Skip to content
Atlas
GET IN TOUCH

C://SECURE37Dark Web Monitoring

Find out before
they use it.

Dark web monitoring watches criminal marketplaces and breach dumps for credentials tied to your domain, so an exposed password can be changed before somebody tries it. It is for organisations whose staff reuse passwords, which is all of them.

Credentials from a breach at some unrelated service get tried against your systems, and because passwords get reused, they often work.

The cost of leaving this alone is rarely one visible failure. It is the slow accumulation: the workaround that became the process, the thing only one person knows, the renewal nobody questioned.

Our starting point is always the same: establish what is actually true today, then decide what to change. Work scoped against an assumption tends to solve a problem you do not have.

  • 01Nobody owns itIt sits with whoever touched it last, which is not the same as being managed.
  • 02No current pictureWhat you have, what it costs, and who has access are all slightly out of date.
  • 03Only handled when it breaksAttention arrives after the disruption rather than before it.

What the engagement covers

Scoped before it starts, so you know what is included and what is not.

  • 01

    Continuous monitoring

    Your domains watched across breach data and criminal marketplaces, continuously rather than as a one-off scan.

  • 02

    Alerting

    Notification when a credential appears, with the source and the date, so you can judge how much it matters.

  • 03

    Response

    Forced reset and session revocation on the exposed account, rather than a report telling you it happened.

  • 04

    Root cause

    Whether the exposure came from your systems or from a third party, which changes entirely what you should do next.

Baseline, remediate, monitor, evidence

Four stages with a written output at each one. You always know which stage you are in and what comes next.

  1. 01Week 1

    Baseline

    What is configured today, measured against a recognised standard, with gaps ranked by real-world risk rather than vendor score.

  2. 02Weeks 2 – 6

    Remediate

    Gaps closed in the order that buys the most safety fastest, with each change recorded.

  3. 03Ongoing

    Monitor

    Tuned to your environment so alerts mean something, and every alert has a named owner.

  4. 04Quarterly

    Evidence

    A written report you can hand to an insurer, a customer, or your board without translating it first.

What you should expect

  • Someone other than you owns it, with that written down.
  • The current state is documented and stays documented.
  • Cost is planned ahead rather than discovered at renewal.
  • Decisions are made against evidence rather than assumption.

Questions we get asked

01What is dark web monitoring?

Dark web monitoring watches criminal marketplaces and breach dumps for credentials tied to your domain, so an exposed password can be changed before somebody tries it. It is for organisations whose staff reuse passwords, which is all of them.

02What does it mean if our company email address is found on the dark web?

Usually it means a service one of your staff signed up to with their work address has been breached, and their password for that service is now circulating. It rarely means your systems have been breached. It matters because people reuse passwords, so a password stolen from a retailer in 2021 gets tried against your email login, and often works.

03What should we do when a credential turns up?

Reset that password and revoke every active session immediately, then work out where else the same password was used, because that is where the real exposure sits. If multi-factor authentication is enforced on the account, an exposed password is a much smaller problem, which is the strongest single argument for enforcing it everywhere.

04Can you get our data removed from the dark web?

No, and be wary of anyone who says they can. Once data is circulating it cannot be recalled. What monitoring gives you is time: knowing an account is exposed before someone tries it, so you can close the door first. Any service promising removal is selling something that does not exist.

05Is dark web monitoring worth paying for?

It is worth having, and it is worth being clear about what it does. It is an early warning, not a control. If you have not yet enforced multi-factor authentication everywhere, spend the effort there first, because that reduces the actual risk rather than telling you about it. Monitoring on top of that is a sensible and inexpensive addition.

06Should staff use work email addresses to sign up for other services?

For legitimate business tools, yes, because you need visibility and the ability to recover the account when they leave. For personal or marginal services, no, and a password manager that generates a unique password for each site removes most of the risk either way. The danger has never really been the address. It is the reused password attached to it.

07How much does dark web monitoring cost in New Zealand?

We quote after scoping rather than before. Anyone pricing this work without looking at your environment is guessing, and the guess is rarely in your favour. Scoping itself is quick, and we tell you what it costs before we start it.

08How long does it take to get started with dark web monitoring?

A first conversation takes about half an hour and costs nothing. Scoping is usually a week or two of our time depending on the size of the environment, and we agree the delivery dates with you before anything is booked in.

09Can you deliver dark web monitoring alongside our existing IT team or provider?

Yes, and it is common. We are happy to work as an extra pair of hands under your internal team, or alongside an incumbent provider on a defined piece of work. We will set out in writing where the responsibilities split, so nothing falls between us.

10Do we have to move our whole IT contract to Atlas?

No. This can be delivered as a standalone piece of work for an organisation we have never worked with before, or folded into a managed agreement if you already have one with us. Plenty of clients use us for one thing and keep everything else where it is.

11Can you support us if we are not based in Auckland?

Our team is based in Auckland and we attend sites across the wider region. Most of this work is delivered remotely, so we support organisations throughout New Zealand, and we will say up front where being on site genuinely matters.

12Who will we be dealing with when something actually happens?

Named people, not a queue. You get a lead who knows your environment and stays with it, which is the difference between explaining your business once and explaining it every time you make contact.

13What happens after it is in place?

You keep the documentation regardless, and anything registered in your name stays in your name. Whether we stay involved is your call. Some clients take it in house from there, others move it onto an ongoing agreement with us. We would rather you left cleanly than stayed because leaving was difficult.

Start with a conversation.

Tell us what you are dealing with and we will tell you whether this is the right service for it, and what it would take.

← All services