The necessary ones make the site work. The others measure which pages help and which ads bring the people who need DM11. Your choice, and you can revisit it from the footer.
CYBER THREAT INTELLIGENCE
Threat intelligence is watching what is said and what is sold about your company outside the perimeter, and turning every signal into a defence decision. An employee credential in a breach, a domain that looks like yours registered by someone else, your brand used in a scam, data for sale in a closed forum. The gain is time: you find out when it appears, and not from the customer who called asking about an email you never sent.
We watch the assets you authorise us to follow, your domains, your brand, your executives, and the sources within our reach. We do not break into systems, we do not buy criminal access, and we handle the data we find for a security purpose, discarding what does not matter. Intelligence is not blocking and it is not incident response: it informs the decision, and containment comes afterwards, with whoever does containment.
Who runs the watch
An in-house Cyber Intelligence Centre
Coverage of the open internet, Deep Web, Dark Web and closed groups, within what is accessible
An analyst who reads the signal and recommends the action, not only collects it
17 years of governance, risk and compliance
WHAT IT IS
Threat intelligence is not a tool you switch on and forget. What you buy is the reading: someone who tells the real breach from the recycled combolist, who confirms which credential still matters, and who ties the finding to what your business cannot afford to lose. A list of alerts nobody reads is not intelligence, it is noise with a stamp on it. The difference between the two shows up in what reaches you and in how fast you decide.
Digital Exposure is the snapshot: the picture of what is already exposed today, a credential, a lookalike domain, your brand in a scam, data for sale. It is there to start out knowing the size of the problem. CTI is the watch that comes afterwards: the warning when something new appears, week after week, because exposure regenerates and a snapshot from January does not protect you from a leak in March. The snapshot is a great way in and a poor final solution.
From outside, we monitor leaks, domains, your brand and what circulates in closed forums. From inside, we cross the signals in your environment with current threat intelligence: behaviour that matches a campaign under way, an address already flagged, a known technique being attempted. Seeing the two together shortens the time between the first signal and the decision to act, because what leaks outside often explains what appears inside.
Every finding arrives dated, validated and tied to the asset it threatens, with what to do about it. When your company answers to a standard, the same finding becomes evidence: control A.5.7 of ISO/IEC 27001:2022 calls for intelligence collected, analysed and used in a decision, and the fourteenth minimum control of the Central Bank of Brazil's cybersecurity resolutions calls for intelligence action with monitoring on the internet, Deep Web, Dark Web and private groups. A report that proves that chain is what the auditor is looking for.
We watch the sources within our reach, and not everything that circulates is accessible. That is why the value is not in a promise of full coverage, it is in the reading of what appears and the action that comes after. By the same honesty, intelligence does not remove the content, does not reset the leaked password, does not run the forensics of the leak and does not respond to the incident: it informs each of those decisions, which stay with whoever carries them out.
WHEN IT MAKES SENSE
In one of them the requirement arrives from outside, with a deadline. In the other two it comes from inside, almost always after the first scare.
Resolutions CMN 5.274 and BCB 538, of December 2025, with compliance required since March 2026, list fourteen minimum controls, and the fourteenth is intelligence action in the cyber environment, with monitoring on the internet, Deep Web, Dark Web and private groups. The standard accepts an in-house or a contracted structure, and what it requires is regularity and someone who acts. In the ISO/IEC 27001:2022 world, control A.5.7 asks for the same: intelligence collected, analysed and used in a decision. A company that declared the control and does not execute it needs the evidence.
A scam campaign using your name, a domain almost identical to yours registered by someone else, a fake profile of a director asking for a transfer, customer data showing up for sale. Here the value is not in finding a lot, it is in knowing early what is already circulating, so you can act before the scam reaches the customer or the till.
An employee credential turned up in a breach, or an email the company never sent reached a customer. The one-off incident was contained, and what stayed was the question the watch answers: what else has already leaked, what is still circulating, and how to find out next time without depending on someone's luck to warn you.
