
One practice, because the two halves keep each other honest
Most firms either prevent incidents or investigate them. Doing both means our assessments are informed by live casework, and our investigations are run by people who know how the control was supposed to work.
- Traced across live matters since 2019
- $412M
- Investigations and assessments delivered
- 230+
- Chains under first-party coverage
- 14
- Jurisdictions worked with counsel
- 31
We kept investigating incidents that a review had already passed
The pattern was hard to miss. Clean assessment report, incident six months later, and the failure sitting in something the review had scoped out: a signer who never got offboarded, a deployment key on a laptop, an approval nobody screened. The reviewers were not incompetent. They just had no exposure to how these systems actually get broken.
- Findings from live matters feed straight back into assessment scope
- Assessment engineers sit in on exploit reconstructions
- The same team carries a matter from intake to filed report
- No handover to a stranger halfway through

Four commitments we will not trade for a fee
These have cost us engagements. We would rather lose the work than write a report we would not want to defend.
Say what you can prove
Chains produce facts and inferences, and the difference matters enormously once someone is cross-examining you. We label which is which, every time, even when the inference is the interesting part.
Never sell hope
Nobody can guarantee recovery. Firms that imply otherwise are charging distressed people for optimism. We tell you what is realistically available before you spend anything.
Speed is a control
The first day of an incident is worth more than the next thirty. We staff an actual rota so the answer to a 2am call is an investigator, not a ticket number.
Show the working
Every cluster merge, every demix inference, every attribution carries its basis in the report. A competent stranger should be able to re-run our work and land where we did.
Fifteen people, deliberately
We staff for depth rather than headcount. Every matter is worked by someone senior, because the alternative is a junior learning on your incident.
Lead investigators
Former financial crime analysts and protocol engineers. Every one of them has given evidence or supported counsel who did.
Security engineers
Custody, contract and infrastructure specialists. They also review the exploits our investigators reconstruct, which is the point.
Advisory & regulatory
Ex-supervisory and MLRO backgrounds. They have sat on the other side of the examination table and write for that reader.
Verifiable credentials, kept current
The certifications below are held across the practice and re-certified on schedule. We are happy to evidence any of them during procurement.

Every chain keeps a record. Our job is making it say something.

Bring us the matter nobody else could close
Cold cases, contested attributions, assessments that need to hold up in front of a regulator. That is the work we are built for.