Обновлено

VULNERABILITY ANALYSIS / RISK MAPPING

A vulnerability becomes a risk when the other party understands how to exploit it

BLACKFILE establishes the circumstances through which financial, legal, informational, reputational or operational harm may be caused to a person, family or company

We check public information, corporate and financial connections, digital footprint, environment, recurring incidents and critical dependencies. The result is a prioritized risk map indicating confirmed circumstances, probable scenarios and possible mitigation measures

At the initial stage it is sufficient to explain what needs to be protected and what circumstances give rise to concern

  • PUBLIC EXPOSURE
  • ENVIRONMENT
  • CORPORATE LINKS
  • DIGITAL TRACE
  • DEPENDENCIES
  • RISK PRIORITY
ОБЪЕКТзащиты0102030405
Red marks a material confirmed risk, not an assumption
02 / INITIAL SITUATION

Material risk is rarely found in a single source

A single publication, a person from the environment, an old company, an accessible document or a digital trace may not appear dangerous on its own. Vulnerability arises when this information forms a coherent pathway for exerting influence.

A standard check often shows circumstances in isolation. Vulnerability analysis establishes the connections, dependencies and scenarios under which individual factors can cause actual harm.

We do not create a sense of threat. We determine which risks are confirmed by facts and which actions are actually necessary.

03 / WHEN AN ASSESSMENT IS NEEDED

When the interest being protected becomes visible to another party

The working environment in which security decisions are made
  1. 01

    Before a public appointment

    It is necessary to understand what information, connections and past events may affect a person or organization once the appointment is announced.

  2. 02

    Before a major transaction

    Factors that could be used for pressure, to shift the negotiating position or to disrupt an agreement are checked.

  3. 03

    After threats or suspicious contacts

    The context of events, possible sources of interest and points of influence available to the other party are reconstructed.

  4. 04

    After an information leak

    It is checked what information has become accessible, what it may be connected to and what risks its further distribution creates.

  5. 05

    When the environment changes

    People who have gained access to information, premises, schedules, family or corporate processes are assessed.

  6. 06

    Before an international relocation

    Differences in the legal environment, public information, local risks and new operational dependencies are analyzed.

  7. 07

    For a family or family office

    The combination of public information, staff, contractors, assets, routes and communication habits is checked.

  8. 08

    In case of political or reputational risk

    Connections, publications, conflicts and circumstances that may take on new significance if the external environment changes are assessed.

04 / RISK CONTOURS

From informational exposure to critical dependencies

The scope of the check is determined by the interest being protected. Each factor is assessed separately: whether it is confirmed, how likely the scenario is, and what impact it could have.

01

Informational exposure

  • personal and corporate information
  • public documents
  • publications
  • disclosure of routes and habits
  • available information about family
  • material contradictions
02

Environment

  • people with access to information
  • employees and contractors
  • former partners
  • conflictual relationships
  • informal intermediaries
  • dependence on specific individuals
03

Corporate connections

  • related companies
  • joint assets
  • nominee roles
  • unresolved obligations
  • conflicts of interest
  • problematic counterparties
04

Financial circumstances

  • public information on assets
  • debts
  • pledges
  • court-ordered recoveries
  • financial dependencies
  • factors of possible pressure
05

Digital footprint

  • open digital traces
  • disclosure of contact details
  • available internal information
  • signs of a leak
  • vulnerability to social engineering
  • inconsistency of digital profiles
06

Operational dependence

  • key employees
  • critical suppliers
  • sole channels of communication
  • concentration of authority
  • absence of a backup scenario
  • dependence on a single contractor or system
07

Limits of the check

  • closed sources
  • circumstances without independent confirmation
  • differences between jurisdictions
  • questions requiring technical expertise
  • information that cannot be obtained lawfully
Situation Room: analysis of risk factors and priorities
RISK PRIORITY

Priority is determined not by how alarming an indicator looks, but by the combination of probability and possible impact

05 / RISK PATH

Risk is assessed as a sequence, not as a single alarming indicator

Select the subject of protection and the scope to see confirmed risk factors

Red marks a material confirmed risk, not an assumption

  1. 01Available information: what can already be found out about you by lawful means.
  2. 02Possible subject of impact: to whom this information is of practical use.
  3. 03Point of contact or dependence: through what access or influence is possible.
  4. 04Likely scenario: how a sequence of events may unfold.
  5. 05Possible consequence: financial, legal, informational or operational.
  6. 06Risk mitigation measure: what can be changed, and in what order.

Each scenario is accompanied by a separation of confirmed facts from analytical assumptions, together with an assessment of likelihood, impact, and the limits of the assessment itself.

06 / RESULT

A prioritized risk map instead of a list of abstract threats

The final materials separate confirmed circumstances from analytical assumptions, and measures are ordered by priority rather than by the length of the list.

R-01 / RESULT

Profile of available information

What can be established about you or the company through lawful means: public information, documents, traces and points of contact.

