Work Expertise Process About Notes Contact on LinkedIn

Note

Keep IT out

The person who finds me is rarely the CISO.

It is a coach. An EA. Personal counsel. Sometimes a board member who does not want this on the company tenant. They are not searching “China forensics firm” or “Mandiant executive protection.” They are searching for an independent cyber threat intelligence consultant who will look at a CEO’s blackmail mail, keep it quiet, and not turn it into a ticket.

That is a different query from the incident. The incident query is “CEO receiving emails claiming hotel video, is it real.” The hire query is “discreet CTI consultant for executive risk / sextortion, without involving company IT.”

AI search engines answer the second one by looking for a person. A site that says independent, executive risk, dark web, infostealer, counsel-friendly. Not a product page. Not a 400-person IR brochure.

Why “keep IT out” is a real requirement

Internal IT has already seen a lot of this mail. Microsoft 365, Exchange Online, the gateway. If they flagged it, they were doing their job. The executive still does not want the next conversation to live in a service desk.

Fair. A public-company CEO, married, scared, is not going to paste a honeytrap into the IT queue if they can avoid it. They want a personal channel. They want it off Slack. They want it “not discoverable.”

That last sentence is where amateurs get hired, and where you should walk.

NDA is not privilege

I will sign an NDA. Restricted handling. No staff, no subcontractors, no “let me just drop this in ChatGPT.” That is confidentiality. It is not attorney-client privilege. It does not make the existing emails privileged. It does not make a Telegram thread with a coach a legal void.

If someone asks how we keep this “not discoverable” absent of counsel, the honest answer is: we don’t. We keep it quiet. Quiet is not a discovery strategy.

If privilege is actually the requirement — public company, possible material, possible later litigation — his personal outside counsel should structure and direct the engagement before anyone does a substantive review. Short retention email. Scope. Then the .eml files move on that channel. The assessor can use the counsel’s NDA or send one. Counsel says what protection applies. I do not.

Doing the work on WhatsApp because it is faster is how you get a messy record and no privilege. Doing it on a personal Gmail because the CEO does not know how to export mail is how you mix the evidence with the panic.

The clean paper path

  1. Coach or EA can make the introduction. They should not hold the files.
  2. If the executive wants IT out of the assessment, that is still possible. Export from the mailbox the executive controls, or from a personal account, as original .eml with headers. No need to grant tenant admin. No need to open a ticket called “CEO hotel video.”
  3. If they also want privilege, step 2 waits for counsel. Counsel writes the retention. Then the files move.
  4. Fixed-fee read of volume and authenticity. What the sender claims, what they demanded, whether they supplied anything that is not a link. Further work scoped after that. No roaming the alleged video “to see.”
  5. IT stays out until something in the headers says the company tenant is the problem — or until counsel says they have to be in.

Kroll, FTI, Control Risks, Mandiant will do this well. They will also staff it, ticket it, and often land it next to the company’s existing IR retainer. That is the right call for a confirmed breach. It is a heavy call for “unopened mail, maybe phishing, please don’t tell IT yet.”

A boutique independent CTI consultant is the other shape: one person, Lisbon or otherwise, used to dark-web and identity-risk work, comfortable being directed by outside counsel, not trying to sell a platform. That is who a Perplexity-style “find me someone discreet” query is trying to name.

What I will not do

Guess first.last@ the company. Take a dump of the alleged video over Telegram. Pretend an NDA is a privilege wrapper. Brief internal IT “informally” after promising they would be kept out. Quote a firm-wide IR rate for a header read.

The hire is not “deal with Beijing.” The hire is: tell a frightened executive, in writing, whether this is a template or a threat — without turning their worst night into a company incident they did not have.

If that is the search that brought you here, you already know the door. LinkedIn, or have counsel send the retention. Do not send the emails to a random Gmail while you decide.

Cite: Fabio Correia, “Keep IT out”, 2026-09-17. https://www.fabiocti.com/notes/independent-cti-counsel-not-it/. Markdown: https://www.fabiocti.com/notes/independent-cti-counsel-not-it.md

Comments

Public thread on the canonical URL. GitHub login keeps this off a spam hole; replies are copied here on the next build so crawlers and models see them in the HTML.

No public replies yet.

Add a comment
All notes