Step-by-step method
A reproducible path from question to conclusion.
- 1
Confirm the minimum observation
Record the address, date, access path and the smallest evidence needed to establish exposure. Do not explore directories or accounts that are not clearly public and authorised.
- 2
Classify visible data
Identify broad categories such as contact details, credentials, documents, technical secrets, financial records or vulnerable people. Avoid copying their content.
- 3
Estimate without scraping
Use limited indicators of volume, period, indexing and accessibility. A cautious range is better than mass collection that creates another sensitive copy.
- 4
Preserve proportionate evidence
Keep the URL, useful headers, contextual capture and observation metadata. Redact working copies while protecting any necessary original.
- 5
Reduce exposure
Alert the technical owner safely, remove public access or indexing when authorised, and avoid announcements that make the issue easier to find before remediation.
- 6
Organise the response
Maintain a timeline, identify affected people and duties, then involve security, legal, privacy, insurance and communications teams as appropriate.
Prove the issue without duplicating the harm
Exposure does not authorise downloading, testing or redistribution. Evidence should answer where, when and how access was observed.
Define a minimal sample, restrict case access and log transformations. Working copies can be redacted when full content is unnecessary.
Separate visibility, indexing and compromise
An indexed page, misconfigured storage and compromised account are different incidents. Do not infer technical origin from the visible outcome alone.
Keep observed, potential and confirmed scope separate to avoid overstatement and guide authorised technical checks.
Prioritise consequences for people
Authentication, health, financial, location or child-related data may need urgent action. Nature and context matter as much as record count.
Communication should help people protect themselves without revealing new exploitable detail or claiming an unconfirmed source or volume.
What to check and what to record
Use this grid to turn the method into a reviewable case file. A missing item remains an open question. The interpretation limit prevents a finding from becoming an unsupported conclusion.
| Check | Useful record | Interpretation limit |
|---|---|---|
| Observed access | URL, time, data type and observed access state. | Do not test credentials or access neighbouring folders. |
| Scope | Minimal lawful sample and potentially affected categories. | An exfiltration claim is not a confirmed leak. |
| Containment | Notified owner, action taken and closure evidence. | Public removal does not establish that no earlier copy exists. |
Common pitfalls
Four shortcuts that weaken the result.
Downloading everything
Mass collection creates a sensitive copy and may exceed necessity or authority.
Publishing raw evidence
A screenshot or public link can amplify exposure.
Equating exposure with attack
Origin and method require authorised investigation.
Announcing a precise volume too soon
Indexing or pagination indicators may not prove the real record count.
Practical questions
Frequently asked questions.
Should one data example be retained?
Only where necessary to establish exposure, in the smallest quantity and restricted storage.
Should visible people be contacted directly?
Not without scoping. Poorly planned notification can expose more data or disrupt the response.
Is public data harmless?
No. Aggregation, context or linkage to a person can create new risk.
Public references
CNIL. Breach documentation and notification criteria; assess the actual context.
Editorial scope
Published by Internet Intelligence Service on 15 September 2026. Last content update: 6 October 2026. This educational guide describes a lawful, defensive method. It is not legal advice, an emergency service or authority instruction.
