A forgotten test system can be a production entry point

Test systems are built quickly, with weak credentials, real data and nobody watching, and then never turned off.

They are frequently connected to the same networks and sometimes to the same databases as production. An attacker does not care that a machine is labelled test; they care that it is reachable, unpatched and holds a credential that works elsewhere. The label describes an intention, not an isolation boundary.

More on Attack surface management