Hard-won notes from the operators' side.
Quarterly threat-landscape briefings, technical primers on exposure, and original research from the ShadowMap intelligence team. Published when there's something to say, not on a content-calendar.
Resource hub
Blog →
Posts on attack-surface trends, threat-actor profiles, and platform updates.
On request
Threat briefings →
Quarterly threat-landscape briefings, filtered to your sector, geography and tech stack. Distributed to customers; ask for a sample in yours.
On request
Research →
Original research from the ShadowMap intelligence team on exposure patterns, actor tradecraft and leak-site activity. Ask for the current set.
Working documents
Print them, fill them in, take them to the meeting
Scope schedules, scoring matrices, evidence checklists and readiness worksheets. Each one is built to stay useful to a team that ends up buying something else — that is what makes it worth forwarding to a colleague.
Working document · PDF
External Exposure Platform: RFP and Evaluation Pack →
A requirements schedule, the questions worth asking any vendor, a fourteen-day proof-of-concept worksheet and a weighted scoring matrix.
Working document · PDF
Stealer-Log and Credential Exposure: Response Playbook →
What to do in the days after a credential dump lands, in the order it has to happen.
Working document · PDF
External Vendor Risk Questionnaire and Outside-In Evidence Annex →
One half attested, one half observed, and a sheet for reconciling them vendor by vendor.
Working document · PDF
External Monitoring Evidence Matrix →
What a review asks you to show, what evidence answers it, and which monitoring artefact produces that evidence — across eight frameworks.
Working document · PDF
External Exposure Maturity Model →
Six levels, scored separately across seven areas — and where the ceiling sensibly sits
Working document · PDF
Takedown Evidence Pack →
A fill-in pack for teams filing their own abuse notices: what to capture, which counterparty type to file with, and what each notice has to carry.
Evidence by regulator
What continuous external monitoring evidences, framework by framework
Each of these states what a monitoring record contributes to that framework's evidence file — and, just as deliberately, where the boundary of the claim sits. None of them is compliance advice, and none claims a control the platform does not operate.
RBI
RBI cyber security framework →
Dated scan windows, session identifiers and workflow history — evidence that an external monitoring control was operating.
SEBI
SEBI CSCRF →
The monitoring record, remediation timelines and accepted-risk entries a CSCRF evidence file asks for.
IRDAI
IRDAI cyber-security guidelines →
An insurer is answerable for an estate it does not operate — intermediary properties, circulating policyholder credentials, look-alike quote sites.
DPDP
Digital Personal Data Protection Act →
What external monitoring can establish about personal data already outside your control, and what it cannot.
DORA
DORA third-party ICT monitoring →
What outside-in monitoring of ICT third parties evidences for a DORA programme, what it does not reach, and where the boundary sits.
NIS2
NIS2 supply-chain security →
A dated, outside-in monitoring record on the suppliers you nominate.
Datasheets
One page per module, for the procurement pack
Everything on these is also on the module pages, ungated. The PDFs exist because procurement asks for one, not because they say anything the site does not.
Exposure · PDF
Attack Surface →
Continuous discovery of external assets, ports, services, mobile apps, and cloud exposures — prioritised by exploitability.
Intelligence · PDF
Dark Web →
Stealer logs, leaked credentials, ransomware victim posts, and threat-actor marketplaces — monitored continuously and matched to your assets.
Operations · PDF
Vendor Risk Management →
Third-party exposure scoring and continuous monitoring — see your suppliers' attack surface and dark-web exposure as if it were your own.
Want a threat briefing keyed to your sector?
The quarterly briefing that lands on a customer's desk is filtered to their industry, geography, and tech stack. Get yours by joining the platform — or ask for a sample in your sector.