They do not get your internal diagram

From inside, you know which system is production and which project died last year. An outsider sees names, pages, documents and services. Your carefully drawn boundary is not part of the view. The forgotten project may look just as relevant as the flagship product.

That is a useful exercise for defenders: forget what you know for a moment. Read your own site, search results and public repositories as a stranger. What would you think the business uses? Which services look important? Which answers are guesses?

Small clues can make a convincing story

A job advertisement names a tool. A public help page explains a workflow. A screenshot reveals an internal project name. None of those is automatically a security incident. Together, they may provide context someone could misuse to make an impersonation attempt sound credible.

The answer is not to delete every trace of the company. People still need to find the business, understand its work and apply for jobs. Review unnecessary technical detail, stale documents and overshared screenshots. Keep the information that actually serves the reader.

Write a portrait, not a verdict

Keep three columns: what is visible, what it suggests and what would confirm it. “This page mentions a provider” is defensible. “That provider gives access to their customer data” needs much more evidence. This little distinction stops a lot of bad reports.

Keep the exercise about your organisation’s public footprint, not employees’ private lives. Ask a colleague unfamiliar with the infrastructure to repeat it. The difference between their picture and yours often reveals exactly which old pages or confusing service names need attention.

Further reading