03 / DARK WEB MONITORING

Has your information leaked?
Get an earlier warning.

Email addresses, passwords and business information can be exposed without you noticing. We monitor agreed sources and alert you to relevant findings so you can investigate and respond earlier.

Request a quote
SUITABLE FOR

For businesses that want to track information circulating outside their own systems and gain ongoing insight relating to agreed domains and business details.

01 / SCOPE AND DELIVERABLES

From insight to action.

Read the service description (Norwegian) PDF ↗
01

Data leaks and credentials

Searches for business information and exposed login details in known leaks and marketplaces covered by the service.

02

Misuse of names and domains

Monitoring of domain registrations and copied websites that could be used to impersonate your business.

03

Relevant threat intelligence

Following relevant grey and dark web forums and discussions for information that can be linked to your business.

04

Alerts you can act on

Findings give your IT team or service provider a basis for investigating exposure. Alerting routines and any support with findings are agreed before starting.

Monitoring covers the sources included in the service. It cannot detect every leak or stop attacks on its own. A leaked credential does not automatically mean a work account has been compromised.

HOW WE GET STARTED

01

Define what to monitor

We agree the domains, business information and recipients of alerts.

02

Monitor the sources

Monitoring tracks relevant findings throughout the agreed subscription period.

03

Investigate and respond

You assess each finding and follow up affected accounts, logins or other misuse.

02 / REGULATIONS AND DOCUMENTATION

Supporting your security work.

See requirements and scope

Our assessment of how the service can support your work. Applicable requirements depend on your organisation and how the service is used.

Requirements for organisations in scope

Norwegian Digital Security Act

Insight into external exposure can support risk assessment and detection; it does not replace security work within your own systems.

NSM guidance
Risk-appropriate requirements

GDPR / privacy

Findings can prompt an investigation into whether personal data is affected and what further handling is needed.

GDPR, including Article 32
A standard, not a separate law

ISO/IEC 27001

Relevant threat intelligence can inform risk assessments and improvements to security measures.

ISO on the standard

Useful to know before we start.

What is the dark web?

These are parts of the internet that require specific software to access. They include forums and marketplaces where stolen information is shared. The service may also cover other agreed leak sources.

What should we do when we receive an alert?

Check what the information relates to, whether it is still current and whether passwords may have been reused. IT can assess password changes, login reviews and further incident handling based on the finding.

Is dark web monitoring a legal requirement?

Regulations may require risk-appropriate security, detection and follow-up. General requirements do not mean everyone must buy a particular dark web service. The need should be assessed against your business risk.

NEXT STEP / A NO-OBLIGATION CONVERSATION

Keep track of your exposure

Which domains or business names would you like to monitor? Do not include passwords or leaked personal data here.

We agree needs, scope and pricing before starting.
An enquiry carries no obligation to purchase.

How can we help?

Choose a service and tell us a little about your needs.

I would like

Opens your email app with a draft to Eddie. Review it and send it yourself. This form does not store your details.