Darkweb and breach monitoring

Service Definition • Armstrong Bell • 8 August 2026

Document summary

This document sets out what's included in our Dark Web and Breach Monitoring solution.

Core service provision

Our Dark Web and Breach Monitoring service is designed to proactively detect and mitigate risks associated with data breaches, compromised credentials, and sensitive information being sold or exposed on the dark web. The service provides the following feature set:

  • Monitor dark web forums, marketplaces, and other illicit online sources for compromised credentials or sensitive organisational data

  • Alert customers when newly identified breaches impact their data

  • Provide detailed breach reports, including the scope and nature of exposed information

  • Detect account takeovers and deliver actionable steps to mitigate risks

  • Generate detailed risk assessments with recommendations for improved security

  • Continuous updates to ensure new threats and breach sources are monitored effectively

The solution is managed and monitored by our in-house team, ensuring threats are detected and addressed proactively. During onboarding, monitoring policies are tailored to align with the customer's organisational needs, including keywords, domains, and high-risk assets.

Service desk support

Customers can directly contact our dedicated support team for assistance with queries or issues. Typical requests include:

  • Adding or updating monitored assets, such as domains or email addresses

  • Reviewing breach alerts and determining appropriate mitigation steps

  • Clarifying breach reports and recommendations provided

  • Adjusting alert thresholds or notification preferences

Service coverage is provided in line with the customer's existing Managed IT Service support contract.

Alert management

Our team receives alerts for various events relating to the Dark Web and Breach Monitoring platform, including:

  • New breach detections or credential leaks

  • Anomalous dark web activity involving monitored assets

  • Platform updates or service disruptions

Upon receiving an alert, our team conducts an initial impact review. If applicable, communications are sent to customers with detailed findings and recommended actions.

User notification

Our platform can notify impacted users of potentially compromised or leaked credentials directly; during onboarding, our team will discuss with the customer whether this functionality is desired.

Available reporting

The platform includes several built-in reports, offering insight into threat exposure and mitigation efforts:

  • Breach and Exposure Reports: detailed insight into identified breaches and leaked data

  • Asset Monitoring Reports: overview of monitored domains, credentials, and keywords

  • Dark Web Activity Insights: highlights trends and specific threats emerging from dark web sources

Vendor escalation

Our team works closely with our preferred partner for dark web monitoring services, ensuring seamless escalation of incidents where required. All initial analysis and investigation are conducted internally before vendor escalation for advanced technical queries or platform-specific issues. This process is fully managed by our team, with no additional cost to the customer.

Addition of new features

When new features are introduced to the platform that could benefit the customer, these changes are evaluated by our team for suitability. If the changes require service disruption or modifications to core components that may impact existing functionality, this will be communicated to the customer, and a suitable path forward agreed.

For additional functionality requiring significant customisation or integration, these items will be scoped and discussed independently with the customer.

Onboarding

  • Initial consultation and requirements assessment

    • Understand the organisation's digital footprint and data protection needs

    • Identify key assets for monitoring, including domains, email addresses, and IP addresses

  • Platform configuration

    • Set up monitoring tools to track specific keywords, domains, or IP addresses

  • Baseline assessment

    • Perform an initial scan of dark web sources and breach databases

    • Deliver a baseline report of existing exposures and risks

  • User notification process

    • Establish communication protocols for alerting affected users, either directly from the platform or via our team

  • Ongoing monitoring and reporting

    • Continuously monitor dark web sources for new threats