Vulnerabilities
You cannot manage exposure on an asset you cannot see.
Vulnerability management starts with a maintained inventory and a clear account of what discovery methods can and cannot observe.
Build an inventory that reflects real use
A purchasing list is not a complete technology inventory. Devices change owners, temporary cloud systems remain running, and suppliers introduce services outside the usual deployment process. Discovery should reconcile these realities with approved records rather than assume that one source is authoritative for everything.
Combine relevant sources such as device management, cloud accounts, network observations and application ownership records. Record an owner, purpose and environment where possible. A newly found system with no accountable owner is a business question as well as a technical finding.
Be explicit about coverage
An authenticated scan can reveal information that a network-only check cannot. An agent may see a laptop off the corporate network, while an external assessment may reveal an exposed service the internal inventory missed. No single method provides complete coverage.
Report discovery failures and excluded systems alongside findings. A device that has not checked in for weeks should not quietly disappear from the risk picture. Similarly, a scan that could not authenticate should not be reported as equivalent to a successful assessment.
Discover safely and within permission
Confirm ownership and authorization before scanning. Sensitive industrial, medical or legacy systems may need vendor-approved methods and maintenance windows. Passive discovery or carefully scoped checks may be more appropriate. Continuous discovery means a repeatable, maintained process, not indiscriminate scanning of every reachable address.
In practice
A temporary cloud server becomes permanent
Illustrative scenario, not a client case study.
In a hypothetical engineering business, a project team creates a cloud server for a short evaluation. Months later it is still running, but it is absent from the normal patching inventory. No one intentionally accepted that ongoing exposure.
- A scheduled reconciliation finds the cloud instance and compares it with the approved asset list. The team confirms the account, project and responsible owner before assessing it.
- The owner verifies whether the server is still needed. If it is, the team records its purpose, checks its exposure and brings it into an approved management process.
- If it is no longer needed, the team follows the authorized retirement process, including data retention and dependency checks. It also changes the provisioning workflow to require an owner and review date.
Finding the server was only the first step. The durable improvement was connecting discovery to ownership, a decision and a lifecycle process that prevents the same gap from recurring.
What to put in place
- Reconcile device, network and cloud inventories regularly.
- Record an owner and business purpose for discovered assets.
- Report failed checks, stale records and exclusions explicitly.
- Use authorized discovery methods appropriate to each environment.
The takeaway
Coverage is a measurable part of vulnerability management. Treat unknown and unassessed assets as visible work, not as empty space in a report.