CyberOne Blog | Cyber Security Trends, Microsoft Security Updates, Advice

Stories from the SOC: If an Asset Is Public, Why Does It Still Need Protecting?

Written by Daniel Bergner | Sep 25, 2026, 10:52:10 AM

 If your website or server is already out in the open, do you really need to bother protecting it?

It's a fair question. Public-facing systems are meant to be easy to get to. Customers want to visit your site, employees might need to log in from home and suppliers could connect to your services online. If these systems are supposed to be open, who or what are we protecting them from?

The simple answer is: just because something's public, doesn't mean it’s isolated.

A public website or service often links to systems inside your business, handles sensitive info or helps keep things running. If someone breaks in, they're probably not after your homepage but where it can take them next.

A Public Website Is Still Part of Your Business

Let's say you run a company that sells fruit and veg online.

Your website's public so people can look around and place orders. They give you their address, contact details and payment info and the site has to send that information on to other parts of your business.

The warehouse needs to know what to pack, delivery needs the address, accounts want a record of the payment and a supplier might need updated stock info.

So, that public website isn't just a page on the internet. It's hooked up to payments, customer details, suppliers and how your business runs day-to-day.

If someone finds a weakness in your website, that's a worry, but it's only part of the story. You need to know if that weakness could be a way into something more sensitive.

Sure, everyone can see it online, but you still need to protect these assets. If there's any link between your public site and your internal systems, then everything inside could be at risk.

That doesn't mean every dodgy web server lets someone straight into your whole organisation. It just means you need to understand the connections, controls and possible ways in between public and private systems.

The Assets You Do Not Know About Can Create the Greatest Uncertainty

We recently helped a client whose public web server got compromised. The big issue? They hadn't mapped out everything they had online. They didn't have the full picture of what was exposed to the internet.

This is more common than many people realise.

A business might know about its main site and customer portal, but what about an old domain from an old campaign? Or a web service that's still online, a forgotten management page or a server set up for a project and never switched off?

Most businesses focus on securing the systems they know about. The trouble is, attackers aren't sticking to that same list.

Once they're in, attackers look for internet-facing systems, open ports and anything else that's vulnerable. If they find something you've forgotten about, that's an entry point that's probably not being watched or looked after like your main systems.

That's why asset discovery matters. You can't fix, check or watch something if nobody even knows it's there.

What Happens After an Attacker Gets In?

Breaking into a public asset is often just the beginning.

Once someone's got a foot in the door, they'll try to reach other accounts, systems or information. Security teams call this 'lateral movement', which means moving past the first spot they got in and looking for something even more valuable.

That might mean trying to reach an application, an internal server or a privileged account. The route they take depends on how your systems are set up and what controls you've got in place.

This is where network segmentation and defence-in-depth become important.

Segmentation stops every system from talking freely to every other one. Defence-in-depth just means you've got lots of layers of protection, instead of relying on a single thing to stop every attack.

Think of a Public Environment Like a Spaceship Airlock

Think about getting into a spaceship from outside, you go through an airlock first.

The outside door opens and lets you into the airlock, but that doesn't mean you get straight into the rest of the ship. The outside door shuts, everything's made safe and only then does the next door open.

A demilitarised zone, or DMZ, works a bit like that. Public services sit in their own area, and only certain routes let them talk to your private network.

When you walk into the airlock, you see the next door won't open for you right away. You can't just wander in without everything being made safe first.

It's a handy control, but just having an airlock doesn't mean you can forget about what's inside. You still need to know what systems are there, how they're set up, what weaknesses they might have and who or what they're allowed to talk to.

 

That's why layered security matters. If one thing fails, the others help limit what an attacker can get to, spot anything odd and help you respond faster.

Three Questions Every Organisation Should Ask

If you want to know how exposed you are, start with three questions:

  1. What internet-facing assets do we have? Check the systems everyone knows about, but also look for old, temporary or forgotten ones.
  2. How do those assets connect to the business? Work out what data they handle, which systems they talk to and which parts of your business rely on them.
  3. Are we monitoring them effectively? Make sure you can spot weaknesses, changes or anything suspicious, and look into them if you need to.

These questions sound simple, but loads of organisations can't answer all three with confidence.

Public Does Not Mean Safe

A public-facing asset needs protecting because anyone can reach it from outside and it might connect to something your business relies on. The goal isn't to make public systems impossible to reach. It's to know what's exposed, control how it links up with the rest of your setup and keep an eye out for any changes.

Because the principle at the centre of all of this is straightforward: You can't protect what you don't know about.

If you're not sure what your organisation's putting online, getting someone to assess your external attack surface is a great place to start.

Connect with a CyberOne expert to know more.