You cannot consolidate an inventory nobody ever finished.
“Twelve operating companies, each with their own IT. I cannot answer what we own, let alone what is exposed.”
A group is not one estate with twelve owners. It is twelve estates, each with its own registrar, its own cloud accounts and its own idea of what belongs on a register. ShadowMap starts at the parent apex domain and works outward through the public registration, naming and certificate record to the operating companies underneath it — so what you get is assembled from what answers, not from what each entity was willing, or able, to declare.
To answer one group-wide question by asking every entity in turn
From the anonymised multinational group set out further down this page. A widely exploited flaw in a common web content-management platform was published, and the group security lead needed to know which brands and subsidiaries were running it. The question went out to local IT teams. Eleven days later the answer came back as partially completed spreadsheets at different levels of confidence — and it was stale before it was collated. That is not a vulnerability-management problem. It is an inventory problem wearing a vulnerability-management costume.
The problem underneath
Twelve partial inventories do not add up to one
The instinct is to ask each operating company for its asset register and merge them. That produces a longer register, not a truer one — because the gap in each is the same gap, and merging preserves it.
Each register is a record of intent, maintained by whoever remembered, accurate at the moment of provisioning and decaying from that moment. The centre has no instrument that reaches past it. Group security holds a policy and a quarterly return; it does not hold administrative access to a subsidiary in another jurisdiction, and in most groups it does not hold read access either. So the honest description of the position is not that the group inventory is out of date. It is that the group inventory has never existed, and the exercise that would produce it depends on the cooperation of twelve teams whose own records have the same defect. Acquisitions make it structural rather than occasional: a newly bought brand arrives with an estate nobody at the centre has ever seen, on domains nobody at the centre registered, behind certificates nobody at the centre issued — and the security migration queues behind the finance, ERP and identity migrations, sometimes for years. Divestitures leave the mirror image, where a business you sold still resolves through your DNS delegation and still presents a certificate with your organisation on it. Meanwhile the attacker enumerating your group asks nobody for anything. Their view is assembled from the public record, it is already assembled, and it does not stop at the boundary of the entities that answered your survey. Outside-in discovery is simply the decision to read the same record they read, from the same side. It needs no cooperation from the asset owner — which is the whole point when the asset owner is a subsidiary you acquired last year and whose IT director does not report to you.
What sits under the parent
Five kinds of estate, and what each one actually needs
A group is not one problem repeated twelve times. The entity types below differ in what the centre can require of them, in what the public record gives up about them, and therefore in which capability answers them. The right-hand column links to how each is done.
| What sits under the parent | What the centre can actually require | What outside-in discovery returns | Answered by |
|---|---|---|---|
| A subsidiary or an acquired brand running its own infrastructure | A policy, a quarterly return, and whatever the local team chooses to put in it. No administrative standing, no agent to deploy, and no realistic way to audit the answer. | Every hostname that answers under the entity apex, on its original domains and its original certificates, whether or not a migration has begun. The entity is not asked, because nothing in the method requires asking. | Attack Surface Management |
| The acquisition case is the hard one, and it is hard for a scheduling reason rather than a technical one. Security migration queues behind finance, ERP and identity, so for as long as that queue takes, the entity keeps answering on its own domains, its own certificates and its own cloud accounts. Outside-in discovery does not wait for the queue, because nothing in it depends on the entity having been onboarded first. | |||
| A platform an operating company outsourced to a supplier | A contract signed by a subsidiary, on terms the centre did not negotiate, with a security schedule the centre has never read. | Systems that answer for the operating company but resolve to a supplier’s infrastructure — surfaced as observed, never as tested, because authorisation over a supplier estate is not the group’s to give. | Third-Party Risk Management |
| This is the row most group programmes discover late. Concentration is a group-level fact and cannot be seen from inside any single operating company: two subsidiaries that each chose a supplier independently, and chose the same one, have made a decision nobody in the group took. | |||
| Regional sites, campaigns and executive identity nobody registered centrally | A brand guideline. Local marketing commissions through a local agency, and the agency is not in anybody’s asset register. | Properties and profiles carrying the group brand across domains, social platforms and app stores, separated into the ones you published and the ones you did not — ending in removal rather than in an alert. | Brand Protection |
| Domains a local team bought, and the look-alikes bought against them | A central registrar account that roughly half the group uses. The other half pays by local card and renews by calendar reminder. | The registered estate reconstructed from the public record rather than from the registrar account, alongside permutation and look-alike registrations scored for intent as they appear. | Domain Monitoring |
| A group is a larger permutation space than a single company, and a convincing look-alike does not have to imitate the parent. It only has to imitate the smallest brand in the portfolio, which is the one with no security function of its own. | |||
| Staff credentials from an entity whose endpoints you cannot see | A password policy the subsidiary attests to annually. No telemetry from their devices, and no standing to demand any. | Credential and session material attributed to the entity’s domains from stealer-log and breach sources, assembled per compromised device rather than as rows, with each credential carrying an explicit state. | Dark Web Monitoring |
A subsidiary or an acquired brand running its own infrastructure
- What the centre can actually require
- A policy, a quarterly return, and whatever the local team chooses to put in it. No administrative standing, no agent to deploy, and no realistic way to audit the answer.
