Open the app
Use case

Mapping your own exposure

Forgotten domains, accounts impersonating the brand, suppliers behind suppliers: seeing your environment rather than holding it in five separate spreadsheets.

The problem

An organisation knows its own exposure badly. Domain names booked over the years by different teams, accounts opened on platforms for a campaign and never closed, suppliers who subcontract to other suppliers: all of it exists in separate spreadsheets, held by people who do not talk to each other.

The day a domain resembling yours gets registered, or an account impersonates your brand, the question is not only how to handle it. It is whether it is isolated, or part of a pattern already spotted six months earlier.

What the map brings

Seeing your perimeter. Domains, subdomains, official accounts, suppliers, brand sites: put on a map, they stop being a list and become a whole, with its dense areas and its blind spots.

Bringing reports together. Three impersonations handled separately tell you nothing. The same three placed on a map, with their registration dates and their hosts, sometimes show they came from the same place.

Following cascading dependencies. A critical supplier that itself depends on another is business-continuity information, not just procurement. A named link makes it visible.

Keeping the history. A map reopened at each incident becomes the department’s memory. It survives people leaving, which personal spreadsheets never do.

A typical session

You start from your main domain name. You put it down, add its registrar and its expiry date, then the exposed subdomains you know about.

Next you put down the lookalike domains reported in recent months, one per entity, with their creation date. Two of them were registered on the same day, through the same registrar: you link them to a common entity that you name for what it is, a grouped registration, without concluding anything about who did it.

You add the brand’s official accounts and the accounts reported as impersonations, noting the platform and the date of the report. You may well see the same handle come back.

On the supplier side, you put down the critical providers and what they themselves depend on when you know it. The links carry the nature of the dependency.

You export, and that map becomes the reference you will reopen at the next report.

What it does not do

The tool monitors nothing. It does not scan, does not alert and connects to no feed. Detection remains the job of your watch systems and your providers.

Nor does it replace a technical inventory held by IT. It serves to understand the relationships between the elements, not to guarantee they are all there.

The sensitive point

An exposure map is a sensitive document: it describes your dependencies and your weaknesses in the same place. It deserves the same care as a continuity plan.

That is an argument for keeping it on a machine you control rather than in an online service, and for only putting in it what serves a decision. The guide on choosing a tool covers the questions to ask before trusting a third party with this kind of document.

Move from reading to mapping.

Ositra brings your entities and their links onto one surface, on your own computer.

Open Ositra