The Internet sees what you expose, not what your CMDB remembers

An attacker looks at what is actually reachable. Your records describe what somebody once wrote down.

The gap between those two is where incidents live. Scanning your own external footprint the way an outsider would, regularly, routinely finds things nobody knew were public: a forgotten interface, a test environment, a service that was supposed to be internal. The record is a description of intent; exposure is a fact.

More on Attack surface management