External attack surface management begins with an unglamorous fact: nobody has a complete list of what their organisation exposes.
The sources
DNS. Zone data for domains you know, plus passive DNS to find subdomains that were never documented. Watch for records pointing at decommissioned cloud resources — a dangling record is a takeover waiting for somebody to claim the name.
Certificate transparency. Every publicly trusted certificate is logged. Searching the logs for your domains reveals hosts that were never in any inventory, often in environments you did not know existed.
Cloud provider APIs. Enumerate from the accounts themselves: public IPs, load balancers, storage buckets, functions with public URLs, managed databases with public endpoints. This is the only authoritative source, and only for the accounts you know about — so start with billing, which knows about all of them.
Registrars, ASNs and acquisitions. Companies you bought bring domains, addresses and systems with them, usually with worse hygiene and no owner.
Turning discovery into a programme
Discovery without ownership produces a list nobody acts on. Each asset needs an owner, a business purpose and a decision: keep and secure, or remove. The second option is the one most under-used — the cheapest reduction in attack surface is turning things off.
Run discovery continuously. Attack surface changes with every deployment, and the asset that appears on a Friday afternoon is the one that will be found by somebody else.