Business
Business Security · Overview Shadow · Mailbox Forensics Fix Session · Implementation Executive Protection
Individual
Personal Protection · Overview Personal Credential Scan
Programs
Family Offices Wealth Firms Sports & Entertainment Agencies Reputation Threat Intelligence Wealth Manager Program Business Broker Program Partners
Intelligence
Research Library Threat Intelligence Global Breach Map Recent Breach Disclosures
Company
How It Works About Contact
Sign In
BREACH INDEX
Origin Energy · 2M records · Aug 2026 PEAR ransomware attack · 1.3M records · Aug 2026 Brown Health Medical Group-MA · 311K records · Aug 2026 Madera Community Hospital · 150K records · Aug 2026 Swiss federal IT office · 200 records · Aug 2026 Dutch retailer De Bijenkorf · Amsterdam-based luxury goods chain De Bijenkorf is the latest… · Aug 2026 FinWise Bank · Insider breach impacted approximately 689,000 customers · 2024 IDMerit · Unprotected database exposed 1 billion identity records used by banks… · 2026 Transport for London (TfL) · Cyber attack on transport network by hackers; caused £39M in damages · 2024 University of Hawaiʻi Cancer Center · Ransomware attack exposed data from Multiethnic Cohort Study… · 2026

Institutional cyber intelligence.

The same rigor Kroll and K2 charge Fortune 500 executives six figures for. Delivered inside a week, not eight.

Engagements are scoped annually by vertical. Mutual NDA before we go concrete.

Mutual NDA required| 72-hour delivery| Encrypted| Senior-analyst reviewed
EXPOSURE PERIMETERLT-2291
FIRM INFRASTRUCTURE 19 MEDIAN INNER CIRCLE 2 MODERATE HOUSEHOLD 3 HIGH PRINCIPAL 4 CRITICAL
PRINCIPAL SELECT A LAYER

Personal credentials, reused passwords, private addresses and every identifier tied to the named individual across breach repositories.

SENIOR-ANALYST REVIEWEDLAST SCAN 00:21 UTC
EXPOSURE TRAVELS WITH THE PERSON, NOT THE COMPANY
WHAT WE FIND · OUR OWN ASSESSMENTS
UPDATED CONTINUOUSLY
PEOPLE WE ASSESS
1 in 4
1 IN 6 HAS AN
EXPOSED PASSWORD

More than one in four individuals we scan appear in at least one monitored breach database. A quarter have personal data exposed outright.

WHAT A FIRST ASSESSMENT SURFACES
4
FIVE MORE ACROSS THE
HOUSEHOLD AND INNER CIRCLE

Four critical findings sit on the principal personally, before the firm’s own infrastructure is assessed.

LIVE · BUSINESS EMAIL COMPROMISE, YEAR TO DATE
$0

An attacker gets inside an inbox, watches finance traffic, then redirects a wire. Highest-loss internet-crime category the FBI tracks, ten years running.

HOW THE COUNTER RUNS
$3.04B
2025 FULL YEAR
FBI IC3
$10B+
ESTIMATED TRUE
GLOBAL LOSSES
$123K
AVERAGE LOSS
PER INCIDENT

TICKS FROM JAN 1 AT THE FBI'S REPORTED RUN RATE · SOURCES: FBI IC3, MICROSOFT DIGITAL DEFENSE, APWG ECRIME

01 · WHY NOW

Criminals already have this data.

Compromised credentials, infrastructure metadata and business identifiers persist across breach repositories, paste archives and broker networks, queryable since the moment they were stolen. What changed is the speed of what reads them: phishing generates in bulk, deepfake impersonation targets principals and their households, and stolen data is scraped and indexed within hours of a leak. Target lists build themselves. The difference between visibility and exposure is whether yours is mapped before an attacker acts on it.

THE COST, AS RECORDED
$20.9B
Internet crime losses recorded in 2025
FBI IC3 · UP 26% YOY
$4.44M
Average cost of a single business breach
IBM · 2025
241
Days to identify and contain a breach
IBM · 2025
$3.04B
Business email compromise losses, 2025
FBI IC3 · HIGHEST-LOSS CATEGORY
02 · HOW WE ENGAGE

One standard. Four perimeters.

