Digital risk protection
In external security, digital risk protection is the monitoring of channels outside your perimeter for threats that use your name or your data: impersonation, lookalike domains, leaked credentials, exposed documents and stolen data offered for sale. Nothing it finds is on your network, which is exactly why nothing else finds it.
How it works
Collection runs across several surfaces. Newly registered domains resembling the client’s, together with certificate transparency records that reveal them the moment a certificate is issued. Criminal marketplaces and forums where access and data are traded. Ransomware leak sites. Code repositories and file sharing services where credentials and internal documents are published by accident. Social platforms and application stores, for impersonated profiles and cloned applications.
Findings are triaged for relevance, verified, and then acted on, which usually means a takedown request to a registrar, a hosting provider or a platform. The discipline overlaps with threat intelligence but is narrower and more operational: it is about your name and your data specifically, rather than about adversaries in general.
What goes wrong
Volume without verification. Automated monitoring for a brand name produces a large number of matches that are coincidental, and a service that forwards them all transfers the analysis to the client, who then stops reading. What makes it worth having is the verification step and the response, not the collection.
The second issue is treating each finding in isolation. A lookalike domain registered on its own is a nuisance. A lookalike domain registered a week after credentials for the same organisation appeared in an infostealer log is a campaign in preparation, and the value is in the correlation.
Third, takedown is slow and partial. A registrar may act in days, a hosting provider may not act at all, and the same content reappears elsewhere. It is worth doing and it is not a control, so a lookalike domain should also produce a defensive action inside the estate: block it, alert on resolutions to it, and warn the people most likely to be targeted through it.
Where this shows up in an audit
This runs as a service rather than as an engagement, and its output feeds two others. Exposed credentials and sessions become immediate remediation with session revocation, not just password resets. Lookalike domains and impersonation feed the scenario design for social engineering exercises, because the most realistic simulation uses the infrastructure an attacker is actually preparing. Findings are reported with the evidence, the assessed relevance and the action taken, since an alert with neither is a search result. This is part of how we monitor your brand and exposed data outside the perimeter.