| Is the provider’s internet-facing estate still what it was when we assessed it? | Every hostname answering from the public internet across the provider apex domains you nominate, resolved without the provider taking part, each carrying the date it entered scope and, where it has gone, the date it left. | Anything the provider runs that never answers from the internet. A private estate has no outside-in signature at all, and asking a monitoring record about it is asking the wrong instrument. | Attack Surface Management |
| Attribution is the load-bearing part, not discovery. A host tied to the wrong company puts a finding on a provider’s file that the provider can disprove in a meeting, and a monitoring record that has been shown to be wrong once is discounted wholesale afterwards. Each host carries the evidence that ties it to the provider, not to a company with a similar name. |
| Has anything changed since the last review? | Movement in that estate as a dated finding: a host that appeared, a service that opened, a software version that moved, an administrative interface that stopped presenting a second factor, an estate that grew after an acquisition nobody announced. | Why it changed. The record states what became observable and on which date; the reason belongs to the provider and is something to ask for, never something to infer from outside. | Third-Party Risk Management |
| This is the row that answers “when did you know”, and it is the reason a change is published as a dated finding with an owner, not as a movement in a score. A grade going from B to D is only the reason somebody looked. |
| Who does the provider itself actually depend on? | The hosting, DNS, mail, certificate and authentication providers each monitored provider resolves to, compared across the whole monitored portfolio instead of one file at a time, so a shared upstream becomes a dated, checkable fact. | The contractual subcontracting chain. A resolution path shows a technical dependency. It does not show who holds the contract, what that contract permits, or which of your functions is sitting on it. | Third-Party Risk Management |
| The dependency you have no contract with is still a dependency, and it is the one a disclosure list structurally cannot show you. A provider can only disclose the arrangements it holds directly. Concentration is worked further down this page. |
| Are credentials belonging to the provider circulating? | Credential records attributed to the provider’s domains in stealer-log and breach material, dated to when they entered the corpus rather than to when the underlying breach is said to have happened. | Whether the provider has rotated them, and whether they still open anything on the provider’s systems. Testing a third party’s estate needs authorisation from the party that owns it, which in a provider relationship is not yours to give. | Dark Web Monitoring |
| There is one narrow exception: where an exposed provider-staff identity maps to an account on your own systems (a contractor remote-access portal, a shared tenancy, a federated login), that account is your estate, and it is validated under the same audit trail as any first-party finding. |
| Did the monitoring actually run, over what scope, and what was done about what it found? | Per-provider detection timestamps and the attributed inventory each run covered, the disposition your team recorded against each finding with the assignee and the timestamps, and the privileged changes made to the monitoring configuration itself. | Any confirmation that the record satisfies an obligation. ShadowMap produces the artefact. Whether the artefact answers a particular clause is a judgement for your auditor and your own advisers. | Regulatory Intelligence |
| The record deliberately includes the occasions your own service levels were missed and the surfaces that were examined and returned nothing. A monitoring trail showing only the months that went well is not evidence. An examiner who cannot find a single miss in a year stops trusting the whole set. |
| Is the provider’s internal control environment sound? | Nothing. There is no outside-in signature for governance, segregation of duties, change management, personnel screening, backup and restore testing, or the resilience testing a provider runs on itself. | All of it. Attestations, audit reports, contractual audit and access rights, and the provider’s own testing carry this half of the question. Nothing here replaces them. | — |
| Outside-in monitoring is evidence about the surface an attacker meets. It is not assurance about the controls behind that surface, and a programme that lets one stand in for the other has quietly swapped the thing for a proxy of it. |