Hosting Provider Concentration and Infrastructure Mapping
How ASN data reveals whether an organization's infrastructure is centralized or spread across providers.
Core Concept
Resolving every IP behind an organization's domains and subdomains to their respective ASNs reveals a pattern that's easy to miss from any single lookup: how concentrated or distributed that organization's actual hosting footprint really is.
An organization running everything through one cloud provider's ASN has a very different infrastructure risk profile than one spread across a dozen independent providers, even if both appear equally reliable on the surface.
Reading Concentration Patterns
- Heavy reliance on a single ASN often indicates centralized cloud adoption
- Multiple ASNs across different providers can indicate multi-cloud strategy or historical infrastructure sprawl
- A mix of major cloud ASNs and small, unfamiliar ones can point to shadow IT or acquired subsidiary infrastructure
- Consistent ASN usage across all discovered subdomains often suggests strong centralized IT governance
Concentration Isn't Inherently Good or Bad
Centralization can mean strong governance and simplified management, or it can mean a single point of failure — the pattern alone doesn't tell you which.
Single-Provider Dependency Risk
Organizations running their entire public footprint through a single ASN carry meaningful concentration risk: a significant outage or issue at that provider affects everything at once, with no fallback infrastructure elsewhere.
This is a legitimate operational consideration worth surfacing during infrastructure review, vendor risk assessment, or resilience planning, independent of whether the provider itself is reliable in the general case.
Spotting Acquired or Legacy Infrastructure
When an organization's subdomains resolve to a mix of expected corporate ASNs alongside unfamiliar, unrelated ones, it can indicate infrastructure inherited from an acquisition that was never fully migrated or consolidated.
This pattern is worth flagging during technical due diligence, since unmigrated legacy infrastructure often carries weaker security posture and less consistent operational oversight than the parent organization's primary systems.
Mapping ASN Data at Scale
The most useful version of this analysis combines subdomain discovery with ASN resolution for every resolved IP, then aggregates the results to show the full distribution of providers an organization actually relies on.
This turns individual ASN lookups into an organizational-level infrastructure map, which is considerably more informative than reviewing hosts one at a time.
Real-World Implementation
Security teams and infrastructure architects use this kind of ASN distribution analysis during resilience planning, vendor risk assessment, and M&A technical due diligence to quickly understand an organization's actual hosting strategy.
It's also a common technique in competitive and market research, where the hosting patterns of a set of organizations can reveal broader trends in cloud provider adoption within an industry.
Common Mistakes to Avoid
- Assuming provider concentration is always a red flag rather than a deliberate strategy.
- Reviewing individual ASN lookups without aggregating them into a broader pattern.
- Overlooking unfamiliar ASNs mixed in with expected corporate infrastructure.
- Not revisiting infrastructure mapping after an acquisition or major migration.
- Treating a distributed footprint as automatically more resilient without deeper review.
Best Practices Checklist
- Combine subdomain discovery with ASN resolution to build a full infrastructure map.
- Flag heavy single-provider concentration as a resilience consideration, not a verdict.
- Investigate unfamiliar ASNs mixed into an otherwise consistent corporate footprint.
- Repeat infrastructure mapping after major migrations or acquisitions.
- Use the resulting map to inform vendor risk and resilience planning discussions.
Frequently Asked Questions
Is relying on a single hosting provider risky?
It carries concentration risk worth acknowledging, though it's also a common and often deliberate strategy for simplifying operations.
How do I build an infrastructure map from ASN data?
Resolve every discovered subdomain's IPs to their ASNs and aggregate the results to see the full distribution of providers in use.
What does an unfamiliar ASN mixed into corporate infrastructure usually mean?
It can indicate legacy or acquired infrastructure that was never fully consolidated, or occasionally shadow IT.
Does infrastructure spread across many ASNs mean better security?
Not automatically — it can also indicate inconsistent governance, so each provider's individual posture still needs review.
Why does this matter for M&A due diligence?
It helps validate infrastructure claims and can surface unmigrated legacy systems that carry their own distinct risk profile.
How often should infrastructure mapping be repeated?
Periodically, and especially after major migrations, acquisitions, or provider changes.
Map an Organization's Hosting Footprint
Resolve IPs to their ASNs to understand hosting concentration and provider distribution.
Launch Tool →