Skip to main content
Service

Dark web monitoring — useful, and smaller than it sounds

Alerts when your staff credentials appear in breach data, so passwords get rotated before someone tries them. A real control, and not the one that will save you.

16+ years

Brisbane-based since 2010

1,500+

Employees supported across SEQ

Named engineers

The same team every time

Essential Eight aligned

Microsoft Partner

Monitoring for your domain's credentials appearing in breach and leak data, with a defined response — rotation, session invalidation and MFA verification.

What it is

Monitoring for your organisation’s email addresses appearing in breach and leak datasets — credential dumps from breached services, combination lists traded on criminal forums, paste sites — with an alert when one shows up.

The name oversells the mechanism. This is automated matching against collected datasets, not an analyst infiltrating forums on your behalf. That is fine; the value is in the detection and the response, not the theatre.

Why your credentials are in there

Almost always because something else was breached.

Staff register for things with their work email — a supplier portal, an industry event, an online retailer, a software trial. When one of those services is breached, the dataset includes that email address and, depending on how badly the service stored it, the password used.

If that password was also used for Microsoft 365, you have a live exposure that originated entirely outside your control. This is the reuse problem, and it is the specific risk monitoring exists to catch. You cannot stop staff registering for things. You can find out when one of those registrations turns into a liability.

The honest sizing of this control

Dark web monitoring is frequently sold as a flagship security product with dramatic branding. It does not deserve that position, and we would rather say so.

It detects one pathway. It does not prevent anything. It tells you a password is exposed; it does not stop that password working.

The control that stops the password working is multi-factor authentication. If you have MFA properly enforced, an exposed credential is a nuisance requiring rotation rather than an incident. If you do not, monitoring is telling you about a door that is standing open.

Given a choice between the two, take MFA every time. Monitoring is a useful, cheap addition once the substantial controls are in place, which is why we include it in managed security rather than selling it separately.

What we do with a finding

An alert is not a response. Each finding triggers a defined sequence:

  • Rotate the password on the affected account.
  • Invalidate active sessions, because a rotation alone does not evict someone already signed in.
  • Confirm MFA is enrolled and enforced for that account, since exposures frequently surface accounts that were exempted years ago.
  • Review recent sign-in activity for unfamiliar locations or devices.
  • Where the account is finance or executive, treat it at higher severity and check for mailbox rule changes.

The initial scan almost always returns historical findings, sometimes a lot of them. Working through that backlog is part of onboarding rather than something we leave sitting in a dashboard.

What nobody can do

Remove your data from circulation. Once credentials are out, they are copied across datasets indefinitely and there is no retraction mechanism. Any service advertising removal is selling a fiction.

The only real response is to make the exposed credential worthless.

What you get with JTIT

Concrete deliverables, not vague promises.

Know before the credential is used

There is often a window between a credential appearing in leak data and someone trying it against your tenant. Rotation inside that window closes it.

Covers the reuse problem

Most exposures are staff using their work email on unrelated services that were breached. You cannot prevent that; you can detect it.

A defined response, not just an alert

A finding triggers rotation, session invalidation and an MFA coverage check for that account — not an email telling you something bad happened.

Executive and finance accounts prioritised

An exposed credential for someone who can authorise payments is a different severity from a general staff account, and is treated that way.

Shows staff why reuse matters

An actual finding involving a real colleague changes password behaviour far more effectively than a training module about it.

Cheap, and included with managed security

Low cost relative to its value, and bundled rather than sold as a headline product — because it is not one.

How it works

A predictable, no-surprises process.

  1. 01

    Register your domains

    Your email domains are monitored against breach and leak datasets, including historical exposures already out there.

  2. 02

    Clear the backlog

    The initial scan almost always returns historical findings. Those get worked through first — rotated where still valid, dismissed where not.

  3. 03

    Monitor and alert

    New appearances raise an alert into our engineer queue with the affected account and the source breach where known.

  4. 04

    Respond

    Password rotated, active sessions invalidated, MFA coverage confirmed, and the account reviewed for signs it was already used.

Frequently asked questions

What does dark web monitoring actually check?

It checks aggregated breach and leak datasets — credentials dumped from breached services, combination lists circulated on criminal forums and paste sites — for email addresses on your domains. The name is more dramatic than the mechanism: it is largely automated matching against collected datasets, not an investigator browsing hidden forums on your behalf.

Why do our credentials appear if we have never been breached?

Because the breach was almost certainly somewhere else. Staff use their work email to register for unrelated services — a supplier portal, a conference site, a retail account — and when one of those is breached, that email address and whatever password was used appear in the dump. The exposure is real and it matters because of password reuse: if that password was also the Microsoft 365 password, you now have a live problem originating from a service you have never heard of.

Is dark web monitoring worth paying for?

It is worth having, and it is worth being realistic about its size. It is a detection control covering one specific pathway, at low cost. It is not a substitute for MFA, and if you had to choose between the two there is no contest — MFA makes an exposed password insufficient, while monitoring only tells you that one exists. We include it in managed security rather than selling it as a headline product, because presenting it as a primary defence would be misleading.

What should we do when a credential is found?

Rotate the password, invalidate active sessions for that account, confirm MFA is enrolled and enforced, and review sign-in logs for unfamiliar activity. If the same password was used elsewhere — which is the whole risk — those accounts need rotating too. We handle this as a defined response rather than forwarding you an alert.

Can you get our data removed from the dark web?

No, and neither can anyone else, whatever they claim. Once credentials are in circulation they are copied endlessly across datasets and there is no mechanism for retraction. Any service offering removal is selling something that does not exist. The only meaningful response is to make the exposed credential useless — rotate it, and ensure a password alone is not enough to log in.

Related services

Most clients combine a few of these — we'll help you decide what's right for your size and risk profile.

Ready to talk?

A 30-minute consultation with an engineer, not a salesperson. You'll get an honest read on whether we're a fit.

Call Get a quote