Protector Class · For practices

Nobody has ever sat down and shown you this.

Your practice publishes more than you think: who works there, what runs your website, whose passwords are already in a breach file. A protector reads all of it back to you, in plain language, with a name and a number attached.

You are not being asked to imagine a risk. Everything we show you is already true, already public, and already findable by anyone who looks. The people who look are not choosy. They run the same checks against every practice in your city and work down the list by whatever comes back easiest.

Have a protector check my practice
Practice assessment · SampleREAD-ONLY
Domain.comSCANNING
MailAccepts spoofed invoicesCRITICAL
Credentials3 staff logins in breach databasesHIGH
ServicesBooking system version publicMEDIUM
Signed · Certified protector72 hrs

Sample · Yours reads from your own domain

Live intelligence17.8BBreach records indexed
Monitoring98%Source uptime & coverage
Active194 daysAvg undetected breach window
Intelligence72hAssessment delivery time
Research methodology anchored in FBI IC3FTC Safeguards RuleSEC Reg S-PIRS Circular 230CISAFINRAGLBAHIPAACCPA / CPRANISTPCI-DSS
01The threat reality

Most practices are picked before anyone tells them why

By the time anyone confirms a breach, whoever did it has usually been in for months. The looking around, the password checks, the reading of your staff page, all of it happened long before anything went off.

Scenario 01

One member of staff. One old password. The whole practice.

Someone on your team reuses a password from an old breach. It gets tried at three in the morning. It works. They are in the email, reading client files, forwarding invoices, before anyone notices anything unusual.

$4.44MAverage cost per business breach · IBM, 2024
Scenario 02

One email that looked like your bookkeeper. One payment. Gone.

Whoever signs your cheques is on LinkedIn. Your domain is publicly registered. A convincing fake email takes under a minute to write. No hacking involved, just your publicly available information, used against you.

$3.05BLost to Business Email Compromise in 2025 · FBI
Scenario 03

The ransom note was six months in the making.

The ransom note is the last step, not the first. By then they have walked your systems, checked whether your backups work, and worked out what you can afford to pay.

194 daysAverage undetected breach window
02The AI threat shift

The threat has changed. Most defenses have not.

The things you already pay for, the spam filter, the annual training, the firewall, were built for a problem that has since changed shape. AI has fundamentally changed how attacks are constructed. Protector Class was built for the current threat landscape, not the one from 2019.

A convincing fake email now takes minutes to write, and reads like anything else in the inbox.
A voice can be copied from audio that is already public. Hearing someone say it is not proof it was them.
Automated attack infrastructure runs against every business on the internet without stopping. The question is whether you know what it found before somebody uses it.
94%

Cannot distinguish AI phishing from legitimate email

IBM Security, 2024
33%

Year-over-year increase in internet crime losses, 2023 to 2024

FBI IC3, 2024
3x

Password attacks are faster than they were

Microsoft
83%

Of organisations breached more than once

IBM, 2024
03Your insurer already scans you

In 2026, underwriters run their own external scan before they quote you.

Cyber insurance carriers no longer take a questionnaire at your word. Before binding or renewing a policy, many now scan your external infrastructure themselves: email authentication, exposed services, patch posture. Gaps found there mean higher premiums, new exclusions, or a declined renewal. Client and vendor security questionnaires increasingly work the same way.

Before renewal

See the same external view the underwriter's scan takes, weeks before they take it, with time to fix what it finds.

Before the questionnaire

Answer client and vendor security questionnaires from evidence instead of guesses, with a report you can point to.

Before the premium moves

Fixing externally visible gaps before underwriting is the cheapest lever a practice has on its cyber premium.

We are not an insurer or a broker, and a clean report does not guarantee any premium outcome. What it gives you is the underwriter's view of your practice, first.

04The assessment

The Protector Class Business Assessment

We look at your domain the way someone targeting it would. Everything we find is written down, scored, and paired with one thing to do about it. You get it in plain language. Your IT contact gets technical detail.

