Many organisations are overlooking one of the most fundamental aspects of cybersecurity – knowing exactly what they need to protect. 

Organisations are investing heavily in security operations centres, threat detection platforms, AI-driven analytics and incident response capabilities to identify and contain attacks as quickly and as effectively as they can.

Resilience is, quite rightly, now a boardroom priority and businesses are recognising that preventing every cyberattack is unrealistic and that rapid detection and recovery are equally important.  However, with the focus on advanced security capabilities, many organisations are overlooking one of the most fundamental aspects of cybersecurity – knowing exactly what they need to protect. 

That is becoming far more difficult than many organisations realise. Most organisations, have digital estates that are almost unrecognisable from those of just a few years ago. Infrastructure is no longer confined to a corporate data centre protected by a firewall. Cloud services can be deployed in minutes, departments regularly purchase SaaS applications without involving IT, developers create temporary environments that quietly become permanent, third parties connect directly into corporate networks and employees are using AI tools and personal devices to improve productivity.  

Every one of these changes delivers business value but they also expand the organisation’s attack surface. This constantly evolving environment is one that many organisations only partially understand. 

Cybercriminals know about this and instead of attacking the systems organisations know about and actively defend, they are increasingly looking for what has been forgotten. Unpatched internet-facing servers, misconfigured cloud storage, exposed remote access services, legacy applications and unmanaged devices present an easier route into an organisation than bypassing multiple layers of security protecting critical systems.  

In many cases, organisations are not breached because security controls failed, it is because those controls weren’t protecting the asset at all. 

This shift in cyberattacks is reflected in the Verizon 2026 Data Breach Investigations Report. For the first time in the report’s 19-year history, vulnerability exploitation overtook stolen credentials as the leading initial access vector, accounting for 31% of breaches. Instead of relying primarily on phishing campaigns to steal passwords, threat actors are exploiting vulnerabilities in systems that organisations have either failed to patch or didn’t realise were exposed to the internet. 

Traditional approaches to asset management simply can’t keep pace with the speed of IT change. Asset registers may only be updated periodically, and annual audits only give a snapshot of that point in time. New cloud services can appear overnight, suppliers may establish new network connections and business units may deploy new applications without oversight. By the time an inventory has been completed, it is already out of date. 

Shadow IT is a significant contributor to this lack of visibility. Once associated with employees installing unauthorised software, it now encompasses cloud platforms, AI services, collaboration tools and business applications that sit outside formal governance processes. Most are introduced with good intentions to solve business challenges, but every unmanaged application creates another potential route into the organisation for attackers.  

Mergers, acquisitions and digital transformation projects often leave connected legacy infrastructure that serves no operational purpose. These forgotten assets can remain exposed for months or even years until an attacker discovers them first. 

This is why visibility is one of the most important cybersecurity disciplines organisations need. Before security teams can assess risk, prioritise vulnerabilities or implement effective controls, they need a complete and continuously updated understanding of every internet-facing asset, cloud service, application and connected device.  

Visibility cannot just be an administrative exercise because it is the foundation for every other element of cybersecurity

This is why continuous discovery and attack surface management are becoming essential disciplines. Rather than relying on periodic audits or manually maintained asset registers, organisations need continuous visibility of their digital estate. Regularly identifying internet-facing systems, cloud services, applications and connected devices allows security teams to spot forgotten assets and address weaknesses before attackers have the opportunity to exploit them. 

This approach also changes the conversation around cyber risk. Instead of assuming that existing security controls are protecting everything, organisations are able to make decisions based on an accurate picture of their environment. It enables more effective vulnerability management, strengthens incident response and provides greater confidence that security investment is being directed at the assets that matter most. 

Organisations will continue to embrace cloud computing, AI, digital transformation and connected supply chains, so maintaining visibility will only become more challenging. But also, more importantly, security investments in detection, response and resilience are all valuable, but their effectiveness depends on understanding what they are protecting. If unknown assets are outside those controls, they become the weakest link. 

One deceptively simple question is at the heart of effective cybersecurity: what exactly are we trying to protect? If an organisation cannot answer that with confidence today, and again as its environment evolves, it cannot confidently claim to understand its cyber risk.  

Martin Saunders is CTO at Bluefin Cyber      Image: Ideogram

Source: Cyber Security Intelligence