Skip to content
Back to Blog
·6 min read·guides

Case Study: Enterprise Reduced External Attack Surface 60% in 90 Days

A 4,000-employee enterprise with operations across 6 Indian cities discovered 412 internet-exposed assets in their first month of ASM. By day 90, they had decommissioned, secured, or migrated 247 of them — a 60% surface reduction.

Shouvik Mukherjee, Founder of Bachao.AI

Shouvik Mukherjee

Founder & CEO, Bachao.AI

Map Your Attack Surface

What this means for your business

Indian SMBs without documented security controls face 3× higher breach costs (IBM Cost of a Data Breach 2024). This guide helps you close that gap.

The situation

A diversified industrial enterprise (we'll call them "EntCo") with 4,000 employees across 6 Indian cities had grown through acquisitions over 12 years. The CISO had inherited a security programme but no comprehensive asset inventory. The board had asked: "How much attack surface do we actually have?"

EntCo's profile:

    1. 4,000 employees
    2. 6 Indian city offices + 3 manufacturing sites
    3. 14 acquired subsidiaries over 12 years (each with own IT)
    4. Mix of AWS + Azure + on-premise + colocation
    5. Existing AppCo platform + Salesforce + 30+ SaaS subscriptions
    6. DPDP applicability + RBI applicability (financial subsidiary)
    7. CISO team: 8 people
The CISO knew the asset inventory was incomplete. The question was: how incomplete?

Onboarding (Weeks 1-2)

Bachao.AI's ASM onboarding established the baseline. Method:

    1. ASN ownership mapping (legitimate IP ranges across all subsidiaries)
    2. Subdomain enumeration on all known + suspected brand domains
    3. Certificate transparency log mining (historical certificates)
    4. Passive DNS analysis
    5. Cloud account discovery (AWS Organizations + Azure subscription graph)
Initial findings on day 14:
    1. 412 internet-facing assets discovered
    2. EntCo's prior inventory: 248 assets
    3. Gap: 164 assets EntCo did not have in their inventory (40%)

First-month critical findings

Among the 412 discovered, critical exposures included:

E-001 — Forgotten staging environment from 2021 acquisition A subsidiary acquired in 2021 had a staging environment running outdated software (PHP 7.2, MySQL 5.6) with default credentials. Live for 4 years, never decommissioned. Likely already compromised based on stealer log analysis showing matching credentials.

E-002 — Three publicly accessible Jenkins servers Two subsidiaries' Jenkins servers were internet-accessible. Both running old versions with known vulnerabilities. One showed unauthorized access patterns in its access log.

E-003 — Unmanaged SSL certificates 14 SSL certificates for various subsidiary brands were nearing expiration in next 60 days, none in EntCo's central certificate management. Several were 4+ years old.

E-004 — Employee credentials on dark web 67 employee email + password pairs found on dark web from various breaches. 14 of those credentials were still valid against EntCo's Okta SSO (employees had reused passwords).

E-005 — Sub-processor with active breach One of EntCo's third-party SaaS vendors (used by HR for benefits management) had a public security incident 3 weeks before the ASM onboarding. EntCo had not received notification.

E-006 — Office Wi-Fi exposure One office's guest Wi-Fi network was misconfigured, exposing the internal employee VLAN through a hairpin route.

E-007 — Acquired entity domain in vendor inventory A subsidiary acquired in 2022 was still using its previous owner's email infrastructure. Email DMARC misconfiguration allowed external email spoofing of the subsidiary's domain.

Know your vulnerabilities before attackers do

Run a free VAPT scan — takes 5 minutes, no signup required.

Book Your Free Scan

The 90-day reduction sprint

EntCo's CISO worked with Bachao.AI on a 90-day attack surface reduction sprint:

Weeks 3–6 (Critical findings closure):

    1. E-001 (forgotten staging) decommissioned + forensic analysis (no breach found, but data exfiltration probability assessed)
    2. E-002 (Jenkins servers) — 2 decommissioned, 1 retained behind VPN with proper monitoring
    3. E-003 (SSL certificates) — all 14 certificates renewed and added to central management
    4. E-004 (employee credentials) — force-rotate 67 employee passwords, MFA enforcement re-validated
    5. E-005 (sub-processor incident) — assess impact, coordinated with vendor for remediation evidence
    6. E-006 (office Wi-Fi) — guest VLAN reconfigured
    7. E-007 (DMARC) — corrected, monitoring enabled
Weeks 7–10 (High findings closure):
    1. 14 non-critical exposed services either decommissioned or moved behind VPN
    2. 23 unnecessary subdomains decommissioned
    3. 18 SSL certificates consolidated under central management
    4. 8 forgotten cloud accounts brought under central Organizations management
Weeks 11–13 (Sustained improvements):
    1. Detection rules for new asset discovery (alerts within 2 hours of new asset appearance)
    2. Acquired entity onboarding checklist (so future acquisitions don't repeat the pattern)
    3. Quarterly review cadence with the security team

Results at 90 days

MetricBaseline90 daysChange
Internet-facing assets412165-60%
Critical exposures70-100%
High exposures234-83%
Medium exposures8431-63%
Assets in central inventory248 (60%)165 (100%)+full coverage
Time to discover new assetunknown<2 hoursfull visibility

What it cost

Line itemCost
Bachao.AI ASM (Enterprise tier)₹5L/month × 3 = ₹15L
EntCo internal time for sprint~₹40L opportunity cost (8-person security team, 90 days)
Decommissioning + remediation infrastructure work~₹25L (DevOps time across subsidiaries)
Total 90-day investment₹80L
EntCo's CISO calculated: the cost of a breach via any of the 7 critical exposures (lowest case = E-006 office Wi-Fi compromise) would have been ₹5+ Cr in remediation + reputational impact. Combined critical risk eliminated: estimated ₹35-50 Cr exposure reduction.

What EntCo's CISO said

"We thought we had 248 assets. We had 412. That alone justified the engagement. Six months in, our security team spends meaningfully less time chasing surprises and more time on the things that actually matter. The 'where did THIS server come from?' phone calls have stopped."

Pattern this engagement followed

Common shape for Bachao.AI ASM engagements:

  1. Diversified enterprise with growth through acquisition
  2. Existing security team capable but bandwidth-constrained
  3. CISO needs comprehensive visibility for board reporting
  4. Willingness to act on findings (not just measure them)
If your organisation needs full attack surface visibility:

Schedule the ASM scoping call →


Related: ASM Methodology · ASM for Indian Fintech

Shouvik Mukherjee, Founder of Bachao.AI

Shouvik Mukherjee

Founder & CEO, Bachao.AI

Ex-enterprise architect turned cybersecurity founder. Built systems for Fortune 500s, now making enterprise-grade security accessible to every Indian business. Writes about threats targeting Indian SMBs, practical defenses, and the DPDP Act.

Connect on LinkedIn

Get cybersecurity insights for Indian SMBs

Weekly vulnerability alerts, DPDP compliance tips, and security guides. No spam — unsubscribe anytime.

We respect your privacy. Your email is never shared.

Discover what of yours is exposed to the internet

Free automated scan — risk score in under 2 hours. No credit card required.

Map Your Attack Surface
Find your vulnerabilitiesStart free scan →