RESOURCE / EN

Company internet exposure worksheet

A worksheet for assigning each public domain, IP, service, owner, MFA, patch date, business reason, and decision.

Use this worksheet for domains and addresses owned by the company or covered by explicit permission. It is an inventory, not permission to actively test someone else’s systems.

Review date:
Scope (domains, public IPs, cloud providers):
Reviewer:
Decision approver:

Register

Domain / public IP Service, protocol, and port System / provider Owner Authentication / MFA Last patch date Business reason Decision
close / restrict / keep
close / restrict / keep
close / restrict / keep

Include intermediary services: VPNs, remote-access gateways, provider consoles, edge devices, and DNS records pointing to unused infrastructure. “Unknown” is a valid value, but it needs an owner and a deadline for clarification.

Questions for every row

  • Must this service be reachable from the entire internet?
  • Do the name and address point to the expected system?
  • Has the owner confirmed the purpose and users?
  • Does MFA cover the actual login flow?
  • Are the version and last patch date known?
  • Can access be restricted to a VPN, gateway, or known sources?
  • Are successful and failed attempts and configuration changes logged?
  • Is there a rollback path that preserves administrative access?

For remote desktops, start with Internet-facing RDP is not a remote-work plan.

Decision and action

Item Decision Reason Action Owner Deadline Closure evidence
close / restrict / keep

Close — there is no current business reason, or the service has been replaced.
Restrict — access is needed, but not from every source or without another authentication layer.
Keep — the owner has confirmed the need, controls, and monitoring; the decision has a next review date.

Summary

Items without an owner:
Items without a known patch date:
Most urgent change:
Change owner:
Next review date:

This worksheet shows the state at the time of collection. It does not prove that no other services exist, and it does not replace an agreed security assessment.

Want this implemented or scoped?

The resource stays open. The form is for implementation, not an email gate.

The inquiry is stored on the server. You will get a short confirmation from hello@tomek.st. The operator is also notified on Telegram and email.