If your website or server is already out in the open, do you really need to bother protecting it?
It's a fair question. Public-facing systems are meant to be easy to get to. Customers want to visit your site, employees might need to log in from home and suppliers could connect to your services online. If these systems are supposed to be open, who or what are we protecting them from?
The simple answer is: just because something's public, doesn't mean it’s isolated.
A public website or service often links to systems inside your business, handles sensitive info or helps keep things running. If someone breaks in, they're probably not after your homepage but where it can take them next.
Let's say you run a company that sells fruit and veg online.
Your website's public so people can look around and place orders. They give you their address, contact details and payment info and the site has to send that information on to other parts of your business.
The warehouse needs to know what to pack, delivery needs the address, accounts want a record of the payment and a supplier might need updated stock info.
So, that public website isn't just a page on the internet. It's hooked up to payments, customer details, suppliers and how your business runs day-to-day.
If someone finds a weakness in your website, that's a worry, but it's only part of the story. You need to know if that weakness could be a way into something more sensitive.
Sure, everyone can see it online, but you still need to protect these assets. If there's any link between your public site and your internal systems, then everything inside could be at risk.
That doesn't mean every dodgy web server lets someone straight into your whole organisation. It just means you need to understand the connections, controls and possible ways in between public and private systems.
We recently helped a client whose public web server got compromised. The big issue? They hadn't mapped out everything they had online. They didn't have the full picture of what was exposed to the internet.
This is more common than many people realise.
A business might know about its main site and customer portal, but what about an old domain from an old campaign? Or a web service that's still online, a forgotten management page or a server set up for a project and never switched off?
Most businesses focus on securing the systems they know about. The trouble is, attackers aren't sticking to that same list.
Once they're in, attackers look for internet-facing systems, open ports and anything else that's vulnerable. If they find something you've forgotten about, that's an entry point that's probably not being watched or looked after like your main systems.
That's why asset discovery matters. You can't fix, check or watch something if nobody even knows it's there.
Breaking into a public asset is often just the beginning.
Once someone's got a foot in the door, they'll try to reach other accounts, systems or information. Security teams call this 'lateral movement', which means moving past the first spot they got in and looking for something even more valuable.
That might mean trying to reach an application, an internal server or a privileged account. The route they take depends on how your systems are set up and what controls you've got in place.
This is where network segmentation and defence-in-depth become important.
Segmentation stops every system from talking freely to every other one. Defence-in-depth just means you've got lots of layers of protection, instead of relying on a single thing to stop every attack.
Think about getting into a spaceship from outside, you go through an airlock first.
The outside door opens and lets you into the airlock, but that doesn't mean you get straight into the rest of the ship. The outside door shuts, everything's made safe and only then does the next door open.
A demilitarised zone, or DMZ, works a bit like that. Public services sit in their own area, and only certain routes let them talk to your private network.
When you walk into the airlock, you see the next door won't open for you right away. You can't just wander in without everything being made safe first.
It's a handy control, but just having an airlock doesn't mean you can forget about what's inside. You still need to know what systems are there, how they're set up, what weaknesses they might have and who or what they're allowed to talk to.
That's why layered security matters. If one thing fails, the others help limit what an attacker can get to, spot anything odd and help you respond faster.
If you want to know how exposed you are, start with three questions:
These questions sound simple, but loads of organisations can't answer all three with confidence.
A public-facing asset needs protecting because anyone can reach it from outside and it might connect to something your business relies on. The goal isn't to make public systems impossible to reach. It's to know what's exposed, control how it links up with the rest of your setup and keep an eye out for any changes.
Because the principle at the centre of all of this is straightforward: You can't protect what you don't know about.
If you're not sure what your organisation's putting online, getting someone to assess your external attack surface is a great place to start.