Practice

Attribution across Indian group structures: whose asset is it

Why a holding company with a bank, an insurer and an NBFC beneath it breaks asset attribution, the five ways it presents, and how to establish the entity boundary before anyone acts on the findings.

In short
Attribution infers which assets belong to which organisation from public signals, and those signals identify a brand more reliably than a legal entity. Indian groups running a bank, an insurer and an NBFC under one name break that inference. Establish which licensed entity the rating is of before reviewing the asset list, because that list is what is in question.

Attribution is the criterion most shortlists ignore and most deployments stall on. A ratings platform infers which internet-facing assets belong to which organisation, and in India that inference meets a corporate structure it was not designed around: a holding company with a bank, an insurer, an asset manager and an NBFC beneath it, sharing a brand, frequently a domain tree, and sometimes a data centre.

The consequence is not a slightly wrong number. It is a rating that nobody inside the organisation accepts, and a programme that never gets past the argument about whose IP address it is.

Why group structures break the inference

Attribution works outwards from what is publicly observable — domain registration, DNS, certificate subjects, IP allocation, hosting relationships. Those signals identify abrand reliably and a legal entity far less reliably, and Indian conglomerates are precisely the case where the two come apart.

One brand, several regulated entities

A group operating a bank, a life insurer and an AMC has three licensed entities, three different regulators, and one name over the door. The bank answers to the RBI, the insurer to IRDAI, the AMC to SEBI. Externally they may share a registrar, a corporate domain, an SSO tenant and a certificate authority. Nothing in that public footprint says which licensed entity owns a given host.

Sponsored and affiliated entities

Indian financial structures produce relationships with no clean external signature — sponsored regional rural banks, corporate agents, business correspondents, joint ventures where a partner runs the technology. Each has a defensible claim to be inside or outside the perimeter depending on the question being asked.

Acquisitions that never finished migrating

An acquired brand keeps its domain for years because customers still use it. A migration gets to eighty per cent and stops because the remaining twenty per cent is hard. Both leave a long tail of hosts that are genuinely yours, genuinely exposed, and attached to a name nobody in the current organisation chart recognises.

The five ways it presents

SymptomUsual causeWhat distinguishes it
Findings from a business you do not runSibling entities under one holding company share a brand, and often a domain treeThe disputed asset resolves to a subdomain of the group domain, not yours
Assets from a company you soldTransitional brand licensing, or DNS never repointed after completionRegistration or hosting changed hands on a date you can name from the SPA
Addresses that were never yoursIP ranges released back to a provider and reissued to someone elseNo corresponding host in your CMDB, and reverse DNS points elsewhere
A neighbour’s compromise on your recordShared hosting, which a large share of the Indian mid-market runs onThe finding is on an IP hosting many unrelated names
Real exposure that is missingAn acquisition, or a sponsored entity, not yet associated with youYou know the estate is larger than the asset list says
How attribution problems arrive, and the check that distinguishes them. The symptom is usually reported by someone who is annoyed, which is why identifying the cause first is worth the delay.

The last row is the one nobody disputes, because an under-stated rating produces no complaints. It is also the only one that represents risk you are carrying without seeing. An asset review that only removes things is a review optimised for the number rather than for the estate.

What a wrong asset list actually costs

  • Internal rejection. A CISO shown findings from a sibling entity will reasonably conclude the platform does not understand the organisation, and the second meeting is harder to get than the first.
  • Remediation effort spent on nothing. Engineering time on a host you do not control is time not spent on one you do, and it is the most expensive way to discover an attribution error.
  • Evidence that does not match the licence. A supervisor asks about a specific regulated entity. Evidence covering a group is not evidence about that entity, and it invites a question you would rather not have asked.
  • A contractual floor that binds the wrong party. Where a vendor agreement sets a minimum rating, the rating has to be of the entity that signed. Getting this wrong is discovered during a dispute, which is the worst moment for it.

Establishing the boundary before the findings

The sequence that works starts from the licence rather than from the asset list, because the asset list is the thing in question.

