Risk, Fraud & Security
Spotting the transaction, message or behaviour that should not be there.
- Transaction monitoring
- Threat detection
- Phishing triage
- Policy enforcement
Checking what leaves the organisation against its own data-handling policy
Inspects outbound mail, file uploads and text pasted into external services for the categories the policy says must not leave — customer identifiers, source code, unreleased numbers — and blocks, quarantines or warns the sender, recording what was matched, on which rule, and who owns that rule.
- Effort
- Weeks of work
- Organisation size
- Enterprise
Triaging what staff report to the phishing mailbox
Reads each message forwarded to the report-phishing address, pulls sender, headers, links and attachments out of the raw source, collapses reports of one campaign into a single case, and drafts a verdict naming the indicators it relied on — so an analyst confirms or overturns a judgement instead of opening four hundred near-identical mails.
- Effort
- Weeks of work
- Organisation size
- Mid-market
Ranking security-log anomalies for the analyst queue
Learns what ordinary behaviour looks like for each account, host and service from the organisation's own logs, then surfaces the windows that depart from it — an account authenticating from a new country at an unusual hour, a host suddenly talking to hundreds of internal addresses — each presented with the baseline it broke and the published technique it resembles.
- Effort
- More than a few weeks
- Organisation size
- Enterprise
Working the alert queue a transaction-monitoring system produces
Scores the alerts a rules-based monitoring system raises against how that customer, product and corridor have behaved before, groups related alerts into one case, assembles the account history and counterparty links an investigator would otherwise pull by hand, and orders the queue — leaving the decision to file or close with a named person.
- Effort
- More than a few weeks
- Organisation size
- Enterprise