Assessment category
What attackers find
Protector Class delivers
Domain & subdomain exposure
Everything visible from outside: services, DNS, certificates
Everything visible from outside, in the order to fix it
Employee credential exposure
Staff addresses, reused passwords, accounts already open
A line per person, and which password to change first
Infrastructure vulnerabilities
Services left open, admin pages reachable, software out of date
Everything found, worst first, each with what to do
Where you are being named
Where your practice is being named
Where it was found, and how to get it taken down
How the money would actually leave
Who can be named, which addresses can be faked, and how the money would move
Business email compromise risk score with domain hardening recommendations
Keys left in your website
Keys left in your website code, config files anyone can open, public repositories
The keys we found, what order to change them in, and how to stop it recurring
Forgotten asset discovery
Forgotten subdomains, DNS pointing nowhere, storage left open, certificates issued in your name
Every forgotten subdomain, and how to tidy them up
Website components out of date
Website components with known holes, or no longer maintained
What to upgrade, in order, and how to stop it recurring
Remediation roadmap
Everything found, ordered by what is most likely to be used
One step per finding, in the order to do them
05What you receive

The write-up, and someone watching after it. Two to three days.

The summary is written so anyone can read it. Hand it to your partners, your insurer or your regulator. Watching carries on after it lands.

A one-page summary anyone can read One score, and what makes it up A technical section your IT person can work from A running order for fixing things FTC / FCRA compliance documentation A walkthrough with your protector, if you want one
Where you check what changed

A page of your own, updated continuously

When the assessment is done you get a page of your own to check. What changed, what is new, which passwords have turned up, and scan coverage status, updated continuously. This is not a report you file and forget. It is a permanent intelligence layer for your organization.

Two to three days from the moment scope is agreed
06The credential

A completed assessment is a credential. Use it as one.

A finished assessment is something you can show. A practice that is watched, and can prove it, is saying something most of its competitors cannot, because they have not done the work. Clients in law, medicine and accounting are starting to ask how their records are kept. The practices with something written down are winning engagements the others never hear about.

Client records checked and covered Watched continuously, not once a quarter What your practice is showing, written down and watched Paperwork you can hand a regulator
Record of

External Assessment

Issued by Protector Class

A one-page signed summary issued on completion of the full assessment, dated and on file with us. Forward it to your insurer, attach it to a client’s security questionnaire, or hand it to a regulator asking what you have done.

07Who this is for

Built for organizations where data is the asset

If your business holds client data, financial records, health information, or privileged communications, your exposure profile is a target. Protector Class works across every professional services vertical.

Law firms

Client confidences are your responsibility. One leaked file, one fake email, one exposed login, and you're explaining it to the Law Society and your clients simultaneously.

Medical & health clinics

Patient files are worth many times more than card numbers to whoever buys them. A PIPEDA or HIPAA breach means you must disclose it, with potential fines, and the kind of press coverage that follows a practice for years.

Accounting & tax practices

You hold banking logins, SINs, statements and CRA letters for dozens of clients. That is well known. Accounting firms are targeted specifically because the data density is unusually high.

Real estate brokerages

Wire fraud is the way money actually leaves a real estate practice. One spoofed email redirecting closing funds. The transaction looks normal until the money is gone.

Financial & advisory practices

Regulators look at how an advisory practice handles data. A breach is not only a cost, it is a question about your licence to operate at risk.

Insurance & risk advisory

You hold client risk profiles and financial information. Regulators expect you to demonstrate the same security practices you recommend to your clients.

We never name a client. Sectors only.

Standing guarantee

If the full assessment finds nothing your preview did not already show, you get the fee back.

The full assessment is meant to find what the preview could not. If it does not, you do not pay for it. If the full assessment produces nothing beyond what the preview showed, we refund the audit portion of the engagement fee. This is a standing guarantee, not a limited-time offer, not conditional on completing a survey. Written into every engagement.

08Request an assessment

What is already out there about your organization?

We read every request and confirm inside a business day. Everything said stays confidential. A mutual non-disclosure agreement is available before any work begins.

Nothing runs until you say so. Sending this form does not start anything. We agree what is in scope, and you authorise it, before a single check runs. Strictly confidential. What you send us, and anything we find, stays confidential. We reply within one business day.
Ask us to look at your practiceEncrypted channel