How a Large BFSI Enterprise Reduced Its Attack Surface Exposure by 40%
Four thousand seven hundred internet-facing assets, against an inventory that listed twelve hundred
Client: Leading BFSI Enterprise
The Challenge
Uncontrolled Attack Surface Across 300+ Subsidiaries
A financial services group with more than 300 subsidiaries kept its asset inventory by hand and could not describe its own perimeter end to end. Subsidiaries stood up domains and cloud accounts without central review, decommissioned services kept resolving, and credential leaks surfaced through customers before they surfaced through monitoring — while regulatory expectations on external exposure tightened across both the banking and securities arms.
- No centralised view of internet-facing assets across 300+ subsidiaries
- Thousands of hosts, subdomains and cloud accounts outside the maintained inventory
- Credential leaks reaching customers before they reached the security team
- RBI and SEBI expectations on external exposure tightening in parallel
The Solution
Continuous Attack Surface Monitoring with Managed Triage and Takedown
ShadowMap was deployed against the group apex domains for continuous external discovery, and a dedicated managed team took the output from raw finding through to triage, subsidiary ownership and takedown. The point was not more alerts: every exposure was routed to the entity that owned it, with a weekly operational report and a monthly summary written for the board.
Services used
Our approach
- 01Asset enumeration outward from the apex domains: 4,700+ assets discovered against 1,200 previously known
- 02Risk scoring by exposure and business criticality, so remediation followed impact rather than discovery order
- 03Dark web and stealer-log monitoring: 14 active credential leaks identified and forced through rotation
- 04Takedown programme run to completion rather than to notification: 47 phishing domains removed
- 05Weekly exposure reporting to the security team, monthly summary to the board
The Results
40% Reduction in Attack Surface Exposure in 6 Months
Six months in, the group could describe its own perimeter for the first time, and the exposure score had fallen 40% — driven mostly by decommissioning what nobody owned rather than by adding controls. Every remaining asset now has a named subsidiary accountable for it.
Ready to discuss your security needs?
Talk to our team about a similar engagement for your organisation.
Request a Scoping Call