Every engagement runs the same correlation and the same senior-analyst review. The only thing that changes is whose perimeter is in scope.

AEGIS FLAGSHIP

Firms & family offices

Continuous coverage across the firm, its principals and their households. Built for family offices, wealth firms, sports agencies and boutique counsel.

BUSINESS

Forensic audit

External attack surface assessment for professional firms. Analyst-grade briefing, sector-tuned regulatory mapping and a prioritised remediation playbook.

21 SECTORS COVERED
72-HOUR DELIVERY
Learn more
EXECUTIVE

Executives & principals

Deep-dive coverage on the principal, household and inner circle. For founders, GPs, general counsel and anyone whose exposure travels with the person.

PRINCIPAL + HOUSEHOLD
DEEPFAKE & IMPERSONATION
Learn more
ONGOING

Continuous coverage

Daily rescan, threshold-based alerting on new exposure and longitudinal trend intelligence. For firms whose attack surface changes weekly.

DAILY RESCAN
THRESHOLD ALERTING
Learn more
Scanning a single individual rather than a firm? Personal credential briefing →
03 · WHAT IT UNLOCKS

Clients renew for what it wins them.

Most firms commission the first briefing because something worried them. They renew because the document turns out to be worth more than the reassurance.

Diligence questions arrive from carriers, counterparties and prospective clients whether or not you are ready for them. A current briefing is the document that answers all of them in one pass.

01

Wins mandates

A family office or agency that can show current exposure intelligence answers the security question before a prospective principal has to ask it.

02

Survives the carrier audit

Cyber applications ask questions firms answer optimistically. When a claim is audited and the answers do not hold, the policy fails. Evidence beats attestation.

03

Protects the valuation

Exposure is a standard diligence line item in any transaction. A clean, dated file stops being a lever against your price.

04

Ends the guessing

Two hundred days of undetected access is the industry average. A mapped surface replaces an assumption with a dated, prioritised list.

04 · THE PRACTICE

Whatever you start with, the rest is already built.

Six products, seven channel programs, twenty-one sector playbooks and a published research library. Firms rarely arrive needing all of it, but nothing has to be invented when they do.

PRODUCTS 06
01Business forensic audit
02Shadow · mailbox forensics
03Executive protection
04Fix session
05Continuous monitoring
06Personal credential briefing
PROGRAMS 07
01Family offices
02Sports & entertainment
03Wealth managers
04Boutique counsel
05Business brokers
06Insurance brokers
07Referral partners
SECTORS 21
01Legal
02Medical & health
03Accounting & CPA
04Wealth & advisory
05Insurance
06Real estate
ALL SECTORS UNDER COVERAGE
01Legal
02Medical & health
03Accounting & CPA
04Wealth & advisory
05Insurance
06Real estate
07Private equity
08Venture capital
09Family enterprise
10Sports & entertainment
11Executive search
12Architecture & design
13Construction
14Logistics & freight
15Manufacturing
16Franchise groups
17Non-profit & foundation
18Education
19Hospitality
20Professional services
21Technology
05 · METHODOLOGY

Read-only, external, and finished in seventy-two hours.

01

Domain fingerprinting

Full enumeration of your external attack surface: DNS, certificates, exposed services and the infrastructure identifiers attackers see first.

02

Source correlation

Multi-source correlation across the same layers attacker tooling operates on: criminal marketplaces, breach repositories and paste archives.

03

Risk quantification

Findings are classified by severity and mapped to the statutory framework that applies to your sector.

04

Intelligence delivery

Executive summary, technical evidence, statutory mapping and a prioritised remediation roadmap. Senior-analyst reviewed.

05

Continuous surveillance

Daily rescans, threshold-based alerting on new exposure, and longitudinal trend analysis.

06 · INTELLIGENCE LAYER

The same sources attacker tooling reads.

