Cyber threat intelligence · Cyber indications and warning · Digital footprint and risk

Intelligence first.
Operations follow.

Most security programs buy the tools, then go looking for something to point them at. We work the other way around: decide what you need to know, collect against it, and let the answer drive what gets changed, bought, or watched. Intelligence sets the risk picture. The risk picture sets the spend.

Thirty years of intelligence work — Navy, DC3, Northrop Grumman, Red Sky Alliance — applied to companies and families who are targets but have no analyst of their own.

Why intelligence

You cannot defend everything. Intelligence is how you choose.

Security budgets are finite and adversaries are not. Every program eventually has to decide what it will not protect, what it will not buy, and what it will not watch. Most organizations make those decisions by default — by catalog, by compliance checklist, by whoever presented last. An intelligence function makes them on purpose, against evidence, and writes down the reasoning so it can be judged later.

Tools answer what happened. Intelligence answers what is coming.

Detection is retrospective by construction — something has to occur before it alerts. Warning is the only part of the stack that operates before the event, which is the only point at which you still have options.

Spend without a threat model is a bet nobody wrote down.

Buying controls before naming the threat means the threat model exists anyway — it is just implicit, unexamined, and usually inherited from a vendor whose interests are not yours.

Most of what will hurt you is outside your perimeter.

Credentials already for sale, a supplier being compromised this week, a principal's address in a broker file, a persona being built to impersonate your CFO. None of it generates a log on your network until it is too late.

A judgment you can argue with beats a score you cannot.

Assessments state confidence, grade sources, and name the alternative explanation where evidence is thin. That is what makes them reviewable — and what lets you hold us to them afterward.

Warning buys the one thing money cannot: time to act before the decision gets made for you.

The cycle

Requirements first, then collection. Never the reverse.

Onboarding produces five to nine priority intelligence requirements — each one a question a decision rests on. No requirement, no collection. That single rule is what separates intelligence from a feed subscription.

01

Requirements

Priority intelligence requirements: what you must know, written as questions, each tied to a decision, an owner, and a risk.

02

Collection

Managed collection against those requirements — open sources, sector reporting, criminal markets and leak sites, credential exposure, brokers, public records. External and lawful.

03

Analysis

Confidence stated, sources graded, alternatives named where the evidence is thin. Fact kept visibly separate from assessment.

04

Indications & warning

Indicators watched against declared thresholds. When one trips, you get the observation, the risk it moves, and the decision it forces.

05

Action

Your staff or your MSP execute. We score afterward: did the indicator predict, and did it change what you did.

The cycle closes each quarter. Every requirement is re-scored as still relevant, retired, or replaced — which is also how you find out whether you are paying for intelligence or for noise.

Risk

Threat against exposure against consequence, stated as something you can argue with — not a color on a heat map.

Digital footprint

Everything about your company, your people and their households that an adversary can collect without touching your network.

Cyber indications and warning

Named indicators, declared thresholds, and a notification path agreed before anything trips.

Priority intelligence requirement

A question a decision rests on. Collection exists to answer it, and nothing else.

Exposure

Credentials, infrastructure, third parties and supply — the surface an adversary already sees.

Decision advantage

Knowing early enough that you still have choices. The only output that matters.

What we set out to answer

The questions. Yours will be specific; these are the shape of them.

Onboarding turns worry into priority intelligence requirements — questions a decision rests on, each with an owner and a date. Collection exists to answer them and nothing else. These are the ones that recur across the sectors we work in; your set gets written against your business, and re-scored every quarter.

The company

Who is coming, and what do they already have?

  • Who targets companies like ours right now, by what method, and has that changed this quarter?
  • What of ours is already exposed — credentials, infrastructure, people, documents?
  • Is anyone preparing to impersonate us to our customers, our bank, or our prime?
  • If we were going to be hit, what would we see first — and is anyone watching for it?
Suppliers and partners

Whose failure lands on us?

  • Which suppliers could stop our operation, and which hold our data without us thinking of them as vendors?
  • Is one of them being compromised right now, and would we learn it before their press release?
  • Which of our contracts make their breach our notification obligation?
The principal and household

What can a stranger assemble about us?

  • What does our digital footprint give away — addresses, routines, family members, staff?
  • Has anyone shown interest in us, and is that interest escalating?
  • Where do our physical movements become predictable enough to act on?
  • What comes down first, and what cannot be removed at all?
The transaction

What are we buying along with the company?

  • Has this target already been breached, and would we inherit the consequence after closing?
  • Is there sanctions or remote-workforce exposure sitting in their payroll?
  • What watch items follow us past the close, and who owns them on day one?

What we produce

Four products. Fixed fee. Nothing hourly.

Entry

Threat & Risk Profile

Who targets your sector and by what method, what your digital footprint already exposes, the risks that follow ranked against your tolerance, and the standing requirements that come out of it. The baseline everything else is measured against.