R-02 / RESULT

Map of people and dependencies

The circle of associates, intermediaries, key employees and connections through which information or control passes.

R-03 / RESULT

Confirmed vulnerabilities

A list of factors confirmed by sources, indicating exactly what they expose.

R-04 / RESULT

Scenarios and matrix

A description of likely scenarios with an assessment of the probability and impact of each.

R-05 / RESULT

Response priorities

What makes sense to change first, and which measures produce the greatest effect at the lowest cost.

R-06 / RESULT

Questions for specialist teams

What to pass on to the legal, technical or security team, and the limits of the check performed.

BLACKFILE does not guarantee the absence of all possible threats. The assessment reflects circumstances established by lawful methods as of the agreed date.

07 / CLIENTS

For those responsible for consequences, not only for responding to an incident

CL-01 / CLIENT

Wealth owners and Family Offices

When it is necessary to protect not only assets but also the family's private life, routine and circle of trusted persons.

CL-02 / CLIENT

Executives and public representatives

When a position makes a person visible, and any available detail becomes an instrument of pressure.

CL-03 / CLIENT

Boards of directors and companies

When the risk is tied to concentration of authority, dependencies and disclosure of internal information.

CL-04 / CLIENT

Legal teams

When it is necessary to understand what circumstances the other side could rely on in a dispute or negotiation.

CL-05 / CLIENT

Investors

When the vulnerability of a project or its founder could affect valuation and investment timing.

CL-06 / CLIENT

Security specialists

When a verifiable factual basis for protection priorities is needed, rather than a general list of threats.

08 / SCENARIOS

How the assessment changes protection priorities

Executive's office ahead of a public appointment
VA-01Pre-Appointment ReviewA composite example based on typical tasks

Risk assessment ahead of a public appointment

Задача. The interest protected - the executive's reputation and the company's stability after the announcement. Before the appointment, it was necessary to understand what information was already available and how it could be used.

Результат. Publications and open profiles disclosed regular routes and a circle of close contacts, part of the information was confirmed in registries. A list of priority measures was prepared before the announcement date. Limitation: closed sources were not checked, the assessment reflects the state as of the agreed date.

One jurisdiction
VA-02Information ExposureA composite example based on typical tasks

Identifying an information vulnerability following a corporate conflict

Задача. The interest protected - internal information and the stability of processes. After a partner's departure, the company faced a leak and could not determine through which channels the information may have left.

Результат. A review of access rights and the surrounding circle showed unrevoked access rights of former employees and disclosure of internal information in public materials. The source of the leak could not be conclusively established, which is stated directly in the report.

International matter
VA-03Family EnvironmentA composite example based on typical tasks

Review of the family's circle of contacts following suspicious approaches

Задача. The interest protected - family safety and routine. After several attempts by new individuals to get closer, it was necessary to determine whether this was coincidence or a pattern.

Результат. Overlaps were established between the new contacts and the prior business circle, as well as public posts disclosing routine. Some connections remained unconfirmed and are marked as requiring further verification.

Several connected jurisdictions
VA-04Pressure FactorsA composite example based on typical tasks

Analysis of pressure factors ahead of an international transaction

Задача. Protected interest - negotiating position and deal terms. Before signing, it was necessary to understand what circumstances the other party could rely on.

Результат. Open-source information on liabilities and dependence on a single supplier in the delivery chain was identified. A probability and impact matrix with priorities was prepared before negotiations began.

International matter

The scenarios presented are composite examples based on typical tasks. They are not descriptions of specific completed projects. BLACKFILE does not promise to detect all possible threats and does not guarantee absolute security.

09 / PROCESS

First we define the protected interest, then we check possible avenues of influence

  1. 01

    Initial contact

    The client describes what needs to be protected and what circumstances give rise to concern.

  2. 02

    Verification of the lawfulness of the task

    We assess the purpose, conflict of interest and permissible working methods.

  3. 03

    Defining the subject

    We agree on the object of protection and the protected interest: a person, family, company or role.

  4. 04

    Subjects and scenarios

    We identify who could practically make use of the available information and which scenarios are realistic.

  5. 05

    Collection and comparison

    We gather information from lawful sources and cross-check it across circuits.

  6. 06

    Verification of factors

    We check material factors and separate what is confirmed from what is assumed.

  7. 07

    Probability and impact

    We assess each scenario for probability and possible consequence.

  8. 08

    Risk map

    We build a priority map and risk mitigation measures.

  9. 09

    Confidential discussion

    We review the results and pass questions to the relevant specialist teams.

10 / ENGAGEMENT FORMAT

Engagement formats and cost

Choose the depth of the engagement depending on how many objects of protection and circuits are involved and how complex the context is.

01

Vulnerability Snapshot

From €3,000

Usually 5-7 business days

The final cost depends on the number of objects, countries, scenarios, depth of verification and agreed timeframe. Third-party expenses are agreed in advance.

A rapid assessment of available information and priority risk factors for one object of protection.

