Attribution across Indian group structures: whose asset is it
Why a holding company with a bank, an insurer and an NBFC beneath it breaks asset attribution, the five ways it presents, and how to establish the entity boundary before anyone acts on the findings.
Attribution is the criterion most shortlists ignore and most deployments stall on. A ratings platform infers which internet-facing assets belong to which organisation, and in India that inference meets a corporate structure it was not designed around: a holding company with a bank, an insurer, an asset manager and an NBFC beneath it, sharing a brand, frequently a domain tree, and sometimes a data centre.
The consequence is not a slightly wrong number. It is a rating that nobody inside the organisation accepts, and a programme that never gets past the argument about whose IP address it is.
Why group structures break the inference
Attribution works outwards from what is publicly observable — domain registration, DNS, certificate subjects, IP allocation, hosting relationships. Those signals identify abrand reliably and a legal entity far less reliably, and Indian conglomerates are precisely the case where the two come apart.
One brand, several regulated entities
A group operating a bank, a life insurer and an AMC has three licensed entities, three different regulators, and one name over the door. The bank answers to the RBI, the insurer to IRDAI, the AMC to SEBI. Externally they may share a registrar, a corporate domain, an SSO tenant and a certificate authority. Nothing in that public footprint says which licensed entity owns a given host.
Sponsored and affiliated entities
Indian financial structures produce relationships with no clean external signature — sponsored regional rural banks, corporate agents, business correspondents, joint ventures where a partner runs the technology. Each has a defensible claim to be inside or outside the perimeter depending on the question being asked.
Acquisitions that never finished migrating
An acquired brand keeps its domain for years because customers still use it. A migration gets to eighty per cent and stops because the remaining twenty per cent is hard. Both leave a long tail of hosts that are genuinely yours, genuinely exposed, and attached to a name nobody in the current organisation chart recognises.
The five ways it presents
| Symptom | Usual cause | What distinguishes it |
|---|---|---|
| Findings from a business you do not run | Sibling entities under one holding company share a brand, and often a domain tree | The disputed asset resolves to a subdomain of the group domain, not yours |
| Assets from a company you sold | Transitional brand licensing, or DNS never repointed after completion | Registration or hosting changed hands on a date you can name from the SPA |
| Addresses that were never yours | IP ranges released back to a provider and reissued to someone else | No corresponding host in your CMDB, and reverse DNS points elsewhere |
| A neighbour’s compromise on your record | Shared hosting, which a large share of the Indian mid-market runs on | The finding is on an IP hosting many unrelated names |
| Real exposure that is missing | An acquisition, or a sponsored entity, not yet associated with you | You know the estate is larger than the asset list says |
The last row is the one nobody disputes, because an under-stated rating produces no complaints. It is also the only one that represents risk you are carrying without seeing. An asset review that only removes things is a review optimised for the number rather than for the estate.
What a wrong asset list actually costs
- Internal rejection. A CISO shown findings from a sibling entity will reasonably conclude the platform does not understand the organisation, and the second meeting is harder to get than the first.
- Remediation effort spent on nothing. Engineering time on a host you do not control is time not spent on one you do, and it is the most expensive way to discover an attribution error.
- Evidence that does not match the licence. A supervisor asks about a specific regulated entity. Evidence covering a group is not evidence about that entity, and it invites a question you would rather not have asked.
- A contractual floor that binds the wrong party. Where a vendor agreement sets a minimum rating, the rating has to be of the entity that signed. Getting this wrong is discovered during a dispute, which is the worst moment for it.
Establishing the boundary before the findings
The sequence that works starts from the licence rather than from the asset list, because the asset list is the thing in question.
- Name the entity. Decide which legal entity the rating is of, and write it down. “The group” is not an answer, because no regulator supervises the group and no contract is signed by it.
- Get the estate from the people who run it. Domains from whoever holds the registrar account, IP ranges from networks, cloud tenancies from platform teams. These three lists rarely agree, and reconciling them is most of the work.
