Skip to main content
Category · Legacy term

Digital risk protection got the direction right. It stopped being a category of its own.

The analyst market that named it has been folded into threat intelligence, and the vendors carrying the label have widened well past it. The work the term described did not recede at all. So this page is a map rather than a pitch: what each part of digital risk protection was for, and which capability now carries it.

−23%
Year-on-year worldwide search for the term
2016
Monitoring external exposure since

The term

What digital risk protection meant, and what happened to it

It was never a bad idea. It was a category defined by what it watched, arriving at the moment buyers started asking what gets resolved.

Digital risk protection named a real shift: look at your organisation from the outside, include the things that are not infrastructure — your brand, your executives, your people's credentials — and end in an action rather than a report. That instinct was right, and almost everything the category promised is still work somebody on your team does every week. What did not survive was its boundary. Because it was drawn around what was monitored rather than around what got resolved, it never had a natural claim on your technical attack surface, your source code or your vendors; and once buyers began asking for those inside the same evaluation, the analysts folded the market into threat intelligence and the vendors widened past the label. The vocabulary is still sitting in budget lines, renewal notices and RFPs, which is why this page exists — and why nothing below asks you to change the word you use.

The map

Each part of it, and where it lives now

Nothing in this list was dropped. Every function found a capability with a sharper boundary — and the last two rows are here because they were never inside the category at all, which is most of the reason it could not hold.

What DRP called itWhere it lives nowWhat that capability covers
Brand and impersonation monitoring Brand Protection Lookalike domains and applications, fake social profiles, executive impersonation, counterfeit listings and misuse of your marks.
What changed: the deliverable. Detection is judged by whether it terminates, so an impersonation finding arrives attached to a removal case rather than to a weekly digest.
Domain and registration watch Domain Monitoring Typosquats, homographs and newly registered lookalikes, watched from registration and certificate issuance rather than from the moment a page goes live.
What changed: the timing. A registration is the earliest observable there is, which moves the decision upstream of the phishing page — and upstream of having anything to tell your customers.
Credential and dark-web exposure Dark Web Monitoring Stealer-log credentials, session cookies and tokens, breach corpora, and the compromised machine each artefact actually came from.
What changed: the state. A credential arrives with an explicit verdict against a named service — probed where that is safe and authorised, and marked as untested with the reason where it is not — so the row tells you whether anything still opens, not only that a password leaked.
Data leakage Data Exposure Monitoring Source code and secrets in public repositories, exposed storage, and documents and datasets published where nobody intended to publish them.
What changed: the scope. Code was never really inside digital risk protection, and it is now one of the highest-yield places to look — a live key in a public repository is an exposure with an owner and a fix.
Takedown and enforcement Phishing and Domain Takedown Dispatch to registrars, hosts, platforms and app stores with the case evidence attached, and a published state at every stage — including the states that mean it has not moved.
What changed: enforcement stopped being a separate purchase. It is the same finding record carried through to a removal, rather than a service you brief once your monitoring vendor has told you something is wrong.
Your technical attack surface Attack Surface Management Internet-facing assets nobody enrolled, origin infrastructure sitting behind your edge, and a subsidiary estate that arrived with an acquisition.
Never a DRP function, and this is the row that explains the absorption. Buyers stopped running a brand evaluation and an attack-surface evaluation as separate purchases, and a category that excluded infrastructure had no answer to that.
The estate your suppliers run Third-Party Risk Management The same outside-in discovery pointed at the vendors you depend on, so a supplier is assessed on what is observable today rather than on a questionnaire answered last year.
Also never a DRP function, and the second half of the same story. A supplier breach becomes your incident, which is why vendor exposure ended up inside the exposure evaluation rather than beside it in procurement.

Brand and impersonation monitoring

Where it lives now
Brand Protection
What that capability covers
Lookalike domains and applications, fake social profiles, executive impersonation, counterfeit listings and misuse of your marks.

What changed: the deliverable. Detection is judged by whether it terminates, so an impersonation finding arrives attached to a removal case rather than to a weekly digest.

