Threat & Exposure
Intelligence
Investigating external exposure and related threats
We turn what is happening outside into evidence you can decide on.
We investigate external information about your organization, brand, accounts, assets and services. We check its source, timing, relationships, history and actual relevance to you, then explain what the risk means and what to check and act on first.
What can be seen from outside, and which threats are relevant? Reviewed
We set out the evidence, what has changed, and what to check and act on first.
Three parts
Depending on your goal, choose a fixed-term assessment, an in-depth investigation of a specific matter or ongoing observation, or combine them.
- Threat & Exposure AssessmentAssessment and advice
We investigate external exposure and signs of leaks and impersonation, and set out the evidence, possible impact and priorities for action.
- Threat InvestigationIn-depth investigation
We analyze how a specific signal, incident, attack infrastructure or campaign connects to others and what history lies behind it. We separate confirmed facts from assumptions and state the limits of the information.
- Threat & Exposure MonitoringOngoing monitoring
We observe and review changes in agreed targets and sources. The observation interval, alert criteria, analyst review and the scope of response support are each agreed before we start.
Our technology, reviewed by experts
Our own intelligence and analysis technology links many external observations through their relationships and history. Experts then review the timing, source and relevance to you of each result before it is used in an investigation or decision.
What you receive
The information observed and its evidence, what the risk means, and what to confirm and act on first.
Evidence and sources
The source and timing of each observation and its relevance to you, with the supporting evidence.
Facts kept apart from assumptions
Confirmed facts are separated from assumptions, and the limits of the information and what still needs checking are stated.
Priorities for checking and response
What to check or act on first, based on the likely impact.
An exposure signal is a reason to check, not proof that a breach has happened or that it can be exploited.
To test your detection and response against scenarios built from threat intelligence: About Threat-Led Penetration Testing (TLPT)