Credential Exposure Monitoring

Know when staff credentials turn up in breach data or on a compromised machine.

When you need it

  • You have had an account takeover and do not know how they got in
  • Staff reuse passwords across work and personal sites
  • An insurer or assessor asks about compromised-credential controls

Compromised credentials are the quiet way into an organisation. We enrol your email domain once and watch it continuously across breach data, infostealer logs and paste sites, so you know which staff are exposed and which breach or malware did it.

Infostealer alerts are the differentiator. A breach hit means a website someone used was compromised, possibly years ago. A stealer hit means a staff member's computer is compromised now and someone holds their saved passwords and live session cookies. The alert names who to reset and revoke today.

The service starts with an onboarding exposure assessment: every breached address and infostealer hit ranked by severity, with a 30-day fix list that becomes the baseline. Compromised password screening installs the published breached-password list into your Active Directory password filter, meeting the NIST SP 800-63B control that appears in most assessments and cyber insurance questionnaires. Executive reporting rolls the data into a trend line for the board, and during an incident we can answer how they got in within hours, not weeks.

How it runs

  1. 1

    Enrol

    Verify control of your email domain and enrol it once.

  2. 2

    Baseline

    An onboarding exposure assessment: every breached address and infostealer hit, ranked, with a 30-day fix list.

  3. 3

    Watch

    Continuous monitoring of breach corpora, infostealer logs and paste sites, with alerts naming who is exposed.

  4. 4

    Screen

    Compromised password screening installed in your Active Directory password filter.

  5. 5

    Report

    Executive exposure reporting for the board, and incident response enrichment when something happens.

What you get

  • Continuous exposure monitoring of your domain
  • Infostealer alerts naming who to reset and revoke today
  • Onboarding exposure assessment with a 30-day fix list
  • Compromised password screening in Active Directory
  • Executive exposure reporting
  • Incident response enrichment

Where it is used most

Questions we get asked

Where does the data come from?

Breach corpora, infostealer logs and paste sites, including Have I Been Pwned data (licensed CC BY 4.0).

Is it safe?

We verify control of your domain before enrolling it, and searches use k-anonymity so full addresses are never transmitted.

Why does an OT consultancy offer this?

Because stolen credentials are one of the common paths from the internet to the engineering network.

Talk to us about credential exposure monitoring.

Tell us about the site, the systems and what you are trying to achieve. A consultant will reply.