TRANSLATING THE ASK
The size of the work does not come from the number of alerts. These are the four ways the ask usually arrives, with what each one means and what genuinely moves the effort.
| What they asked for | What that actually means | What changes the size |
|---|---|---|
| We want to monitor our brand | A watch on the brand, the domains and the official profiles outside the perimeter, with a warning when misuse, a lookalike domain or a scam using your name appears. | How many brands and domains come in, whether ownership is yours or a partner's, and how many official profiles there are to compare against the fakes. |
| We need to know whether a credential leaked | It can be the one-off snapshot, to know what is already exposed today, or the continuous watch, to be warned when it appears again. Both start from the same survey. | How many email domains, how many executives will be followed, and whether the ask is a single snapshot or the recurring watch. |
| The Central Bank requires intelligence in the cyber environment | The fourteenth minimum control, with monitoring on the internet, Deep Web, Dark Web and private groups. The standard accepts an in-house or a contracted structure, as long as the intelligence is read and used. | The frequency of the report, the monitoring window, and whether you want support on the response decision when something urgent appears. |
| ISO 27001 asked for control A.5.7 | Evidence that threat intelligence is collected, analysed and used in a decision. What the auditor reads is the chain from signal to action, not the tool. | The evidence format your auditor accepts and the regularity that closes the cycle within your own audit. |
The scoping conversation happens before the proposal, and it is there to separate the one-off snapshot from the recurring watch. It is what decides whether you need to know what has already leaked, be warned about what comes next, or both.
STORIES
We change our clients' names with the same confidentiality that will protect your company later. The names change, the pattern of the problems repeats. Where a client authorises it, we share named references in a conversation.
Banks and fintechs
The Central Bank of Brazil's cybersecurity resolutions began requiring intelligence action in the cyber environment, with monitoring on the internet, Deep Web, and Dark Web. The institution had the control on paper and nothing actually running, and the compliance deadline was ticking.
We set up a recurring watch over domains, brand, and employee credentials, and tied every finding to the control it evidences. In the very first cycle, employee credentials showed up in a breach, dated and confirmed, and a domain that looked like the bank's had been registered by someone else.
The institution now has the recurring evidence the regulator demands, read and acted on, not a tool switched on and forgotten. The confirmed credentials were reset by the IT team before any abuse, and the lookalike domain entered the monitoring queue.
Branded retail
Customers began reporting fake promotions in the chain's name, with lookalike domains and cloned profiles. The company only found out from the customer who complained, when the scam had already run.
We put the brand, the domains, and the official profiles under continuous watch, with an immediate alert whenever misuse appeared. Every appearance became a dated finding, with what to do, and the decision to act came to be made with evidence in hand.
The chain came to learn of the scams before its customers. Setting aside removal, which is a separate step, the time between the first signal and the response fell, and the conversation with the customer stopped being a reaction to a complaint.
SaaS and platforms
The platform would see, every so often, strange access attempts, without knowing whether they were noise or the start of something. What was missing was tying what appeared inside the environment to what circulated outside.
We cross-referenced the environment's internal signals with current threat intelligence: a credential that had leaked in a recent dump was being tried against the company's access, and the source address was already flagged in a known campaign.
What looked like noise became a clear path: the client's IT team invalidated the credential and cut the access before the attempt turned into an incident. Seeing both sides together shortened the time between the first signal and the decision.
HOW WE RUN IT
Each phase ends in something you can check without taking our word for it. That is the point: a report your audit can read is worth more than a screen full of alerts nobody opens.
We register the domains, the brands, the official profiles and the assets to follow, and we agree in writing what comes into the watch and what stays out. For the inside, we define access to the telemetry we will cross-reference. This is also where the report frequency and the monitoring window are decided, because that is what separates a watch that warns in time from one that only documents after the fact.
Assets registered, with brands, domains, profiles and what belongs to third parties
A written scope, with what comes into the watch and what stays out
Agreed access to internal telemetry, when the inside comes in
Report frequency and monitoring window defined
Delivery milestoneScope and access agreed in writing, with no coverage question left open.
We collect from the sources within reach, the open internet, Deep Web, Dark Web and closed groups, and we validate before any alert. Validating is what separates a useful alert from noise: deduplicating what repeats, dating what appeared, discarding the recycled combolist that only repackages an old leak, and confirming which credential still matters. Without this phase, you receive a data dump that moves no decision at all.
Findings collected from accessible sources, with no promise of full coverage
Repetition removed and every finding dated
Recycled combolist discarded, with the reason recorded
Confirmation of which credential is still valid and matters
Delivery milestoneEvery finding dated and classified, with no recycled combolist in the report.
Every validated finding is tied to the asset it threatens and to what your business cannot afford to lose, and prioritised by that, not by the order in which it appeared. When your company answers to a standard, the finding is also tied to the control it evidences, A.5.7 of ISO/IEC 27001:2022 or the fourteenth control of the Central Bank of Brazil's resolutions. It is that tie that turns an alert into evidence and into action.
