What does an attacker see from the outside?
Attackers often need no insider access. Publicly visible websites, open systems, forgotten subdomains and compromised credentials can be enough. Stage 1 creates this external view before someone else exploits it.
