Nobody has ever sat down and shown you this.
Your practice publishes more than you think: who works there, what runs your website, whose passwords are already in a breach file. A protector reads all of it back to you, in plain language, with a name and a number attached.
You are not being asked to imagine a risk. Everything we show you is already true, already public, and already findable by anyone who looks. The people who look are not choosy. They run the same checks against every practice in your city and work down the list by whatever comes back easiest.
Have a protector check my practiceSample · Yours reads from your own domain
Most practices are picked before anyone tells them why
By the time anyone confirms a breach, whoever did it has usually been in for months. The looking around, the password checks, the reading of your staff page, all of it happened long before anything went off.
One member of staff. One old password. The whole practice.
Someone on your team reuses a password from an old breach. It gets tried at three in the morning. It works. They are in the email, reading client files, forwarding invoices, before anyone notices anything unusual.
One email that looked like your bookkeeper. One payment. Gone.
Whoever signs your cheques is on LinkedIn. Your domain is publicly registered. A convincing fake email takes under a minute to write. No hacking involved, just your publicly available information, used against you.
The ransom note was six months in the making.
The ransom note is the last step, not the first. By then they have walked your systems, checked whether your backups work, and worked out what you can afford to pay.
The threat has changed. Most defenses have not.
The things you already pay for, the spam filter, the annual training, the firewall, were built for a problem that has since changed shape. AI has fundamentally changed how attacks are constructed. Protector Class was built for the current threat landscape, not the one from 2019.
Cannot distinguish AI phishing from legitimate email
IBM Security, 2024Year-over-year increase in internet crime losses, 2023 to 2024
FBI IC3, 2024Password attacks are faster than they were
MicrosoftOf organisations breached more than once
IBM, 2024In 2026, underwriters run their own external scan before they quote you.
Cyber insurance carriers no longer take a questionnaire at your word. Before binding or renewing a policy, many now scan your external infrastructure themselves: email authentication, exposed services, patch posture. Gaps found there mean higher premiums, new exclusions, or a declined renewal. Client and vendor security questionnaires increasingly work the same way.
See the same external view the underwriter's scan takes, weeks before they take it, with time to fix what it finds.
Answer client and vendor security questionnaires from evidence instead of guesses, with a report you can point to.
Fixing externally visible gaps before underwriting is the cheapest lever a practice has on its cyber premium.
We are not an insurer or a broker, and a clean report does not guarantee any premium outcome. What it gives you is the underwriter's view of your practice, first.
The Protector Class Business Assessment
We look at your domain the way someone targeting it would. Everything we find is written down, scored, and paired with one thing to do about it. You get it in plain language. Your IT contact gets technical detail.
The write-up, and someone watching after it. Two to three days.
The summary is written so anyone can read it. Hand it to your partners, your insurer or your regulator. Watching carries on after it lands.
A page of your own, updated continuously
When the assessment is done you get a page of your own to check. What changed, what is new, which passwords have turned up, and scan coverage status, updated continuously. This is not a report you file and forget. It is a permanent intelligence layer for your organization.
A completed assessment is a credential. Use it as one.
A finished assessment is something you can show. A practice that is watched, and can prove it, is saying something most of its competitors cannot, because they have not done the work. Clients in law, medicine and accounting are starting to ask how their records are kept. The practices with something written down are winning engagements the others never hear about.
External Assessment
A one-page signed summary issued on completion of the full assessment, dated and on file with us. Forward it to your insurer, attach it to a client’s security questionnaire, or hand it to a regulator asking what you have done.
Built for organizations where data is the asset
If your business holds client data, financial records, health information, or privileged communications, your exposure profile is a target. Protector Class works across every professional services vertical.
Law firms
Client confidences are your responsibility. One leaked file, one fake email, one exposed login, and you're explaining it to the Law Society and your clients simultaneously.
Medical & health clinics
Patient files are worth many times more than card numbers to whoever buys them. A PIPEDA or HIPAA breach means you must disclose it, with potential fines, and the kind of press coverage that follows a practice for years.
Accounting & tax practices
You hold banking logins, SINs, statements and CRA letters for dozens of clients. That is well known. Accounting firms are targeted specifically because the data density is unusually high.
Real estate brokerages
Wire fraud is the way money actually leaves a real estate practice. One spoofed email redirecting closing funds. The transaction looks normal until the money is gone.
Financial & advisory practices
Regulators look at how an advisory practice handles data. A breach is not only a cost, it is a question about your licence to operate at risk.
Insurance & risk advisory
You hold client risk profiles and financial information. Regulators expect you to demonstrate the same security practices you recommend to your clients.
We never name a client. Sectors only.
If the full assessment finds nothing your preview did not already show, you get the fee back.
The full assessment is meant to find what the preview could not. If it does not, you do not pay for it. If the full assessment produces nothing beyond what the preview showed, we refund the audit portion of the engagement fee. This is a standing guarantee, not a limited-time offer, not conditional on completing a survey. Written into every engagement.
What is already out there about your organization?
We read every request and confirm inside a business day. Everything said stays confidential. A mutual non-disclosure agreement is available before any work begins.