  1. Name the entity. Decide which legal entity the rating is of, and write it down. “The group” is not an answer, because no regulator supervises the group and no contract is signed by it.
  2. Get the estate from the people who run it. Domains from whoever holds the registrar account, IP ranges from networks, cloud tenancies from platform teams. These three lists rarely agree, and reconciling them is most of the work.
  3. Mark up the attributed list against it. Someone who knows the estate goes line by line: ours, not ours, ours but should sit under a sibling entity, and the one worth pausing on — ours and not on our own list.
  4. Resolve the siblings deliberately. Where group entities share infrastructure, decide once whether a shared host sits with the entity that operates it or the one that depends on it, and apply that consistently. Either rule works; changing rules between reviews does not.
  5. Re-run it after every transaction. An acquisition, a divestment or a brand migration invalidates the inventory. Attaching the review to deal completion is cheaper than rediscovering it a year later.

Getting attribution corrected

Every serious platform has a dispute process, and the quality of a submission decides how long it takes. A dispute that asserts an asset is not yours will be slower than one that shows why: registration records, the date and counterparty of a divestment, an IP allocation that moved, or a hosting relationship that explains a neighbour's finding.

Ask about this during evaluation rather than after purchase, and ask two specific questions: what evidence the process expects, and what the turnaround is in days. A vendor that cannot answer the second question has told you something about the first.

The same problem, pointed at your vendors

Attribution errors on your own estate are visible because someone recognises them. Attribution errors on a vendor are invisible, and there are more of them, because nobody in your organisation knows that supplier's estate well enough to notice.

The specific risk with Indian conglomerates is monitoring the wrong entity of the right group: your contract is with the technology subsidiary, and the rating on your dashboard is the listed parent. The two can differ substantially, and the one on the contract is the one that matters. When onboarding a vendor that belongs to a group, confirm which legal entity you are monitoring against the entity named in the agreement.

Where BitScore fits, and where it does not

Attribution is not a feature to be evaluated from a datasheet. Resolving a group's real external footprint is pattern recognition built from having done it repeatedly in this market, which is the part of the work BitScore does rather than the platform.

What is not on offer is a promise of a clean list on day one. The first attributed list for a large Indian group will contain errors in both directions, and the useful question is not whether they occur but how quickly they are found and how good the dispute submission is. BitScore publishes an open-source tool for this — the entity-scope skill validates the attributed footprint, flags likely mis-attributions and drafts the dispute submission — because the process benefits from being repeatable rather than remembered.

The failure modes and the sequence above are drawn from BitScore's own delivery experience with Indian group structures rather than from published vendor documentation, and are described as practice rather than as platform behaviour. BitScore Cybertech LLP is an authorised Bitsight partner.

Questions this page answers

Why do assets from another company appear in our rating?
Usually because sibling entities under one holding company share a brand and often a domain tree, so public signals cannot tell which licensed entity owns a host. Other causes are divested businesses whose DNS was never repointed, IP ranges reissued to someone else, and shared hosting where a neighbour’s compromise lands on your record.
What should we do before remediating any finding?
Name the legal entity the rating is of, then reconcile the attributed list against domains from the registrar account, IP ranges from networks and tenancies from platform teams. Those three lists rarely agree, and reconciling them is most of the work. Remediating a host you do not control is the most expensive way to find an attribution error.
One asset is attributed to two companies. Is that shared hosting?
More often it is two records for the same organisation — the same group entered twice under different names, from an acquisition or a spelling variant. Checking for a duplicate entity before disputing a shared-hosting attribution saves a round trip, because the fix is a merge rather than a removal.
How do we get an attribution corrected?
Through the platform’s dispute process, and the quality of the submission decides the turnaround. A dispute that shows why — registration records, the date and counterparty of a divestment, an IP allocation that moved — resolves faster than one that simply asserts the asset is not yours.
Does attribution matter for vendors as well as for us?
More so, because nobody in your organisation knows a supplier’s estate well enough to spot an error. The specific risk with Indian conglomerates is monitoring the listed parent while contracting with a technology subsidiary. Confirm which legal entity you are monitoring against the entity named in the agreement.

See where you actually stand.

Your organisation already has a rating, calculated from signals anyone can see. Request the complimentary Cyber Risk Rating Report and find out what it says — as little as 45 minutes for publicly listed entities, up to 48 hours for all others. No agent, no system access, no questionnaire.

Request my rating Read the FAQ