Begin with a defined boundary

Agree which domains, subsidiaries and internet-facing services belong in the review. Record ownership and authorisation before testing. Discovery can reveal unfamiliar assets; validate ownership before treating them as part of your estate.

  • Known domains and externally reachable services
  • Business owner and technical owner for each asset
  • Written scope and testing constraints

Connect the finding to its context

A certificate problem, an exposed service and a leaked credential are different findings. Prioritisation should consider what is reachable, what an attacker could do with it and which business service depends on the asset. A severity label alone does not explain that relationship.

Make remediation an owned decision

The report should state the observation, the evidence, the proposed action and the owner. Changes need an agreed process. Preserve a record of exceptions and compensating controls rather than silently removing an unresolved finding.

  • Observation and evidence
  • Affected asset and business context
  • Owner, decision and verification method

Verify the change, then keep watching

An asset that was fixed can drift. Recheck the exposure and record what was verified, what could not be checked and what remains open. Continuous discovery complements a scoped assessment; it does not turn a limited observation into a guarantee.