Skip to Content

What an attacker already knows about your company

How to turn your external exposure into decisions about priority, budget and contracts before an incident happens
September 14, 2026 by
What an attacker already knows about your company
Kleber Leal by Zamak Portal

On the day of the monthly progress measurement, the CFO of a mid-sized construction company receives an email from a known subcontractor. The subject line carries the correct contract number, the real project name, the usual spreadsheet format, and a request to update banking details before payment. Nothing feels strange because nothing in it was invented: every detail came from information already circulating outside the company, on procurement portals, in attachments forwarded between partners, and in a credential leaked in an incident that never even touched the construction company's network.

Before any intrusion attempt there is a silent research phase, and that is where most of the attacker's work happens. They rebuild the org chart from public professional profiles, identify who approves payments, find out which supplier has network access, and learn the operation's financial calendar. By the time the incident finally reaches the board's radar, the adversary has already studied the company for weeks, using information the organization itself published or entrusted to third parties.

Threat intelligence applied to external exposure (the practice of mapping what is already available about the business outside your perimeter) exists to reverse that asymmetry. The purpose is a business one: turning what the attacker already knows into decisions about priority, budget, and contract clauses, before the inventory of your own exposure is discovered in the middle of a crisis.

The economics behind target selection

Victim selection follows economic logic. The attacker estimates how much it is worth to interrupt an operation, how quickly the company decides under pressure, and how many third parties move around inside that environment. Engineering and construction score high on all three criteria, because margins are tight, deadlines carry penalties for each day of delay, and dozens of subcontractors, designers, and suppliers share files and access throughout a project's life cycle. According to the Microsoft Digital Defense Report 2024, the company's customers face more than 600 million daily attacks against identities, which confirms the user credential as the preferred entry point.

The first exposed asset is usually the password. When a service used by an employee suffers a breach, that pair of corporate email and password starts circulating in resold databases, and reusing the same password on the company portal opens the way for credential stuffing (automated testing of credentials leaked from other services). No intrusion has to happen, because the access obtained is valid, and valid access rarely triggers an alarm.

The second asset is whatever was left online after the project ended. A tracking portal created for a development delivered in 2019 is still responding on the internet, with outdated software and a user list that includes former employees and partners whose contracts have ended. Adding up mailboxes from completed projects, test environments published out of convenience, and plans shared through open links, the real attack surface almost always exceeds the inventory that IT maintains.

The third asset is public by obligation or by marketing. Procurement portals disclose schedules, amounts, and technical leads, opening-day press releases reveal partnerships, and professional profiles describe the systems used day to day. Each piece in isolation seems harmless, though together they make it possible to assemble a payment-redirection fraud convincing enough to pass three levels of approval, precisely because it uses real names, vocabulary, and deadlines.

How to treat exposure as a business decision

The starting point is an honest inventory of what is yours outside your walls: active domains and subdomains, published portals and applications, corporate accounts present in known breaches, project documents shared by link, and access granted to third parties. This assessment does not fit into a one-off project, because exposure changes with every project started, supplier hired, and employee let go. It is worth naming someone responsible for periodic review, with the authority to shut down whatever no longer has an owner.

The second front is contractual. When an engineering firm is given access to the client's network and a construction company distributes project files among dozens of subcontractors, the entire chain shares the same risk, and the contract needs to reflect that with clear requirements: multifactor authentication (a second verification factor beyond the password), access with an expiration date, immediate revocation when the service ends, and an obligation to report incidents within a defined window. A foundation of managed cybersecurity supports these requirements day to day.

Finally, choose intelligence that arrives with context. Global trend reports serve any company equally and rarely change a budget decision, whereas a named finding changes the conversation: this domain resembling yours was registered, this credential from your finance department showed up in a leaked database, this old portal is still published. Services of threat intelligence with specialized backing support internal IT in this work, with continuous monitoring and recurring review of what is exposed.

5 questions every manager should ask

1. What information about our company is already circulating outside it, and who is responsible for tracking that?

2. Would our threat intelligence change any investment decision this quarter?

3. If a partner's credential is used against our contract, who is accountable?

4. What metrics translate digital exposure into board-level language?

5. How do we maintain a recurring exposure review cycle without generating one more report that nobody reads?

What information about our company is already circulating outside it, and who is responsible for tracking that?

