ScopeDefine attack surface as everything an external party can reach or discover.
Include public IP space, domains and subdomains, DNS records, web applications, APIs, VPNs, remote access, email infrastructure, cloud endpoints, storage, exposed management interfaces, certificates, third-party hosted services, development and test environments, acquired-company assets, legacy systems, and services published through content delivery networks or reverse proxies.
Do not assume the configuration-management database is complete. The purpose of external discovery is partly to find systems that were never registered, were forgotten after a project, were created directly in cloud consoles, belong to a newly acquired business unit, or remain reachable after a service was supposedly retired.
Decide which discoveries matter enough to create an incident-like escalation. Internet-exposed administrative interfaces, unauthenticated data stores, abandoned applications, expired or unexpected certificates, remote access without required authentication, and publicly reachable systems with known exploited vulnerabilities may require immediate ownership and containment.