Industry application · Priority 04

Cybersecurity, Privacy and Digital-Risk Research

Verify vendors, incidents, certifications, public claims and regulatory context without pretending to perform technical testing.

The subject changes. The core question does not: can this information responsibly be relied upon for the decision being made?

Cyber and privacy decisions often depend on technical claims, security certifications, incident accounts, regulatory obligations and vendor assurances. Aperture independently researches the documentary and public-source foundation surrounding those claims.

US and regulated-matter review

US-facing assignments are accepted only after jurisdictional, intended-use, data and professional-boundary review. Aperture does not provide consumer reports, employment or tenant screening, licensed private-investigator services, legal advice, regulated KYC or AML certification, or eligibility determinations. Restricted government, export-controlled, protected health and regulated financial-customer information is not accepted without separate written approval and suitable controls.

Read the US assignment acceptance policy

Typical questions

Questions clients may bring to us

  • Does the vendor’s public security posture match its representations?
  • What is established about the breach, incident or response chronology?
  • Are claimed certifications, controls or regulatory positions current and correctly described?
  • Which issues require direct testing by qualified cyber or privacy specialists?

Why it matters

A clearer foundation before reliance.

The client gets a disciplined documentary view that separates verified public facts from technical assertions that still need direct examination.

What we investigate

Research shaped around the assignment

  • cyber-vendor and product claims
  • breach and incident chronology
  • certification and assurance claims
  • privacy and data-governance context
  • regulatory and enforcement records
  • ransomware and threat-context research
  • digital-risk due diligence
  • independent evidence assessment of cyber reports
  • public statements and reputational effects

What you may receive

Concrete professional outputs

  • Cyber Vendor Evidence Review
  • Incident Chronology and Evidence Map
  • Privacy and Regulatory Research Brief
  • Certification-Claim Review
  • Digital-Risk Due-Diligence Memorandum
  • Cyber Report Independent Review

How the work is handled

Human-directed research with controlled verification.

Your assignment is handled by Paul Hattingh and the Aperture research team. Technology may support organisation, comparison and drafting, but evidence assessment, material research choices and final review remain human-directed.

Material claims must be connected to an identifiable evidential basis. Contradictions, source dependence, missing records and limitations remain visible rather than being concealed behind polished language.

Professional boundary

Aperture does not conduct penetration testing, hacking, vulnerability scanning, digital forensics, live incident response or technical certification. Those activities require authorised qualified specialists.

Illustrative assignment

How the service may be applied

A company is considering a cloud-security vendor. Aperture verifies corporate identity, public certifications, incident history, regulatory statements and customer-risk signals, while clearly identifying controls that cannot be verified without technical testing.

Illustrative only. The final scope, sources, output, timing and professional boundaries are agreed separately for each assignment.

Scope and commercial approach

The quote reflects the work required.

Assignments in this area commonly require a standard assessment or enhanced investigation because multiple entities, jurisdictions, documents or high-impact claims may need to be tested. Focused reviews remain available for tightly defined questions.

Before work begins, Aperture defines the questions, intended use, jurisdiction, evidence requirements, output and limitations. The fee is then quoted for the agreed scope and reflects real research labour, evidence control and accountable review.

Client outcome

What this helps you resolve

The sector may change the sources and specialist questions, but the client objective stays practical: reduce uncertainty before a consequential decision is made.

See what is established

Separate verified facts and supported findings from claims, repetition, inference and assumption.

See what could change the answer

Keep contradictions, missing evidence, alternative explanations and specialist dependencies visible before reliance.

Know the responsible next step

Understand what the evidence supports now, what it does not support and whether further work is proportionate.

Bring us the questions.

You do not need to formulate the final scope yourself. Tell us what must be understood or decided, and Paul and Xandro will help organise the assignment before quoting.

Tell Us What You Need to Establish
Start Your EnquiryOpen formSee Our WorkView a complete case