you can't secure what you can't see
expressionsecuritygovernance & risk
The visibility maxim: security begins with an accurate inventory of what exists, because unknown assets get no controls.
Why asset management leads every serious controls framework, unglamorous as it is. Shadow IT, forgotten subdomains, and orphaned cloud accounts are breaches waiting patiently for their moment; discovery is the first control.
You cannot secure what you cannot see is the argument that asset inventory precedes every other control, and it is correct in a way that most security programmes underweight because inventory is unglamorous and never finished.
The failures are consistent across organizations. A server nobody remembered is unpatched because no process included it. A cloud account created for a project three years ago still holds data and still has credentials. A subdomain points at a decommissioned service and can be claimed by whoever registers what it points to. None of these are sophisticated attacks; they are things nobody knew existed.
The uncomfortable part is that inventory is a moving target rather than a project. Cloud resources are created by anyone with an API key, devices arrive with the people carrying them, and the shadow IT that gets discovered is by definition the visible fraction. Continuous discovery is the only version that works, which means treating inventory as a live signal rather than a spreadsheet somebody updates annually, and accepting that the number is always slightly wrong.