Domain and registration watch

Where it lives now
Domain Monitoring
What that capability covers
Typosquats, homographs and newly registered lookalikes, watched from registration and certificate issuance rather than from the moment a page goes live.

What changed: the timing. A registration is the earliest observable there is, which moves the decision upstream of the phishing page — and upstream of having anything to tell your customers.

Credential and dark-web exposure

Where it lives now
Dark Web Monitoring
What that capability covers
Stealer-log credentials, session cookies and tokens, breach corpora, and the compromised machine each artefact actually came from.

What changed: the state. A credential arrives with an explicit verdict against a named service — probed where that is safe and authorised, and marked as untested with the reason where it is not — so the row tells you whether anything still opens, not only that a password leaked.

Data leakage

Where it lives now
Data Exposure Monitoring
What that capability covers
Source code and secrets in public repositories, exposed storage, and documents and datasets published where nobody intended to publish them.

What changed: the scope. Code was never really inside digital risk protection, and it is now one of the highest-yield places to look — a live key in a public repository is an exposure with an owner and a fix.

Takedown and enforcement

Where it lives now
Phishing and Domain Takedown
What that capability covers
Dispatch to registrars, hosts, platforms and app stores with the case evidence attached, and a published state at every stage — including the states that mean it has not moved.

What changed: enforcement stopped being a separate purchase. It is the same finding record carried through to a removal, rather than a service you brief once your monitoring vendor has told you something is wrong.

Your technical attack surface

Where it lives now
Attack Surface Management
What that capability covers
Internet-facing assets nobody enrolled, origin infrastructure sitting behind your edge, and a subsidiary estate that arrived with an acquisition.

Never a DRP function, and this is the row that explains the absorption. Buyers stopped running a brand evaluation and an attack-surface evaluation as separate purchases, and a category that excluded infrastructure had no answer to that.

The estate your suppliers run

Where it lives now
Third-Party Risk Management
What that capability covers
The same outside-in discovery pointed at the vendors you depend on, so a supplier is assessed on what is observable today rather than on a questionnaire answered last year.

Also never a DRP function, and the second half of the same story. A supplier breach becomes your incident, which is why vendor exposure ended up inside the exposure evaluation rather than beside it in procurement.

The successor

Detection was always the easy half

What external exposure management adds is not more sources. It is two obligations digital risk protection never had to take on: proving the exposure works, and ending it.

01 Impersonation

A lookalike domain is registered against your brand

What monitoring alone tells you
A domain exists, it resembles yours, it was registered on Tuesday. All true, and not yet a decision — most lookalikes never resolve to anything, and a queue that treats them equally is a queue nobody works.
What validation adds
Whether it resolves, whether a certificate was issued for it, whether it now serves a sign-in page copied from yours. The exposure is tested where it is safe and authorised rather than assumed from its existence.
What termination adds
A notice filed against whoever actually controls the name — the registrar, the host, the platform — and a case that stays open until it resolves rather than until it has been read. An alert closes when you acknowledge it. A removal closes when the page is gone, and those are not the same event.
02 Exposure

A credential belonging to your domain appears in a corpus

What monitoring alone tells you
A password associated with your organisation is in circulation. It may be nine years old, it may have been rotated twice since, and the row on its own cannot tell you which.
What validation adds
Continuous Automated Red-Teaming probes it where that is safe and authorised, and the credential carries an explicit state afterwards. Not every finding is validated — the ones that were not say so, rather than being presented as though they had been.
What correlation adds
The credential joins the machine it came from and the asset it reaches, in one correlated exposure model. Two separate products each holding half of that is precisely the arrangement the old category left buyers with.

Evaluation

What the label stopped telling you, and what to ask instead

The term now sits on platforms covering considerably more than it implies, and on products that do one narrow thing well, and the word itself will not tell you which one you are reading. So evaluate on mechanics. These four questions sort a shortlist faster than any category name now does — including this one.

Tested or reported

Is a finding probed, or only observed?

