.

What happens to a business we have already sold?

It shows up, which is usually the point at which somebody discovers the separation was never finished. The common residue is a DNS delegation still pointing through group infrastructure, a certificate still naming the group as the organisation, and a footer or a privacy notice on the divested site still carrying the parent name. None of that is a vulnerability in itself and all of it means the group is still visibly answerable for an estate it no longer runs. It is raised as its own state, because the fix is a contractual and administrative one before it is a technical one, and it is tracked until the identity is genuinely separated.

Start with the parent apex domain and see what answers underneath it

One apex domain is the whole input. No seed list from any operating company, nothing to install, and two business days to a written account of the estates answering underneath it. No call required to get it.