Security that fits how media businesses actually work
Freelancers on their own laptops, a long tail of production SaaS bought on a card, a large public footprint, and pre-release content that is worth money to somebody. Standard corporate security advice does not survive contact with any of it.
The shape of the problem
- Workforce churn is the model. Freelancers and production companies arrive for a project and leave. Access granted in week one is often still live a year later.
- Shadow SaaS is not a policy failure. A production team buying a review tool at 11pm is doing their job. The tool still ends up holding your content.
- Your attack surface is public by design. Campaign microsites, event domains and partner subdomains accumulate, and old ones rarely get retired.
- Content leaks have a market. Pre-release material is a target in a way that most corporate data is not.
- Rights and privacy obligations follow the content, including contributor data that is often personal and sometimes sensitive.
The one that surprises people. Certificate transparency logs make every subdomain you have ever issued a certificate for permanently public. Campaign sites from three years ago, staging environments, and the microsite an agency built and forgot. Attackers read those logs. Most media businesses have never looked.
What we do
- Find the estate
- Attack surface mapping from public sources: every subdomain, every exposed service, every forgotten campaign site.
- Offboarding that actually completes
- A leaver process built for freelancers and production companies, not just permanent staff, with evidence that access was removed.
- Bring shadow SaaS into view
- Discover what is in use and triage by what data it touches, rather than banning tools people need.
- Assess the partners who hold your content
- Post houses, VFX vendors, review platforms and distribution partners, checked continuously rather than at contract.
- Practise the incident
- A leak response that names who decides, who speaks and who calls the lawyer, rehearsed before it is needed.
Start with what is already public
The free vendor check works on your own domain too. It is a reasonable five minutes before deciding whether any of this is a priority.
Know how many subdomains you have?
Almost nobody does. It is usually the fastest way to see the shape of the problem.
Book a call