Business
Business Security · Overview
Individual
Personal Protection · Overview Personal Credential Briefing
Programs
Perimeter · Households Wealth Firms Sports & Entertainment Agencies Reputation Threat Intelligence Wealth Manager Program Business Broker Program Partners
Intelligence
Research Library Threat Intelligence Global Breach Map Recent Breach Disclosures
Company
How It Works About Contact
Sign In
Breach index
McKesson284M recordsSep 2026 Russian pizza restaurant chain68M recordsSep 2026 Gyazo24M recordsSep 2026 Aeroméxico15M recordsSep 2026 Carhartt13M recordsSep 2026 Aesto Health9.5M recordsSep 2026 Manchester Airport Group8.7M recordsSep 2026 CenterPoint Energy7.5M recordsSep 2026 Times Car6.6M recordsSep 2026 ShinyHunters6.4M recordsSep 2026
Independent exposure intelligence, read from outside

Institutional cyber intelligence.

For firms, their principals and their households. The view an attacker gets from outside, correlated across the sources attacker tooling reads, audited against the obligations your sector answers to, and handed back as a prioritised plan, verified closed.

Read-only. Delivered inside 72 hours of confirmation. Mutual NDA before we go concrete. Includes what AI assistants now tell your clients about you.

Mutual NDA required| 72-hour delivery| Read-only| Human-reviewed before release
EXPOSURE PERIMETERLT-2291
FIRM INFRASTRUCTURE 19 MEDIAN INNER CIRCLE 2 MODERATE HOUSEHOLD 3 HIGH PRINCIPAL 4 CRITICAL
PRINCIPAL SELECT A LAYER

Personal credentials, reused passwords, private addresses and every identifier tied to the named individual across breach repositories.

HUMAN-REVIEWED BEFORE RELEASEILLUSTRATIVE EXAMPLE
EXPOSURE TRAVELS WITH THE PERSON, NOT THE COMPANY
This week · 29 Sep 2026

What attackers used this week, and what we check for it.

179 organisations were listed on criminal leak sites in the last 7 days, by 44 different groups. Of these, 45 were in the United States and 5 in Canada.

Source: public ransomware leak-site listings
28 Sep 2026DataBreaches.net

Telecommunications companies

A former U.S. Army soldier was sentenced to 70 months in prison for hacking into the databases of at least 10 organizations, including telecommunications companies, and attempting to extort over $1 million. The threat …

How they got in
Stolen or reused passwords.
What we check
Staff addresses present in monitored breach databases.
28 Sep 2026CBC

Health P.E.I.

Health P.E.I. announced that personal information belonging to approximately 234,000 individuals was compromised in a data breach. The incident occurred through service provider Maximus Canada, where an unauthorized person accessed a...

How they got in
A supplier or vendor that was compromised first.
What we check
The outside services your domain depends on.
28 Sep 2026TechCrunch

A grandfather fooled by a cloned voice

An individual was scammed into paying a ransom after receiving a phone call featuring an AI-generated deepfake voice impersonating his brother. The caller claimed the brother had been kidnapped, leading the victim to pay …

How they got in
A cloned voice or video of a real person.
What we check
Public audio, video and accounts using a principal's name.
ESTIMATE · BUSINESS EMAIL COMPROMISE, YEAR TO DATE
$0

An attacker gets inside an inbox, watches finance traffic, then redirects a wire. One of the costliest internet-crime categories the FBI tracks.

HOW THE COUNTER RUNS
$3.05B
REPORTED LOSSES, 2025
24,768 COMPLAINTS
$123K
AVERAGE REPORTED
LOSS PER COMPLAINT

TICKS FROM JAN 1 AT THE 2025 REPORTED RATE · SOURCE: FBI IC3 2025 INTERNET CRIME REPORT

01 · WHY NOW

Criminals already have this data.

Compromised credentials, infrastructure metadata and business identifiers persist across breach repositories, paste archives and broker networks, queryable since the moment they were stolen. What changed is the speed of what reads them: phishing generates in bulk, deepfake impersonation targets principals and their households, and stolen data is scraped and indexed within hours of a leak. Target lists build themselves. The difference between visibility and exposure is whether yours is mapped before an attacker acts on it.

