The risk starts outside, not inside your firewall
Credentials belonging to your staff turn up in leaks, someone registers a domain one letter away from yours, and the catalog of actively exploited vulnerabilities lists a product you are running. None of it happens in your network. All of it concerns you.
Collecting signals is the easy part. The hard part is deciding which of those signals should shape your Monday morning.
The sources are public. Breach collections, domain registrations and the catalog of actively exploited vulnerabilities published by the US agency CISA are open to everyone, including the other side. The difference is not access, it is who holds them against their own estate on a regular basis.
Tools like to report everything. Every name similarity, every old leak, every vulnerability in the catalog. Reporting everything says nothing, and after two weeks nobody reads along anymore.
Responsibility is split. A lookalike domain is a brand issue and a phishing issue at the same time. If the two sit in different hands, the coordination costs exactly the days that matter.
Without documentation nothing is left. Once a page is taken down, the proof that it existed disappears with it. For insurance, legal action and internal records that is the most expensive mistake.
What is visible from outside
- Matching of your domains and mailboxes against known breach collections, with the source and the date of each finding
- Monitoring of new domain registrations related to your name and its spelling variants
- Tracking of brand mentions across the web, on marketplaces and on social networks
- A daily situation picture from the CISA catalog of actively exploited vulnerabilities, matched against your own estate
From finding to decision
- Assessment by actual risk instead of alerting on everything, so the list stays short enough to be read
- Time-stamped evidence capture so a case stays provable after the page is gone
- Immediate containment in your own network, meaning blocks in DNS filtering and firewall plus rules in your mail filters, regardless of how fast the other side responds
- A clear assignment of who takes the next step, so no finding is left sitting between responsibilities
Enforcement and evidence
- Formal notices to platforms, hosters and registrars, including notice and action procedures under Article 16 of the Digital Services Act
- Preparation of trademark and unfair competition claims together with your legal counsel
- Checks on incoming invoices, documents and business partners when a finding turns into a fraud attempt
- Documented evidence per case, usable for insurance, legal action and internal records
Each building block stands on its own and can be commissioned separately. Together they produce the picture this is about.
Instead of four tools with four inboxes, one list in priority order that you work through from top to bottom
Monitoring, immediate containment and enforcement come together in one place, with no handover between a tool vendor and a law firm
A finding is an event, a pattern is a process. What works is the repetition, not the single action
Digital Risk Protection
What does Digital Risk Protection actually mean?
The term covers what happens about you outside your network and can do you harm. Leaked credentials, fake domains and profiles, misuse of your brand, fraud attempts against your company, and publicly known vulnerabilities in products you are running. Classic security tools look inward. Digital Risk Protection looks at you from the outside, the way an attacker does.
What does CAVRIX actually do here, and what not?
We monitor the sources named above continuously, assess the findings, capture evidence, put immediate containment in place in your network and your mail filters, and run the notice procedures with platforms, hosters and registrars. What we do not do: we do not act autonomously in your systems and we do not run attack simulations such as penetration testing or red teaming. We tell you what needs to happen and take on the steps that are agreed.
Does this require you to run my IT?
No. The monitoring works regardless of who runs your IT. Immediate containment such as blocks in DNS filtering or rules in your mail filters is faster when we look after the IT anyway, but it can just as well be handed over to your existing provider.
How is this different from a tool I can buy myself?
A tool reports. It does not tell you which of this week's sixty alerts actually counts, it captures no evidence, and it runs no procedure against a registrar. The work sits exactly in between, and hardly any mid-sized company carries it internally. Above that there are platforms built for large corporations, below it there is pure monitoring. We occupy the middle.
Am I obliged to run something like this?
There is no explicit legal obligation to monitor the market. If your company falls under NIS2, however, the directive requires risk management that includes external threats, and the management level is liable for putting it in place. Either way the practical reason is the stronger one: a claim is of little use if nobody noticed that it arose.
How do we start?
With a stocktake. We look at which of your domains and mailboxes already appear in known leaks, which lookalike domains around your name exist, and whether the catalog of actively exploited vulnerabilities lists something you are running. The result is a short list in priority order, not a presentation.
You only know what is out there about you once someone looks
We run the stocktake and go through with you which findings are a risk and which are not. Write to us at info@cavrix.de.