← Practice areas
Area 02

Cybersecurity & digital intelligence

Understanding what you expose, and who you’re really dealing with.

Before you can protect yourself, you need to know what is visible about you, what can be exploited, and who is behind a partner, a domain or a document. We combine two perspectives — the security of your exposure and open-source analysis — to turn a vague concern into an actionable finding.

Discuss a situation
TracesVerificationExposure
Exposure made legible.
The problem

We don’t know what we expose, or who we’re really dealing with.

You don’t know your own exposure. Information about your organisation, your executives and your systems is circulating in the open — without you knowing which pieces, or what a hostile third party could do with them.

A partner, a supplier or a contact presents themselves to you. The name checks out, the website is clean, the documents look in order. But you don’t know who is really behind it, or whether what you’re being shown matches reality.

Something has happened — or you fear it will. Impersonation, a leak, a campaign targeting you, an incident. You need to understand what happened, or to reduce the risk before it materialises.

Our reading

You can’t defend what you haven’t first looked at.

Most digital risks don’t come from sophisticated attacks, but from simple things that stayed invisible: an exposure no one was aware of, a contact no one verified, a weak signal no one connected to another. Our work therefore starts with seeing — mapping what is actually exposed, comparing what you are shown against what open sources reveal — before advising anything.

We combine two perspectives that are too often kept apart: that of cybersecurity (what is exposed, exploitable, to be fixed) and that of digital intelligence (what public traces reveal about an entity, a person, a document). It is the intersection of the two that turns a concern into a finding you can act on.

What we do

Four types of engagement, combined according to your situation

  1. 01Exposure audit & digital hygiene. We map what is visible about your organisation and your executives in open sources, identify the exploitable weak points, and hand you concrete risk-reduction measures. This audit is built on our Digital Hygiene method.
  2. 02Awareness & risk culture. We train your teams in the reflexes that matter — recognising a manipulation attempt, protecting sensitive information, keeping up a digital hygiene that holds day to day. This is the core of our CAMO™ programme.
  3. 03Digital intelligence & due diligence (OSINT). From lawful open sources, we verify an entity, an organisation, a domain, a document or the executives involved, and document what you need to know before committing — each conclusion traceable and stated with its confidence level. Two dedicated tools support this: CAMO™ document verification and domain reliability checks.
  4. 04Open-source analysis after an incident. When an incident has occurred — impersonation, leak, compromise —, we establish from open sources what has been exposed, what is circulating and what can be inferred from it, and we draw the right measures from it. The technical investigation itself — forensics, incident response — falls outside our scope: we refer you to dedicated specialists, and can coordinate with them if you wish.

Our logic: see (exposure, sources) → verify (what is presented vs what is real) → qualify (established, likely, uncertain) → report back (a finding and measures). It is the same discipline of verification as in our other practice areas, applied to the digital domain.

Situations & deliverables

Typical cases, representative of what we work on

You’re about to sign with a partner you met recently. You want to confirm they are what they claim to be.
→ Open-source verification file.
An executive is concerned about their personal exposure.
→ Exposure map + recommendations.
Your organisation has never taken stock of what is visible about it.
→ Digital exposure audit.
A document or an identity looks doubtful to you.
→ Documented verification, with an explicit confidence level.
Your teams are the main way in for risk.
→ Awareness session tailored to your context.

What you receive: an exposure or verification report, a map, a risk matrix, and prioritised measures — not just a finding, but what to do next. Each conclusion states its level of certainty.

A limited initial scope is possible to begin with.

Limits & scope

This practice area touches on sensitive matters; rigour is part of the job here.

Our approach: lawful, ethical and documented work, from open sources and information that can be accessed lawfully. Each conclusion is traceable and its confidence level is stated — which is what makes our findings usable, including in a demanding setting.

Our limits: we do not access any system without authorisation and use no unlawful means. We also decline requests aimed at surveilling or harming a third party.

What we expect from you: a clear framework and a legitimate purpose. Every engagement is covered by a confidentiality agreement.

Frequently asked questions

Frequently asked questions

How do you work, in practice?
From open sources and information that can be accessed lawfully, with a documented method. Each conclusion is traceable and stated with its confidence level.
Do you carry out penetration testing?
It isn’t our core business: we focus on exposure, hygiene and verification. When offensive technical or forensic expertise is needed, we refer you to dedicated specialists.
What happens if a piece of information can’t be verified?
We state it clearly, with its confidence level. A named uncertainty is better than a false certainty.
Do you work with confidential data?
Yes. Every engagement is covered by a confidentiality agreement.
Can we start small?
Yes — a limited exposure audit or a targeted verification lets you start before going further.

A situation to clarify?

You can engage us on this area — or simply outline it, and we’ll tell you how to approach it.

Discuss a situation

→ The CAMO framework, shared across our four practice areas