THE COST, AS RECORDED
$20.9B
Internet crime losses recorded in 2025
FBI IC3 · UP 26% YOY
$4.44M
Average cost of a single business breach
IBM · 2025
241
Days to identify and contain a breach
IBM · 2025
$3.05B
Business email compromise losses, 2025
FBI IC3 · 2025
02 · HOW WE ENGAGE

One standard. Four perimeters.

Every engagement runs the same correlation and the same human review before release. The only thing that changes is whose perimeter is in scope.

INSTITUTIONAL FLAGSHIP

Owner-run professional firms

Coverage across the firm, its principals and their households. Built for law, accounting and wealth firms, sports agencies and boutique counsel.

BUSINESS

The audit

External exposure assessment for professional firms: the Owner Summary and Action Brief, Technical Evidence and Findings, the Rules and Insurance Briefing and the Signed Assessment Record.

21 SECTORS COVERED
INSIDE 72 HOURS
Learn more
EXECUTIVE

Executives & principals

Deep-dive coverage on the principal, household and inner circle. For founders, GPs, general counsel and anyone whose exposure travels with the person.

PRINCIPAL + HOUSEHOLD
DEEPFAKE & IMPERSONATION
Learn more
ONGOING

Monitoring

Daily re-checks, an alert when something new appears, and a record of how exposure changes over time. For firms whose exposure changes week to week.

DAILY RE-CHECKS
ALERTS ON NEW EXPOSURE
Learn more
Looking at a single individual rather than a firm? Personal credential briefing →
03 · WHAT IT UNLOCKS

Clients renew for what it wins them.

Most firms commission the first briefing because something worried them. They renew because the document turns out to be worth more than the reassurance.

Diligence questions arrive from carriers, counterparties and prospective clients whether or not you are ready for them. A current briefing is the document that answers all of them in one pass.

01

Wins mandates

A firm that can show a current exposure briefing answers the security question before a prospective client has to ask it.

02

Survives the carrier audit

Cyber applications ask questions firms answer optimistically. When a claim is audited and the answers do not hold, the policy fails. Evidence beats a self-declared answer.

03

Protects the valuation

Exposure is a standard diligence line item in any transaction. A clean, dated file stops being a lever against your price.

04

Ends the guessing

In 2025 a breach took an average of 241 days to identify and contain (IBM). A mapped surface replaces an assumption with a dated, prioritised list.

04 · THE PRACTICE

Whatever you start with, the rest is already built.

Four products, seven channel programs, twenty-one sector playbooks and a published research library. Firms rarely arrive needing all of it, but nothing has to be invented when they do.

PRODUCTS 04
01Business audit
02Executive protection
03Monitoring, re-checked daily
04Personal credential briefing
PROGRAMS 07
01Law & accounting firms
02Sports & entertainment
03Wealth managers
04Boutique counsel
05Business brokers
06Insurance brokers
07Referral partners
SECTORS 21
01Legal
02Medical & health
03Accounting & CPA
04Wealth & advisory
05Insurance
06Real estate
ALL SECTORS UNDER COVERAGE
01Legal
02Medical & health
03Accounting & CPA
04Wealth & advisory
05Insurance
06Real estate
07Private equity
08Venture capital
09Family enterprise
10Sports & entertainment
11Executive search
12Architecture & design
13Construction
14Logistics & freight
15Manufacturing
16Franchise groups
17Non-profit & foundation
18Education
19Hospitality
20Professional services
21Technology
05 · METHODOLOGY

Read-only, external, and finished in seventy-two hours.

01

Domain fingerprinting

Enumeration of your external attack surface: DNS, certificates, exposed services and the infrastructure identifiers attackers see first.

02

Source correlation

Multi-source correlation across the layers attacker tooling reads: breach repositories, paste sites and public records.

03

Risk quantification

Findings are classified by severity and mapped to the statutory framework that applies to your sector.

04

Intelligence delivery

A private dashboard of every finding with its fix, the Owner Summary and Action Brief, Technical Evidence and Findings, the Rules and Insurance Briefing, the Signed Assessment Record and a prioritised remediation plan, verified closed once it is done. Reviewed by a person before release.

