
Operate
Threat intelligence and external exposure
Continuous monitoring of what an attacker can see about you from outside — leaked credentials, spoofed domains, executive impersonation, exposed infrastructure and brand abuse — routed into your response process rather than into a newsletter.
Duration
Baseline 2 weeks, then continuous
Built on
ISO/IEC 27001 Annex A
Who this is for
CISO
Knows the inside position and has no view of the outside one.
Finance director
Is the target of invoice fraud that begins with a domain nobody noticed.
Brand or marketing lead
Has counterfeit or cloned properties damaging conversion.
Executive team
Is impersonated, and usually finds out from a customer.
Your perimeter is the last place an attack starts
By the time something touches your infrastructure, the preparation is finished. The credentials were bought from a breach of an unrelated service where one of your people reused a password. The domain that will send the fraudulent invoice was registered three weeks ago and looks almost exactly like yours. The executive profile that will ask your finance team for an urgent payment already exists.
None of that is visible from inside your network, and no amount of endpoint tooling will show it to you. It sits in credential dumps, in domain registrations, on social platforms and in the parts of the internet where this material is traded.
Credential reuse is the single most common route in, and it is also the cheapest to close — if you know. Knowing that a specific address and password combination for one of your staff is circulating is the difference between forcing one password reset and investigating an intrusion six weeks later.
Domain abuse damages you before any system of yours is touched. A convincing typosquat can take invoice payments, harvest customer credentials and run recruitment scams in your name, and every one of those costs you money and trust while your infrastructure remains untouched and your monitoring stays green.
The failure mode of this category is a feed nobody acts on. Intelligence that arrives as a monthly PDF is a newsletter. Ours routes findings into the same response process as any other detection — a leaked credential triggers a reset, a fraudulent domain triggers a takedown request, and both appear in the same report as everything else.
How we do it
- 01
Footprint definition
3–5 days
What we are watching for: your domains, brands, executive names, product names, IP ranges and the variations an attacker would plausibly use. This list is more important than the tooling and it is the part clients under-invest in.
- 02
Baseline sweep
1 week
The current position — everything already exposed. The first report is usually the uncomfortable one, and it is also where most of the immediate value sits.
- 03
Continuous monitoring
ongoing
Credential exposure, domain registrations and certificate transparency, social and marketplace impersonation, exposed services and leaked documents.
- 04
Triage and routing
ongoing
Findings assessed for real risk in your context and routed — to a password reset, a takedown request, an internal warning, or the incident process where it warrants one.
- 05
Takedown
as required
Requests filed against fraudulent domains, profiles and listings, and tracked to outcome. Not every takedown succeeds, and we report the ones that do not.
- 06
Reporting and review
monthly
What was found, what was done, what is still open, and what the trend says.
Named artefacts
What you receive
- External footprint inventory — what is monitored and why
- Baseline exposure report
- Exposed credential findings, routed to reset as they appear
- Domain and certificate abuse register
- Executive and brand impersonation monitoring
- Takedown requests, tracked to outcome including failures
- Monthly exposure report with trend
- Findings routed into the detection and response process where they warrant it
What we need from you
- The definitive list of your domains, brands and executives — including the ones marketing registered and forgot.
- A named contact for credential findings who can force a reset without a change board.
- Legal or brand authority for takedown requests, since some require it.
- Tolerance for the first report. It is always worse than expected and that is the point of it.
What changes
- 01Leaked credentials are reset on discovery rather than on exploitation.
- 02Fraudulent domains are identified while they are still being prepared, not after the invoice is paid.
- 03Executive impersonation is found by you rather than reported to you by a customer.
- 04You know what your external attack surface actually is, including the assets nobody remembered.
- 05Exposure findings arrive in the same process as everything else, so they get acted on.
What it costs
On request
All prices exclude VAT.
Questions
Is this the same as a dark web scan?
Credential exposure is part of it, and it is the part most vendors sell on its own. The rest — domain abuse, impersonation, exposed infrastructure, leaked documents — is usually where the expensive incidents start.
Can you get a fraudulent domain taken down?
Often, and we file and track the request. Success depends on the registrar, the jurisdiction and the evidence. We report the failures as well as the successes, because knowing a hostile domain is still live is operationally useful.
How many findings should we expect?
The baseline is usually large and the steady state is small. Most of the initial volume is historical credential exposure that needs one clean-up pass.
Which tooling sits behind it?
Infoblox for threat intelligence and external exposure, alongside our own monitoring. We name our tooling rather than describing it as proprietary.

Leave with your top three risks documented
Thirty minutes with a senior practitioner. No slideware, no sales engineer.