Skip to main content

Domain

Cybersecurity

Adversary tradecraft rarely announces itself. We track intrusion sets, pre-positioned access, and infrastructure exposure so decisions are made before the disruption, not after it.

Services

Cyber intelligence practice

Nation-state threat tracking

Attribution-aware reporting on Chinese, Russian, Iranian, and North Korean intrusion activity relevant to your sector and geography.

Critical infrastructure exposure

Assessment of OT and IT convergence risk across energy, ports, telecom, water, and transportation.

Ransomware and extortion

Actor profiling, initial-access trends, exploited vulnerabilities, and third-party provider abuse.

Pre-positioned access

Indicators of dormant footholds intended for crisis activation rather than immediate espionage or theft.

Executive cyber briefings

Board-ready briefings translating technical intelligence into operational, legal, and reputational risk.

Incident-adjacent advisory

Independent analytic support during and after an incident, including adversary intent and escalation assessment.

Library

Cyber and electronic warfare assessments

SM-2026-TA-118Threat level: High

QTFY's IoT Obfuscation Network and Persistent PRC Cyber Access

U.S. authorities disrupted QScan and QTRouter, platforms attributed to the PRC-linked QTFY group that weaponized thousands of IoT devices and proxy systems to obscure cyber operations against government, defense, financial, academic, and critical-infrastructure targets.

  • Cybersecurity
  • Critical Infrastructure
  • China
SM-2026-TA-116Threat level: Elevated

Venezuela's Oil Control Accord Reshapes Hemispheric Energy Risk

Washington's announced majority-control arrangement over Venezuelan reserves could reorder hemispheric energy relationships, but unclear legal authority, underinvestment, grid weakness, and limited export capacity make rapid production gains unlikely.

  • Energy Security
  • Political Stability
  • Foreign Investment