Notes from the watch.
What our analysts and leads learn from real cases, written for the IT directors and finance leads who hire us.

6 min
What a 02:14 alert looks like from our side
Minute by minute: a forwarding rule on an accounts payable mailbox, found and contained before anyone was awake.
Priya Raman, night watch lead

9 min
The cyber insurance questionnaire, answered line by line
What carriers mean by 24/7 monitoring, MFA everywhere and tested backups, and what evidence they accept.
Keisha Morrow, head of client security

5 min
Why we price per employee, not per device or per gigabyte
Per gigabyte pricing punishes you for logging more. Per device pricing punishes you for owning more. Here is our reasoning.
Tom Brennan, founder

7 min
Business email compromise in 11 minutes
The inbox rule is the tell. How we catch it, and the four settings that stop most of these cases before they start.
Sam Whitaker, detection engineering lead

8 min
Twelve questions to ask a security provider before you sign
Response times, who is actually watching, what you own when you leave. Ask these of anyone, including us.
Tom Brennan, founder

10 min
A ransomware Friday, as a tabletop exercise
The scenario we run with a 400 person manufacturer’s leadership team every year, and the three decisions it always comes down to.
Dana Okafor, day watch lead
Thirty minutes to find out who is watching your network tonight.
Bring your last insurance questionnaire or audit finding. We tell you in plain words where you are exposed after hours and what closing it would cost, then send a written quote within two business days.