Why now
See what your underwriter sees, before you sign.
Insurance renewal forms ask about email authentication, multi-factor sign-in, backups and patching. Then there is wire fraud: someone can send email as your firm. Then your regulator or professional body. Most break-ins start with something anyone could see.
We watch your firm the way an attacker’s tools would: email that can be forged in your name, staff addresses in monitored breach databases, look-alike domains, and how those combine into a way in.
Reported losses to business email fraud reached $3,046,598,558 in 2025 in the United States (FBI IC3 2025 Internet Crime Report), and Canadians reported $67,900,000 CAD lost to spear phishing in 2025 (Canadian Anti-Fraud Centre). Every week we log how firms like yours were reached, and the finding that would have shown it first: this week’s incidents.
United States: In 2025 the FBI received more than 22,000 complaints reporting AI-related information, with adjusted losses over $893 million. FBI IC3, 2025 Internet Crime Report. Canada: The Canadian Centre for Cyber Security says AI technologies are “almost certainly lowering the barriers to entry” for malicious cyber activity. National Cyber Threat Assessment 2025-2026.
Breaches that began with a stolen or reused login
Verizon DBIR 2025, 9,891 breaches with a known way in
Breaches that began with a known, unpatched flaw
Verizon DBIR 2025, 9,891 breaches with a known way in
Breaches with a third party involved
Verizon DBIR 2025, share of all breaches analysed
Source: Verizon Data Breach Investigations Report, 2025.
23%
Firms assessed with at least one staff address in monitored breach records
of 2,507 firms assessed, April to October 2026
79%
Firms assessed whose email can be forged in their name (no DMARC enforcement)
of 2,512 firms assessed, April to October 2026