- What outside-in discovery returns
- Every hostname that answers under the entity apex, on its original domains and its original certificates, whether or not a migration has begun. The entity is not asked, because nothing in the method requires asking.
- Answered by
- Attack Surface Management
The acquisition case is the hard one, and it is hard for a scheduling reason rather than a technical one. Security migration queues behind finance, ERP and identity, so for as long as that queue takes, the entity keeps answering on its own domains, its own certificates and its own cloud accounts. Outside-in discovery does not wait for the queue, because nothing in it depends on the entity having been onboarded first.
A platform an operating company outsourced to a supplier
- What the centre can actually require
- A contract signed by a subsidiary, on terms the centre did not negotiate, with a security schedule the centre has never read.
- What outside-in discovery returns
- Systems that answer for the operating company but resolve to a supplier’s infrastructure — surfaced as observed, never as tested, because authorisation over a supplier estate is not the group’s to give.
- Answered by
- Third-Party Risk Management
This is the row most group programmes discover late. Concentration is a group-level fact and cannot be seen from inside any single operating company: two subsidiaries that each chose a supplier independently, and chose the same one, have made a decision nobody in the group took.
Regional sites, campaigns and executive identity nobody registered centrally
- What the centre can actually require
- A brand guideline. Local marketing commissions through a local agency, and the agency is not in anybody’s asset register.
- What outside-in discovery returns
- Properties and profiles carrying the group brand across domains, social platforms and app stores, separated into the ones you published and the ones you did not — ending in removal rather than in an alert.
- Answered by
- Brand Protection
Domains a local team bought, and the look-alikes bought against them
- What the centre can actually require
- A central registrar account that roughly half the group uses. The other half pays by local card and renews by calendar reminder.
- What outside-in discovery returns
- The registered estate reconstructed from the public record rather than from the registrar account, alongside permutation and look-alike registrations scored for intent as they appear.
- Answered by
- Domain Monitoring
A group is a larger permutation space than a single company, and a convincing look-alike does not have to imitate the parent. It only has to imitate the smallest brand in the portfolio, which is the one with no security function of its own.
Staff credentials from an entity whose endpoints you cannot see
- What the centre can actually require
- A password policy the subsidiary attests to annually. No telemetry from their devices, and no standing to demand any.
- What outside-in discovery returns
- Credential and session material attributed to the entity’s domains from stealer-log and breach sources, assembled per compromised device rather than as rows, with each credential carrying an explicit state.
- Answered by
- Dark Web Monitoring
The walk
From one parent domain to every estate underneath it
Each step is only possible because of the one before it. Nothing here is a lookup against a pre-built list of companies — the group structure is reconstructed from records that were already public, which is precisely why no operating company has to agree to it.
-
Seed
One apex domain is the entire input
The parent company’s own domain, and nothing else. No seed list, no scope file, and no export from anybody’s configuration database. Name the trading names and acquisitions you are unsure about if you want to, but withholding them is the more useful test: a seed list that already contains the answer proves nothing, and a group that has to assemble the input first has already lost the estates it cannot name.
-
Expand
Walk outward through the public record
Corporate registration filings, DNS delegation, certificate transparency, registrar records and hosting neighbourhood are followed outward to the subsidiary and brand apexes beneath the parent — then the same walk runs again from each of those. The group tree that comes back is the one the outside world can already draw, which is the only version an attacker is working from.