This decides how much of your week the platform costs you, because an unverified queue moves the triage to your team. Ask which finding types are tested, which are not, and what a finding says when it was not — a platform reporting validation as universal across brand, infrastructure, credentials and forum chatter simultaneously is describing an aspiration.

Terminate or escalate

Does enforcement end the thing, or hand it back to you?

Detection is cheap and enforcement is not, which is where a well-written report tends to stop. Ask who the notice is actually filed with, whether the platform files it or drafts it for you to file, and what the case record looks like in the weeks when a registrar simply does not reply.

Licensed or metered

Is enforcement inside the licence, or bought as credits?

Metering changes who decides. Somebody on your side begins weighing whether an impersonation is worth spending an allowance on, and the ones judged not worth it stay up. Ask where the limit is written — the licence or the datasheet — and ask what happens in the month the allowance runs out.

Scope

Does one platform see the estate, the code and the suppliers?

These are the three areas buyers most often discover late, and none of them sat inside the digital risk protection definition. Ask whether they are one evaluation or three — and if three, ask who is responsible for noticing when a finding in one of them explains a finding in another.

Sourcing

Why we say the category is receding

This page ranks on a term it is arguing against, so the claim should carry its arithmetic — and, more usefully, what we refused to put in it.

How the category read was arrived at As of August 2026
  • Worldwide search demand for "digital risk protection" sits at roughly 590 a month and is down about 23% year on year, measured across the head term and its service, platform and vendor variants.
  • That decline is not by itself evidence the underlying problem shrank. Across the same pull, most established security terms are down double digits, which tracks AI answer panels absorbing definitional searches more closely than it tracks budgets moving.
  • The structural signal is the analyst one: Digital Risk Protection Services was folded into Security Threat Intelligence Products and Services, which is itself transitioning to Cyber Threat Intelligence Technologies. A market that has become a sub-heading of another market is no longer a separate buying decision.
  • We kept the page because buyers still use the words in live evaluations, and being met in your own vocabulary is worth more than being corrected in ours.

Deliberately excluded

  • Any suggestion that a vendor still carrying the digital risk protection label is a narrow point tool. Several are not — Cyble and CloudSEK among them run genuinely broad platforms — and the argument here is about whether the category still describes a coherent purchase, never about a product's quality.
  • Win-rate, renewal or pipeline data of our own. What a market searches for is sourceable; what it buys is not, and we are not going to model it and present the model as a finding.

Questions buyers actually ask

Before you evaluate this

Our budget line says digital risk protection. Does that have to change?

No, and you should not have to re-scope a renewal to buy the same work under a newer noun. What was bought as a digital risk protection service is bought here as external exposure management, and the table above is the mapping between the two, function by function. Procurement can keep the line item as it stands. The one thing worth changing is what the renewal gets assessed against: a category name was a usable proxy for a set of capabilities while the category held its shape, and now that it does not, the criteria have to do the work the name used to do.

Is external exposure management just digital risk protection renamed?

If it were, it would not be worth the disruption of changing the word. Two differences do the actual work. The scope is drawn around what is exposed rather than around what is watched, which is why the map above ends on two rows the old category had no claim to at all. And the deliverable is different: exposure is probed where it is safe and authorised rather than reported on sight, and an impersonation case is worked until the thing is off the internet rather than until somebody has read about it. Not every finding is validated — but every finding carries the state it was left in, which is the part a renaming exercise could not have produced.

Which digital risk protection vendors should we be looking at?

Not a question the label can answer any more, which is the awkward part of ranking for it. We have published the four questions above rather than a shortlist, because a shortlist written by a vendor is a sales document and you would be right to read it as one. What we would suggest instead: put all four to every vendor in writing, against your own apex domain rather than a reference account, and compare the answers side by side. Answers to those diverge a good deal faster than the marketing does.

Start from what is exposed, not from what the category is called

One apex domain, two business days, a written snapshot — each finding mapped to the capability that owns it, whatever your budget line calls it.