Included
  • one object
  • one main scenario
  • public information
  • basic analysis of environment
  • digital and corporate indicators
  • up to five priority factors
  • brief risk map

A brief risk map with priority factors and the limits of verification.

02Recommended format

Vulnerability Assessment

€6,000 to €15,000

Usually 10-20 business days

The final cost depends on the number of objects, countries, scenarios, depth of verification and agreed timeframe. Third-party expenses are agreed in advance.

A full assessment across several circuits with verification of environment, connections and digital footprint, and construction of a probability and impact matrix.

Included
  • several risk circuits
  • extended verification of environment
  • corporate and financial connections
  • digital traces
  • several impact scenarios
  • probability and impact matrix
  • detailed report
  • recommendations for relevant specialists

A detailed report with a probability and impact matrix and response priorities.

03Strategic

Strategic Risk Review

On request

Timeframe determined after briefing

The cost is determined after the briefing and depends on the number of objects, countries and the complexity of the context. Third-party expenses are agreed in advance.

Work with an individual, family and related companies across several countries with an extended scenario model.

Included
  • individual, family and related companies
  • several countries
  • complex, adversarial context
  • extended scenario model
  • individual dependency map
  • materials for the legal and security team
  • support in discussing the results

An individual dependency map and materials for the legal and security team.

11 / ADMISSIBILITY

A risk assessment must not itself become an intervention

BLACKFILE does not engage in unlawful surveillance, obtaining private correspondence, hacking, pressure, provocation or interference in private life.

We do not promise absolute security or the detection of every possible threat. The assessment reflects what has been established by lawful methods as of the agreed date, and it always states its limitations.

  • lawful purpose and agreed scope
  • separation of facts from assumptions
  • prioritization by likelihood and impact
  • honest limitations of the assessment
  • minimum of sensitive data
  • confidentiality of the client
13 / QUESTIONS

What is important to understand before the assessment begins

A Background Check answers the question of who a person is and what can be confirmed about their past. A vulnerability assessment answers a different question: which circumstances around you could be used by another party and in what order they should be addressed. The former looks backward, the latter - forward, at possible scenarios.

Yes, and this is one of the frequent tasks. We check public information about the family, routine, the circle of assistants and persons with access, as well as digital traces revealing locations and schedule. We do not collect data on children beyond what is necessary and do not take on tasks that in themselves violate privacy.

Yes, the immediate circle is one of the main areas of scope. We look at who has access to information, whether there is dependence on a single person, whether conflicting relationships and informal intermediaries exist. The check is conducted through lawfully accessible sources, without surveillance or contact with the persons being checked without prior agreement.

Yes, within the scope of open sources: accessible contact points, reuse of addresses and numbers, disclosure of internal information, public indications of leaks. We do not obtain access to correspondence, devices or private accounts - this falls outside the scope of lawful work.

Sometimes it is possible to establish the circle of persons for whom the available information is of practical use, and to confirm connections between episodes. A definitive identification of a specific individual is not always possible, and we do not present a hypothesis as an established fact. In the report, such conclusions are accompanied by a degree of confirmation.

It remains in the report as unverified, with the reason stated: closed source, no independent confirmation, differences between countries. Such factors do not disappear from the picture, but they are not given priority equal to confirmed ones - otherwise measures would be misdirected.

Yes, and this is often necessary: information unavailable in one jurisdiction may be disclosed in another. Each country involves its own sources and legal limitations, and the number of countries directly affects timing and cost.

For an initial assessment, a description is sufficient: what needs to be protected, what circumstances are of concern, which countries are involved, and whether any incidents have occurred. Documents and personal data are not submitted at this stage - they are requested only after a secure channel has been agreed.

Snapshot usually takes 5-7 business days, a full assessment - 10-20 business days. The strategic format depends on the number of subjects, countries, and the complexity of the context; the timeframe is determined after the briefing. The countdown begins once the scope has been agreed.

Only the client and the specialists named by the client. We do not share materials with third parties and do not disclose the fact of the engagement. If the results are intended for a legal, technical, or security team, the report structure is agreed in advance.

Yes, and we account for this in the structure of the materials in advance: conclusions are separated from assumptions, each material fact is accompanied by a source and date, and measures are formulated so they can be handed to specialists without additional explanation. You determine the list of recipients.

Information about the client, the subject of protection, and the content of the work is not disclosed, materials are not shared with third parties, and access within BLACKFILE is limited to the specialists involved in the matter. We do not contact people from the subject's circle without your separate approval, since such contact itself changes the situation.

Risk becomes manageable once its source, route, and possible consequences are understood

14 / INITIAL ASSESSMENT

Describe what needs to be protected and what circumstances are causing concern

At this stage, general information is sufficient. Do not attach documents, personal data, or incident materials. After reviewing the matter, we will propose a secure channel for further work.

Contact

An initial enquiry creates no obligations and does not mean the matter is automatically accepted.