Retainer · Exposure

Executive Exposure Monitoring (Retainer)

Before anyone attacks your organisation, they research the people who run it. This tracks what that research would turn up — and tells you which parts you can actually do something about.

Targeted attacks start with reconnaissance, and reconnaissance starts with your leadership team.

A convincing payment-redirection email needs to know who your CFO is, who they report to, how your finance team writes, and when the CEO is travelling. Almost all of that is publicly assembled from conference bios, LinkedIn, press releases, filings and social accounts. None of it is secret, and none of it feels like a security problem individually.

Set against credentials from an old breach and a domain registered one character away from yours, it becomes the raw material for a very specific attack. This retainer watches that material and tells you when something changes.

What's included

Credential exposure checks — named executives and company domains checked against known breach corpora, with an assessment of whether it's actually still usable.

Lookalike domain monitoring — newly registered domains that typo-squat or impersonate yours, caught while they're still being set up.

OSINT footprint review — what an attacker can assemble about your leadership from public sources, written up as they would use it.

Actionable reduction advice — what to remove, change or lock down, ranked by how much it actually reduces risk.

Why we don't call this dark web monitoring

Because that term promises something nobody can honestly deliver. Most services sold under it are reselling the same aggregated breach feeds, and the implication — that someone is watching criminal forums on your behalf and will warn you before an attack — is largely theatre.

Breach corpora are one input here, and a useful one. But the value is in what an operator does with it: correlating a leaked credential against a lookalike domain registered last week and a spoofed profile of your CFO, and recognising that as the beginning of something. A feed cannot do that. We'd rather describe the work accurately and be judged on it.

Each month

Reconnaissance, run against yourself

01

Collect

Public sources, breach corpora, domain registrations and platform profiles gathered against your named scope.

02

Correlate

Signals connected to each other rather than reported in isolation — which is where the real warnings live.

03

Assess

An operator judges what is genuinely usable by an attacker today and what is old noise.

04

Reduce

A short list of what to change, with the items that meaningfully shrink your footprint at the top.

Where this ends

Monitoring is not protection

We cannot remove your information from the internet, we cannot force a platform to take a fake profile down, and we will not claim early warning of an attack. We can tell you what is exposed, what it enables, and what genuinely reduces it — and we'll support a takedown request rather than promise its outcome.

This is also not physical or personal security for your executives. If travel risk or personal protection is the concern, that is a different profession and you should engage one.

Find out what's already public

Tell us who you'd want covered. We'll scope it honestly, including telling you if your exposure is low enough that this isn't worth buying yet.