Cybersecurity
Dark Web Monitoring
Useful. Just not first.
Dark web monitoring watches criminal marketplaces, paste sites and stolen-credential dumps for your domains, staff email addresses and company details, and tells you when something of yours appears. It is a useful early warning. It is also a lower-value control than multi-factor authentication, and nobody, including us, can remove your data once it is out there.
Who it's for
Worth buying for the right reason.
It is an inexpensive early warning attached to a defined action. It is not a protective measure, and any page that implies otherwise is selling.
You want to know when a staff password turns up in someone else’s breach. Usually from a third-party website an employee signed up to with their work address, using a password they also used at work. That is the ordinary, realistic case, and it is the one this catches.
A client or insurer asked whether you monitor. It has started appearing on questionnaires as its own line, and answering yes is inexpensive.
You are acquiring a company or onboarding a supplier. A one-off look at what is already circulating about an organization is reasonable diligence, and it is a different job from continuous monitoring.
Someone showed you a free report. Running a domain through a free tool and presenting a long list of long-changed passwords is a standard sales approach. We will read it with you and mark which lines still mean anything. Usually very few.
Where this sits in the order
If your budget is fixed and multi-factor authentication is not yet on every account, spend it there instead. A leaked password that cannot be used on its own is a much smaller problem than one that can.
We would rather sell you this second than sell it to you first.
What's included
What is watched, and what happens when something appears.
The monitoring is the commodity half. The value is entirely in what is attached to the alert.
-
Domains, mailboxes and named executives
Your email domains, individual addresses for the people who matter most, and directors’ personal addresses where they ask for it, a director’s personal account is a business problem.
-
Credential dumps and combination lists
The bulk files that circulate after a third-party breach, where the overwhelming majority of genuine hits come from. Not a screenshot of a forum, which is what some demonstrations show you.
-
Alerts with context, not a raw feed
Each hit arrives with where it surfaced, how old the record looks, and whether the exposed password is anything like one currently valid in your directory. Context is what turns a line of text into a decision.
-
A defined action for every hit
Reset the password, revoke active sessions, check for new mailbox rules and any newly added second-factor method, and check whether that password pattern is in use anywhere else. Written down in advance, so nobody has to invent it at the time.
-
Reuse checking inside your own tenancy
Comparing an exposed credential against what is actually valid today is what separates a headline from a task. Most hits are already dead. Confirming that quickly is a real part of the service.
-
Supplier and acquisition checks
A scoped, one-off look at another organization’s exposure, for due diligence or before granting a supplier access to your systems. Delivered as a short written summary rather than a data dump.
-
A quarterly summary that says so when nothing happened
Including the months with no hits. Silence from a monitoring service should be evidence that it is running, not an absence of evidence.
How it works
Set it up, clear the backlog, then it goes quiet.
The first fortnight is noisy and mostly historical. After that a hit is rare, which is exactly what you want from this.
-
Decide what is watched
Domains, addresses and the handful of individuals worth watching personally. We agree who receives an alert and who has authority to force a password reset without asking first.
-
Work through the history
The first run always returns years of accumulated records. We sort them into still-valid, already-changed and irrelevant, force resets where anything is live, and give you a short list rather than the export.
-
Then handle hits as they come
A new hit runs the agreed sequence within the hour it is seen, and you get a note saying what was exposed, what we did and whether it was still usable. Reviewed with everything else each quarter.
What it costs
Included with monitoring, not sold on its own.
An alert with nobody attached to act on it is a subscription, not a control. That is why we bundle it rather than list it.
Dark web monitoring is included in happier IT’s managed security service and in managed IT It is deliberately not a separate line on your invoice.
What cannot be bought
Nobody can delete your data from a criminal forum, and any vendor implying otherwise is selling a service that does not exist.
Removal services that do work operate on data brokers and people-search sites, legitimate businesses with a legal obligation to respond. That is a genuinely different product, and worth knowing about, but it is not this one.
Why us for this
The value of a provider who ranks their own products honestly.
This page is the easiest one on the site to write badly. The standard version leads with a screenshot of a marketplace and a count of your exposed records, because that works. The reason we do not is practical rather than principled: a control bought while alarmed is a control nobody maintains.
What happier IT will do is attach the alert to people. Hits route to our security operations centre in Canada, staffed by our own employees, who check the credential against your live directory before anybody is asked to do anything. Staffed hours: 24/7, with the Surrey office on Monday to Friday, 8:00 am to 5:00 pm Pacific.
And if you ask us whether to buy this before you have multi-factor authentication everywhere, the answer is no.
Go deeper
- What is dark web monitoring? The plain version, including the limits.
- What is MFA? The control that makes a leaked password less useful.
- Identity and access management Where a hit gets actioned.
Questions
What people ask before they sign anything.
What is dark web monitoring?
It is a service that continuously searches criminal marketplaces, forums, paste sites and leaked-credential collections for your domains, email addresses and company information, and alerts you when something matching turns up. Despite the name, most genuine findings come from bulk files of stolen usernames and passwords rather than anything resembling a shop front. Its purpose is early warning, so a password can be changed before it is tried.
Can you remove our data from the dark web?
No, and neither can anybody else. Once a credential file has circulated it exists in copies nobody can enumerate, let alone delete. Anyone offering removal is either misunderstanding the product or misrepresenting it. What you can do is make the exposed data useless: change the password, revoke the sessions, and make sure a password alone was never enough to sign in.
We got a hit. What should we do?
Work through a fixed sequence rather than improvising. Reset that password and revoke active sessions. Check the mailbox for new forwarding or filing rules. Check whether an unfamiliar second-factor method was registered. Check whether the same password pattern is used on other systems, including personal ones. Then note whether the record was old, most are, and confirming that is a legitimate outcome rather than an anticlimax.
Does a hit mean we have been hacked?
Usually not. The common case is that a website someone signed up to with their work email address was breached, and their password for that site is now in a list. Your systems were not touched. It becomes your problem only if that password was reused at work, or is close enough to a work password to guess, which is exactly why the check against your own directory is part of the service.
How is this different from Have I Been Pwned?
Have I Been Pwned is an excellent free service, and for a single address you should just use it. The differences that justify paying are scope and attachment: monitoring across your whole domain continuously, alerting on new appearances rather than requiring someone to remember to check, and a defined response with people who will carry it out. If nobody will act on an alert, the free tool is the honest answer.
Is dark web monitoring worth it?
Yes, once the things above it are done. It is inexpensive, it occasionally gives you days of warning you would not otherwise have had, and it answers a question insurers now ask. It is worth considerably less than multi-factor authentication, endpoint detection and a tested backup, and any provider putting it ahead of those is arranging their product list rather than your risk.
What does dark web monitoring cost?
Standalone monitoring is cheap enough that the question is never really the price, it is whether anyone will act on what it finds.
Related
Where to go next.
Related services
Worth reading
Want to know what this would look like for you?
A 30-minute call. No slides, no audit fee, no obligation. We ask what is breaking and tell you honestly whether we are the right fit.