Every finding tied to the asset and to the business risk
Priority set by impact, not by order of arrival
A tie to the standard's control, when the company answers to one
A recommended action per finding, with the action owner named
Delivery milestoneEvery finding with an owner, a priority and a recommended action.
What is urgent becomes an alert the same day, with the initial recommendation. The rest goes into the consolidated report at the agreed frequency, with what appeared, what was validated and what to do. The report is read with your team, because intelligence that does not turn into a decision is cost with no return, and it is that reading the standard requires when it calls for the intelligence to be used.
An immediate alert on the urgent finding, with an initial recommendation
A consolidated report at the agreed frequency
A record of what appeared, what was validated and what to do
A reading of the report with your team, with the decisions noted
Delivery milestoneAn urgent alert the same day; the report delivered and read at the agreed cadence.
HOW THE WATCH RUNS
We do not publish a deadline or a price, because a watch's scope varies widely and a published number becomes a promise. The first conversation already shows which of these factors your company is in, and it is what produces the scoping requirement.
A brand with few domains runs light. A group with several brands, dozens of domains, official profiles across many channels and executives to follow consumes more. Ownership weighs in too: monitoring what is yours is straightforward, and what belongs to a partner has to be agreed beforehand.
Part of what circulates is in open sources and is quick to cover. Part is in a closed group or a restricted-access forum, and not everything is accessible. The scope says honestly what can be covered, instead of promising what nobody delivers.
A monthly report with an immediate alert on the urgent is one regime; closer monitoring, with an extended window and support on the response decision, is another. That choice moves the effort more than the technical part does, and it is agreed at the start.
FREQUENTLY ASKED
The questions that come up in almost every first meeting, answered without hedging.
The tool collects and lists. Intelligence reads what the tool brought in: it tells the real breach from the recycled combolist, confirms which credential still matters, ties the finding to your asset and says what to do. A screen full of alerts nobody opens is not intelligence, it is noise with a stamp on it. Both control A.5.7 of ISO/IEC 27001:2022 and the fourteenth control of the Central Bank of Brazil's resolutions ask for exactly this: that the intelligence be used in a decision, and not only gathered.
It is the same work in two tenses. Digital Exposure is the one-off snapshot: the picture of what is already exposed today, delivered once. CTI is the continuous watch that comes afterwards: the warning when something new appears, at the agreed frequency. The snapshot is a great way in, because it shows the size of the problem, and a poor final solution, because exposure regenerates and a picture of today does not protect you from tomorrow's leak.
Not as part of the intelligence. Removal depends on the platform where the content sits and can come in as separate support, agreed separately. The intelligence work finds, validates, prioritises and says what to do; the takedown, when it is possible, is another step. Promising removal alongside would be selling what intelligence on its own does not deliver.
No. Resetting the leaked credential or the password stays with your IT team, after the alert. Our role is to warn early, confirm that the credential still matters and say what to do. By the same division, intelligence does not run the forensics of what caused the leak, does not block the threat and does not respond to the incident: it informs each of those decisions, which stay with whoever carries them out.
It does. Resolutions CMN 5.274 and BCB 538, of December 2025, with compliance required since March 2026, list fourteen minimum controls, and the fourteenth is intelligence action in the cyber environment, with monitoring on the internet, Deep Web, Dark Web and private groups. The standard accepts an in-house or a contracted structure, and what it requires is regularity and someone who acts. The recurring report, with what appeared and what was done, is the evidence of that.
A.5.7 asks the organisation to collect, analyse and use threat intelligence to decide about its security. What we deliver is the evidence of that whole chain: the signal collected, the validation, the tie to risk and the action taken. A certified company that declared the control without executing it has, in the report, exactly the artefact the auditor is looking for. It is the difference between having the control on paper and having the control working.
No, and it is worth being wary of anyone who guarantees it. We watch the sources within our reach, and not everything that circulates is accessible: part is in a closed group, part never shows up anywhere you can see. That is why the value is not in a promise of full coverage, it is in the reading of what appears and the action that comes after. An honest watch says what it covers and what it does not, instead of promising the impossible.
A short conversation defines the scope and separates what you need to know now from what you need to be warned about later. It is there to size the one-off snapshot and the recurring watch with judgement, and to engage knowing exactly what you get at each step.