Your profile is already assembled in the databases attacker infrastructure references. Nothing we surface is obtained illicitly; all of it is correlated from sources already in circulation.

READ-ONLY · NO INTRUSIVE TESTING
MUTUAL NDA BEFORE WE GO CONCRETE
EVIDENCE RETAINED ENCRYPTED
2026 BREACH INDEX 299,491 TRACKED
DISCLOSURESURFACEDCLASS
Origin Energy · 2M records AUG 2026 CRITICAL
PEAR ransomware attack · 1.3M records AUG 2026 CRITICAL
Brown Health Medical Group-MA · 311K records AUG 2026 CRITICAL
Madera Community Hospital · 150K records AUG 2026 CRITICAL
Swiss federal IT office · 200 records AUG 2026 MEDIUM
Dutch retailer De Bijenkorf · Amsterdam-based luxury goods chain De B… AUG 2026 MEDIUM
FinWise Bank · Insider breach impacted approximately 6… 2024 CRITICAL
SOURCES CORRELATED 04
01
Credential repositories

Billions of compromised credentials, cross-referenced by domain and email pattern.

02
Data broker indices

Contact records and organisational metadata across broker networks and registry filings.

03
Threat intelligence feeds

Paste archives and the monitored channels where stolen data first surfaces.

04
Infrastructure signals

DNS, certificate chains, open services and headers. The surface attacker scouting maps first.

See what is already exposed. 72 HOURS · MUTUAL NDA · READ-ONLY
Request discovery call
06 · MAPPED AGAINST

Findings arrive already mapped to the rule that applies to you.

Every finding in the briefing carries the statutory reference a regulator, carrier or counterparty would cite. Your counsel does not have to translate an engineering report into an obligation.

01
SEC REG S-P

Safeguards and disposal rules for customer records held by registered advisers and broker-dealers.

02
GLBA

The federal standard for protecting non-public personal information at financial institutions.

03
FINRA

Supervisory and recordkeeping obligations examined at member firms.

04
HIPAA

Safeguards for protected health information and the records that identify patients.

05
PIPEDA

Canadian obligations for personal information held in the course of commercial activity.

06
NIST CSF 2.0

The control framework counterparties and carriers most often ask firms to map against.

07
SOC 2

The attestation criteria buyers request during vendor and transaction diligence.

+
Sector-specific mapping

Each briefing cites the frameworks that govern your sector, not the full list.

FULL MAPPING →
07 · QUESTIONS

What firms ask before they engage

Do you touch our systems?

No. Every assessment is read-only and external. We correlate publicly available and breach-sourced data and analyse what your infrastructure already publishes. No intrusive testing, no agents, no access to your network.

Why does this cost less than Kroll?

Because correlation is automated and only the analysis is billed at senior rates. The intelligence layers are the same. What you are not paying for is a Fortune 500 engagement structure you do not need.

What happens to the evidence?

Retained encrypted, disclosed only to you, and destroyed on request. A mutual NDA is signed before we discuss anything specific about your exposure.

How long does it take?

Seventy-two hours for the briefing suite from the point scope is agreed. Boutique intelligence firms typically quote six to eight weeks for comparable work.

Can we act on it without a security team?

Yes. The remediation roadmap is prioritised and written for an operator, not an analyst. Firms without internal security are the majority of our clients.

What if you find nothing serious?

You get that in writing, dated and signed. That document answers carrier applications, client diligence questionnaires and counterparty requests on its own.

08 · DISCOVERY CALL

Find out what your exposure looks like from outside.

Twenty minutes, under mutual NDA. We scope what is in range, confirm a delivery date, and tell you plainly whether an engagement is worth it for a firm your size.

Mutual NDA BEFORE ANYTHING SPECIFIC
Briefing delivery 72 HOURS FROM SCOPE
Evidence handling ENCRYPTED · YOURS ALONE
Institutional engagements SCOPED ANNUALLY BY VERTICAL
DISCOVERY REQUESTENCRYPTED

MUTUAL NDA · ENCRYPTED · NO OBLIGATION