One time · 3–4 weeks
Subscription

Watch — Indications & Warning

Standing collection against your requirements, a monthly written risk assessment, a warning product the moment a threshold trips, and a quarterly briefing to the board or the owner.

Monthly · 12-month term
Principal & household

Gingerbread — Digital Footprint

The digital footprint of a named individual and their family: data-broker exposure, doxxing and threat chatter, residence and travel context — what a stranger can assemble, how they would use it, and what comes down first.

Assessment · quarterly refresh
PE & M&A

Transaction Intelligence

Pre-close diligence on a target: breach history, exposed credentials, adversary interest, third-party and supply-chain risk, digital footprint, and the warning items that follow you past closing.

Per deal · 2–4 weeks

And when you need someone to own it

A Chief Information Security Officer on retainer.

Intelligence tells you what is coming. Somebody still has to decide what gets fixed, answer the insurer, brief the staff, and run the incident at two in the morning. For companies too small to carry a full-time security executive, that seat is the virtual CISO retainer — and it starts where the intelligence does: I find out what an adversary already knows about you before I recommend a single control.

Every price is fixed or published before the first call. No software sold, no cut of what you buy, and I do not replace your IT.

Published pricing

Main Street Security Check
New Hampshire · under 25 employees
$1,495
Fixed · on site
Main Street CISO
New Hampshire · under 25 employees
$750
Per month
Virtual CISO retainer
Companies under 50 employees
$4,000
Per month
Virtual CISO retainer
50 to 200 employees · CMMC and 800-171 where applicable
$6,500
Per month

What drives what

Intelligence decides; operations execute.

  • Spend follows the risk picture. Controls get funded because a named risk moved, not because a vendor's matrix has a gap.
  • Warning has a clock and a channel. Agreed at onboarding: the threshold, who is called, in what order, at what hour, and who can act.
  • Every warning is scored. Did the indicator predict, and did you act. That record is the renewal argument.
  • Physical and cyber are one picture. A permit filing, a scheduled appearance and a credential dump are indicators of the same kind, on the same risk register.

Boundaries

What we don't do, said up front.

  • No SOC, no alert queue, no 24/7 watch floor, no incident retainer.
  • No device management, no tooling deployed or administered in your environment.
  • No access to your production systems. Collection is external unless you hand us an artifact.
  • No software resold, no cut of what you buy. You license in your own name.

This does not replace an MSSP for security operations or an MSP for running IT. It is the layer neither of them sells: someone whose job is to know what is coming and to say so in writing.

Who this is for

Targets without an analyst.

Eight years running an MSSP, with direct operating experience in the first four. I know what an adversary wants from each of them, because I have defended against it.

Family offices & UHNW households

The risk attaches to the person, not to a company. The digital footprint is the attack surface, and nobody on staff does this work.

Defense contractors and suppliers

CMMC and 800-171 pressure, a prime demanding answers, and a nation-state adversary that is genuinely interested in the program you support.

Architecture & engineering

Drawings, specifications and client property data that are valuable to a competitor and to anyone casing the buildings you designed.

Manufacturing

Process knowledge worth stealing, a supply chain worth impersonating, and a plant floor where downtime is measured in shifts.

PE & lower-middle-market sponsors

Deal-timeline pressure and real transaction risk. The cost rides on the deal rather than on operating expense.

Banks, credit unions, insurers

Examiners expect a threat intelligence function and a defensible risk assessment. Boards want a named analyst, not another dashboard.

Daily intelligence brief · blog.monadnockcyber.ai

What happened in cyber in the last 24 hours — verified, graded, stripped of hype.

Published every weekday under a byline. Confirmed facts and unverified claims are labeled throughout, with the risk implication called out where there is one. It is a working sample of the product: read a week of it and you will know exactly what you would be buying.

Read today's brief All briefs →
30 yrs
Navy intelligence officer · Carnegie Mellon SEI
DC3 / DCISE
Defense Cyber Crime Center leadership
Northrop
CISO, $7B Electronics Sector
Exterran
Global CISO, Houston · 2018–24
Trusted Internet
Founded and sold · MSSP, eight years
Red Sky
Founded Wapack Labs / Red Sky Alliance

Start here

Find out what your digital footprint exposes.

The self-assessment is free and takes about twenty minutes. You get a scored risk result and the gaps in writing. If the result warrants a conversation, we will have one; if it does not, you still keep the assessment.

Connect

Start with a conversation.

Principal
Jeff Stutzman
Email
[email protected]
Direct
603 930 2222
Office
Amherst, New Hampshire

If something looks wrong

Call before you change anything. The evidence worth having is the same evidence that gets destroyed by cleaning up. Answered day or night.

Under attack?