The honest answer, in most organizations, is that nobody knows and nobody is accountable. The information is scattered across credential databases leaked in third-party incidents, portals published by project teams, documents shared with partners, and content disclosed as a requirement in procurement processes. Each piece was created by a different department, at a different time, without anyone consolidating the overall view.

From a management perspective, the gap is one of ownership before it is technical. As long as external exposure has no named owner, no scheduled review, and no place on the board's agenda, it will continue to be discovered by the adversary before it is discovered by the company. Assigning that role costs little and changes the nature of the conversation, because it creates someone with an obligation to bring the updated list.

Would our threat intelligence change any investment decision this quarter?

This is the most efficient test for separating generic intelligence from contextualized intelligence. If the material you receive describes trends that would apply equally to a retail chain, a hospital, and a construction company, it informs without guiding. Actionable intelligence cites your domains, your identities, your suppliers, and your published systems, with an indication of severity and remediation effort.

The practical consequence shows up in the budget. When a finding shows that procurement department credentials are circulating in resold databases, enabling strong authentication across the entire approval chain stops being a technical preference and starts directly protecting the payment flow. The criterion for evaluating any intelligence provider follows from this: ask for examples of findings and check how many would have changed an actual priority in the last cycle.

If a partner's credential is used against our contract, who is accountable?

Legally, the answer depends on the contract; commercially, it usually falls on the company that signed with the end client. The client rarely accepts the explanation that the compromised access belonged to a subcontractor, because the commitment to deadlines, project confidentiality, and continuity was made by the prime contractor.

This turns third-party access management into a board-level topic. It is worth inventorying who accesses what, for how long, and under whose responsibility, and it is worth treating a partner credential with the same rigor applied to an employee's, including immediate deactivation at the end of the engagement. In supply chains with dozens of vendors, this discipline reduces more risk than most tool purchases.

Which metrics translate digital exposure into board-level language?

The metrics that work speak of money, time, and commitments made: cost per hour of halted operations, number of active contracts with a security clause, volume of proposals in progress that depend on exposed systems, average time between the discovery of a leaked credential and its blocking, and the percentage of third-party access with a defined expiration date.

When these indicators appear side by side, the conversation shifts register, because the board begins to compare exposure with exposure, in the same way it tracks customer delinquency or supplier delays. Estimating the cost of downtime per hour, with the support of a downtime impact calculator, is usually the step that makes the debate concrete.

How do you maintain a recurring exposure review cycle without generating yet another report that nobody reads?

Reports die when they have no recipient with decision-making power. The cycle works when each review ends in three short lists: what was shut down, what was fixed, and what remains accepted as risk, with the name of whoever accepted it. This format fits on one page and survives any board's agenda.

Cadence also matters, and quarterly reviews supported by continuous verification serve most operations well, with adjustments during busier periods, such as the start of major construction projects or the onboarding of critical suppliers. Specialized backup support, in the NOC (network operations center) and SOC (security operations center) model, sustains the repetitive part of the work and gives internal IT back time for what requires business knowledge.

Frequently asked questions

What is threat intelligence applied to external exposure?

It is the practice of continuously mapping and monitoring everything available about a company outside its perimeter, including published domains, forgotten portals, credentials leaked in third-party incidents, and documents shared with partners. The goal is to turn these findings into decisions about priority, budget, and contracts before they are exploited. Gartner classifies this set of services as digital risk protection.

How often should a company review its external digital exposure?

Most operations are well served by formal quarterly reviews, supported by continuous monitoring in between. Moments of change call for an additional review: the start of large projects, the onboarding of suppliers with network access, mergers, and the offboarding of entire teams. The interval matters less than the existence of a named owner and a record of what was actually fixed.

Why do credentials leaked in third-party incidents affect my company?

Because employees frequently reuse passwords between personal services and corporate systems. When an external service suffers a breach, the corporate email and password pair begins circulating in resold databases and can open valid access to the company's systems, without any perceptible intrusion. Multifactor authentication and monitoring of exposed credentials reduce this risk directly.

If the question that opens this text still has no clear answer at your company, start with a no-obligation Strategic IT Assessment.

What an attacker already knows about your company
Kleber Leal by Zamak Portal September 14, 2026
Share this post
Tags
Archive