-
Attribute
Establish which entity owns what, before calling any of it yours
Responding hosts are grouped into logical applications by served content, certificate subject, technology stack and hosting neighbourhood, then assigned to an operating company. Cloud resource tags decide ownership where they exist and the answering entity decides it where they do not. Anything that references the group without resolving to an entity is labelled for confirmation and never absorbed into a group total.
-
Consolidate
One model, readable at two altitudes
The group roll-up and the per-entity view are the same finding seen from two distances, not two products reporting separately — one correlated exposure model, so a board number and a subsidiary CISO’s work queue can never disagree about what was found. Findings route into whichever queue the owning entity already uses, which for a group means several different ones at once.
Sourcing the number
Where "eleven days" comes from, and the number we are not going to give you
A figure with no derivation behind it is worth nothing to a group security function that has to defend it internally. Here is the one on this page — and the reason the obvious companion figure is missing rather than estimated.
The last time the question was answered by asking As of Anonymised multinational manufacturing group, 2026
- The group ran dozens of subsidiary legal entities across several continents with decentralised IT, and a group security function carrying responsibility for the whole estate and authority over almost none of it.
- The trigger was ordinary. A widely exploited flaw in a common web content-management platform was published, and the question was which brands, subsidiaries and applications across the group were running the affected technology.
- There was no instrument that answered it, so the question was posted to local IT teams. Eleven days is the interval from asking to holding a set of partially completed spreadsheets returned at different levels of confidence — and by then the estate had moved underneath them.
- The group did run a configuration database. It was accurate for everything that had been enrolled in it and silent about everything else, and in a group that had absorbed several acquisitions, everything else was the substantial part.
Deliberately excluded
- It is not our number. Eleven days measures what asking cost that group, not what any method of ours took. It sits on this page because it is the honest description of the alternative, not because it flatters us.
- We are not publishing the figure that replaced it. Outside-in, the same question stops being a request to every operating company and becomes a query against an estate already discovered and fingerprinted. Naming an interval for that would mean quoting you somebody else’s group as though it were a forecast of yours, which is the failure the eleven days above is an argument against.
- It is not a forecast for your group. A portfolio held under one registrant and one certificate authority resolves differently from one where every operating company buys its own; the shape of your registration record sets what a first pass costs, and we have not seen it yet.
- It is not an assessment. Port and service enumeration, technology fingerprinting and exposure analysis run against the discovered estate afterwards, and they take considerably longer than the discovery pass does.
- It does not adjudicate ownership. An estate that references the group is surfaced and labelled as such. Whether it belongs to you is a judgement the group makes, and we do not make it on your behalf.
What arrives in the report
Every estate declares how it got there
A group total is only defensible if each entry says how it was established. These are the states an estate can hold, and the two that matter most to a group are the ones that say the estate is not yours to act on alone.
| State | What it means | What follows |
|---|---|---|
| Attributed | Resolved to a named operating company in the group. It carries an owner, it counts in the group total, and its clock starts at discovery rather than at triage. | Route to the entity that owns it. This is the queue that moves first. |
| References the group, not attributed | An asset that names or brands the group but resolves to infrastructure no entity in the group controls — a franchisee, a distributor, an agency, or an impersonation. | Confirm ownership before acting. We surface it; we do not decide it for you. |
| Operated by a third party | Answers for an operating company but sits on a supplier’s estate. Observed from outside and not probed, because authorisation over another company’s systems is not the group’s to grant. | Route to the supplier through the entity that holds the contract, with the observation and its date attached. |
| Divested, still carrying your identity | A business the group sold, still resolving through group DNS delegation or still presenting a certificate naming the group as the organisation. | The fix is contractual and administrative before it is technical. Raised with both, and tracked until the identity is separated. |
| On the register, answering nowhere | Carried by an entity register but no longer responding to anything. Recorded explicitly rather than dropped, because a register that counts dead systems is producing false assurance in the group total. | A correction to hand back to the entity, and evidence the surface was examined. |
- Group estate — owned, counted and clocked
- Observed, not tested — somebody else’s estate
- Contractual step before a technical one
- Confirm ownership first
- A correction, not a finding
Where this lands
The same job, three different shapes of group
The work is identical and what it turns up is not. How a group acquired its estate decides what the first pass finds, which is worth knowing before anyone reads a number out of context.
