Digital Risk Protection

Overview

Digital Risk Protection (DRP) watches the risks that sit outside your perimeter — the ones that never touch your logs, so a SIEM alone cannot see them. It runs as a scheduled agent per project, discovers external exposure, and promotes the serious findings into your normal threat queue where they are triaged, assigned and governed like any other threat.

Key capabilities:

Where the other capabilities look inside-out (the telemetry you send in), DRP looks outside-in (the attack surface you don’t control). Both land in one context.


Look-alike domains

Domains registered to resemble yours — character insertions and omissions, transposed letters, homoglyphs (visually identical characters from other alphabets), hyphenation and alternate TLDs. Each candidate is resolved and scored on the signals that decide whether it is a real threat:

Signal Why it matters
Mail-capable (MX present) The domain can send mail as you — the setup for invoice fraud and business email compromise. The single strongest signal.
Resolves to a live host Something is actually running there, not just parked.
Valid TLS certificate It looks legitimate to a visitor in a browser.
Registration age Most malicious look-alikes are young. A domain registered days ago scores far higher than one registered a decade ago.

Registration age is read from RDAP, with a WHOIS fallback for registries RDAP doesn’t serve. Where a registry publishes no registration date at all (auDA, for .com.au and .org.au, is one), the age is shown as unavailable rather than guessed — an absent age is never treated as a risk signal.

Domain age is deliberately not certificate age. A certificate is typically reissued every 90 days, so certificate freshness says nothing about how long a domain has existed.


Credential & breach exposure

Credentials tied to your monitored domains appearing in breach and stealer-log data — surfaced as an actionable threat so you can force resets before the credentials are used.


AI reputation

How the major AI models answer questions about your brand. Reputation-shaping and false claims in AI answers are treated as a security and governance risk, not a marketing metric. A default set of questions is built in, and you can add your own for the claims specific to your business.


How it works — the lifecycle

Each scheduled scan discovers findings, scores them transparently, and decides — per finding — whether to raise a new threat, leave an existing one alone, or reopen one that has materially worsened. Closing a threat is a human decision the platform respects: a domain you have already dealt with is not raised again unless the risk escalates.

Watch domains & brands Detect & score mail · cert · age · verdict Decide new · seen · escalated Promote to threat high / medium findings Worked in the threat queue triaged by agents · assigned · governed Close Own / Benign Escalate Closed threats stay closed — reopened only if the risk materially escalates
  1. Watch — the agent scans the domains and brands configured for the project on a schedule (daily by default).
  2. Detect & score — each candidate is resolved and scored transparently against the signals above, with the reasons recorded so a score can always be explained.
  3. Decide — the agent compares each finding to the threats that already exist for it (see the lifecycle rules below) and decides whether to raise, leave alone, or reopen.
  4. Promote & work — high and medium findings become managed threats; lower-risk findings stay as inventory you can browse but are not raised as threats.

The threat lifecycle applies

A promoted Digital Risk finding is a normal platform Threat — it is not a separate object in a separate console. That means the threat lifecycle you already use applies unchanged: severity and score, an owner, notes, exceptions, responses, and a close with an outcome.

The same threat is visible in two places, and they are the same record — a change in one is immediately reflected in the other:

Digital Risk threats can also be picked up by your digital workers: the L1 Triage worker assesses them like any other threat, and responses configured for the project fire when they are raised.


How re-detection is handled

A look-alike domain does not disappear because you dealt with it — it stays registered. So the agent cannot simply re-raise everything it finds on the next scan. Each finding carries a stable identity, and on every scan the agent checks the threats already recorded against that identity:

What it finds What happens
No existing threat Raise a new threat — this is genuinely new.
An open threat Leave it alone. No duplicate is created; the existing threat is already being worked.
A closed threat, risk unchanged Stay closed. Your decision is respected — the domain is not raised again, and appears under Detections as something already dispositioned.
A closed threat, risk materially escalated Reopen the same threat, with a note recording exactly what changed.

“Materially escalated” is deliberately narrow. It means the domain became more dangerous in a way a human would want to look at again — a parked domain starts sending mail, a live certificate appears, the domain starts resolving, or the verdict moves up a band. A score that drifts a few points because a DNS lookup responded differently is not an escalation and will not reopen a threat you closed.

This is the key difference from vulnerability management, where a remediated finding genuinely vanishes from the source data. Closing a Digital Risk threat is a human disposition — “we’ve looked at this, it’s fine” or “we’ve dealt with it” — and the platform holds that decision until the facts change.


Enable Digital Risk Protection

Open Digital Risk from the left navigation. If no DRP agent is deployed in the project yet, you’ll see an option to Enable a DRP Agent, which deploys one in basic mode.

Digital Risk Protection landing page showing monitored brands with per-category counts, open threats, estimated exposure and a risk score

Once enabled:


Working a Digital Risk threat

A DRP threat opens a purpose-built detail view: a plain-language summary, the estimated exposure, the technical evidence (DNS, SSL certificate, WHOIS), and the related-domain graph — with the state clearly shown and an Operations menu for assign / close / add-note / add-exception. The shared timeline sits below, so notes and evidence read in one place.

Findings that were detected but not raised as a threat (below the promotion threshold, or already dispositioned) appear under Detections on the brand page — expand a row to see why it wasn’t raised.


Need Help?

For assistance with Digital Risk Protection, contact support@secure60.io.

See also Detect & Investigate for how threats are triaged and closed once DRP raises them.

Back to top