- Mark up the attributed list against it. Someone who knows the estate goes line by line: ours, not ours, ours but should sit under a sibling entity, and the one worth pausing on — ours and not on our own list.
- Resolve the siblings deliberately. Where group entities share infrastructure, decide once whether a shared host sits with the entity that operates it or the one that depends on it, and apply that consistently. Either rule works; changing rules between reviews does not.
- Re-run it after every transaction. An acquisition, a divestment or a brand migration invalidates the inventory. Attaching the review to deal completion is cheaper than rediscovering it a year later.
Getting attribution corrected
Every serious platform has a dispute process, and the quality of a submission decides how long it takes. A dispute that asserts an asset is not yours will be slower than one that shows why: registration records, the date and counterparty of a divestment, an IP allocation that moved, or a hosting relationship that explains a neighbour's finding.
Ask about this during evaluation rather than after purchase, and ask two specific questions: what evidence the process expects, and what the turnaround is in days. A vendor that cannot answer the second question has told you something about the first.
The same problem, pointed at your vendors
Attribution errors on your own estate are visible because someone recognises them. Attribution errors on a vendor are invisible, and there are more of them, because nobody in your organisation knows that supplier's estate well enough to notice.
The specific risk with Indian conglomerates is monitoring the wrong entity of the right group: your contract is with the technology subsidiary, and the rating on your dashboard is the listed parent. The two can differ substantially, and the one on the contract is the one that matters. When onboarding a vendor that belongs to a group, confirm which legal entity you are monitoring against the entity named in the agreement.
Where BitScore fits, and where it does not
Attribution is not a feature to be evaluated from a datasheet. Resolving a group's real external footprint is pattern recognition built from having done it repeatedly in this market, which is the part of the work BitScore does rather than the platform.
What is not on offer is a promise of a clean list on day one. The first attributed list for a large Indian group will contain errors in both directions, and the useful question is not whether they occur but how quickly they are found and how good the dispute submission is. BitScore publishes an open-source tool for this — the entity-scope skill validates the attributed footprint, flags likely mis-attributions and drafts the dispute submission — because the process benefits from being repeatable rather than remembered.
Read next
- How to improve your Bitsight rating — why attribution is step zero, before any remediation.
- Cyber security rating vendors in India — attribution accuracy as one of the six criteria that separate the platforms.
- What SEBI's CDSL order says about the assets you forgot to list — the same inventory problem, with a penalty attached.
The failure modes and the sequence above are drawn from BitScore's own delivery experience with Indian group structures rather than from published vendor documentation, and are described as practice rather than as platform behaviour. BitScore Cybertech LLP is an authorised Bitsight partner.
Questions this page answers
- Why do assets from another company appear in our rating?
- Usually because sibling entities under one holding company share a brand and often a domain tree, so public signals cannot tell which licensed entity owns a host. Other causes are divested businesses whose DNS was never repointed, IP ranges reissued to someone else, and shared hosting where a neighbour’s compromise lands on your record.
- What should we do before remediating any finding?
- Name the legal entity the rating is of, then reconcile the attributed list against domains from the registrar account, IP ranges from networks and tenancies from platform teams. Those three lists rarely agree, and reconciling them is most of the work. Remediating a host you do not control is the most expensive way to find an attribution error.
- One asset is attributed to two companies. Is that shared hosting?
- More often it is two records for the same organisation — the same group entered twice under different names, from an acquisition or a spelling variant. Checking for a duplicate entity before disputing a shared-hosting attribution saves a round trip, because the fix is a merge rather than a removal.
- How do we get an attribution corrected?
- Through the platform’s dispute process, and the quality of the submission decides the turnaround. A dispute that shows why — registration records, the date and counterparty of a divestment, an IP allocation that moved — resolves faster than one that simply asserts the asset is not yours.
- Does attribution matter for vendors as well as for us?
- More so, because nobody in your organisation knows a supplier’s estate well enough to spot an error. The specific risk with Indian conglomerates is monitoring the listed parent while contracting with a technology subsidiary. Confirm which legal entity you are monitoring against the entity named in the agreement.