| Group shape | What "group-wide" means there | What the first pass usually turns up |
|---|---|---|
| Manufacturing and industrial groups | Plants, distributors and acquired entities across several countries, most of them predating any central IT function and some of them still running the network they were bought with. | Remote-access and management interfaces published for a maintenance contract that ended, and acquired brands still serving customer-facing systems on their pre-acquisition domains. |
| Banking and financial services | Regulated entities, lending and insurance subsidiaries and a shared-services company, where the group total has to hold up in an inspection rather than in a slide. | Customer-facing properties operated by a subsidiary through a supplier the group never assessed, and credential material attributed to an entity with no security function of its own. |
| Technology and software | Product companies acquired for their engineering teams, each with its own cloud tenancy, its own pipeline and its own release cadence, folded in faster than governance can follow. | Short-lived environments that outlived their purpose, cloud accounts outside central enrolment, and repository and build infrastructure inherited rather than provisioned. |
Manufacturing and industrial groups
- What "group-wide" means there
- Plants, distributors and acquired entities across several countries, most of them predating any central IT function and some of them still running the network they were bought with.
- What the first pass usually turns up
- Remote-access and management interfaces published for a maintenance contract that ended, and acquired brands still serving customer-facing systems on their pre-acquisition domains.
Banking and financial services
- What "group-wide" means there
- Regulated entities, lending and insurance subsidiaries and a shared-services company, where the group total has to hold up in an inspection rather than in a slide.
- What the first pass usually turns up
- Customer-facing properties operated by a subsidiary through a supplier the group never assessed, and credential material attributed to an entity with no security function of its own.
- What "group-wide" means there
- Product companies acquired for their engineering teams, each with its own cloud tenancy, its own pipeline and its own release cadence, folded in faster than governance can follow.
- What the first pass usually turns up
- Short-lived environments that outlived their purpose, cloud accounts outside central enrolment, and repository and build infrastructure inherited rather than provisioned.
What this job draws on
The capabilities behind it, and what each one contributes
Where this job comes up most: Banking and financial services and Technology and software .
Questions buyers actually ask
Before you evaluate this
Does a subsidiary have to agree to this before we can see their estate?
Not for discovery. Every input to the walk — corporate registration filings, DNS delegation, certificate transparency, registrar records, hosting neighbourhood — is a public record, so an operating company that would not return your survey is discovered on exactly the same terms as one that would. Testing is a different question and the boundary is real. Continuous Automated Red-Teaming runs only where it is safe and authorised, which in a group means the parent has to be in a position to authorise on the entity’s behalf. For a wholly-owned subsidiary that is usually straightforward. For a minority-held joint venture or a supplier-operated platform it usually is not, and those estates arrive observed and untested with a state on the finding that says so.
We already have a consolidation programme running. Does this replace it?
No, and it is worth more to that programme than as a replacement for it. A consolidation programme is a migration exercise with a plan, a sequence and a budget, and what it has never had is a denominator — a count of what is actually out there that was produced independently of the teams being consolidated. It is more useful as a sequencer than as a substitute: the entities whose observed estate disagrees most with what they reported are the ones to migrate first, and the ones already close to their own record can wait. It also gives the programme a way to show progress that is not self-reported, which is usually the harder half of the reporting problem.
How do you tell one operating company’s assets from another’s?
By what the estate itself shows rather than by which entity claimed it. Responding hosts are grouped into logical applications on served content, certificate subject, technology stack and hosting neighbourhood, and those groups are assigned to an entity from cloud resource tags where they exist and from the operating company that answers for the address where they do not. Two guards matter more than the mechanics. Anything that references the group without resolving to an entity is labelled for confirmation and never counted in a group total. And an estate can be reassigned as evidence changes, with the reasoning retained — so an attribution is something a subsidiary can argue with rather than something they have to accept.
What happens to a business we have already sold?
It shows up, which is usually the point at which somebody discovers the separation was never finished. The common residue is a DNS delegation still pointing through group infrastructure, a certificate still naming the group as the organisation, and a footer or a privacy notice on the divested site still carrying the parent name. None of that is a vulnerability in itself and all of it means the group is still visibly answerable for an estate it no longer runs. It is raised as its own state, because the fix is a contractual and administrative one before it is a technical one, and it is tracked until the identity is genuinely separated.
Start with the parent apex domain and see what answers underneath it
One apex domain is the whole input. No seed list from any operating company, nothing to install, and two business days to a written account of the estates answering underneath it. No call required to get it.