05

Ongoing monitoring

Daily re-checks, an alert when something new appears, and a record of change over time.

06 · INTELLIGENCE LAYER

The same sources attacker tooling reads.

Your profile is already assembled in the databases attacker infrastructure references. Nothing we surface is obtained illicitly; all of it is correlated from sources already in circulation.

READ-ONLY · NO INTRUSIVE TESTING
MUTUAL NDA BEFORE WE GO CONCRETE
EVIDENCE DISCLOSED ONLY TO YOU
2026 BREACH INDEX 1,900+ TRACKED
DISCLOSURESURFACEDCLASS
McKesson · 284M records SEP 2026 CRITICAL
Russian pizza restaurant chain · 68M records SEP 2026 CRITICAL
Gyazo · 24M records SEP 2026 CRITICAL
Aeroméxico · 15M records SEP 2026 CRITICAL
Carhartt · 13M records SEP 2026 CRITICAL
Aesto Health · 9.5M records SEP 2026 CRITICAL
Manchester Airport Group · 8.7M records SEP 2026 CRITICAL
SOURCES CORRELATED 04
01
Credential repositories

Billions of compromised credentials, cross-referenced by domain and email pattern.

02
Public records

Published business listings, corporate registry filings and the firm’s own public pages.

03
Threat intelligence feeds

Paste sites where stolen data is posted, and public threat-reputation lists.

04
Infrastructure signals

DNS, certificate chains, open services and headers. The surface attacker scouting maps first.

See what is already exposed. 72 HOURS · MUTUAL NDA · READ-ONLY
Request discovery call
07 · MAPPED AGAINST

Findings arrive already mapped to the rule that applies to you.

Every finding in the briefing carries the statutory reference a regulator, carrier or counterparty would cite. Your counsel does not have to translate an engineering report into an obligation.

01
SEC REG S-P

Safeguards and disposal rules for customer records held by registered advisers and broker-dealers.

02
GLBA

The federal standard for protecting non-public personal information at financial institutions.

03
FINRA

Supervisory and recordkeeping obligations examined at member firms.

04
HIPAA

Safeguards for protected health information and the records that identify patients.

05
PIPEDA

Canadian obligations for personal information held in the course of commercial activity.

06
NIST CSF 2.0

The control framework counterparties and carriers most often ask firms to map against.

07
SOC 2

The trust services criteria buyers ask about during vendor and transaction diligence.

+
Sector-specific mapping

Each briefing cites the frameworks that govern your sector, not the full list.

FULL MAPPING →
08 · QUESTIONS

What firms ask before they engage

Do you touch our systems?

No. Every assessment is read-only and external. We correlate publicly available and breach-sourced data and analyse what your infrastructure already publishes. No intrusive testing, no agents, no access to your network.

Why does this cost less than a consulting engagement?

Because collection and correlation are automated, and a person’s time goes into review and analysis. What you are not paying for is a large engagement team you do not need.

What happens to the evidence?

Disclosed only to you, kept until you ask us to delete it, and deleted when you do. A mutual NDA is signed before we discuss anything specific about your exposure.

How long does it take?

The documents are delivered inside 72 hours of confirmation, after a person has reviewed them.

Can we act on it without a security team?

Yes. The remediation roadmap is prioritised and written for an operator, not an analyst. Firms without internal security are the majority of our clients.

What if you find nothing serious?

You get that in writing, dated and signed. That document answers carrier applications, client diligence questionnaires and counterparty requests on its own.

09 · DISCOVERY CALL

Find out what your exposure looks like from outside.

Twenty minutes, under mutual NDA. We scope what is in range, confirm a delivery date, and tell you plainly whether an engagement is worth it for a firm your size.

Mutual NDA BEFORE ANYTHING SPECIFIC
Delivery commitment INSIDE 72 HOURS OF CONFIRMATION
Every finding SOURCE ATTACHED · RE-RUNNABLE
Evidence handling YOURS ALONE
Institutional engagements SCOPED ANNUALLY BY VERTICAL
DISCOVERY REQUEST

MUTUAL NDA · NO OBLIGATION