ingrid.fyi India's software hiring trends, explained.
Sign in to ingrid.fyi with Google
Your Google account
name@gmail.com
Continue with Google
Home / Product companies / I · Networking, infrastructure and security / Cybersecurity / Threat intelligence and attack surface management
On this page
Threat intelligence and attack surface management Watching the outside world, and the company as an attacker sees it Every Market Segment so far in Industry Vertical 4 has looked inward, at the company's own mail, logins, devices, networks, clouds, code and data. This one looks outward.

Picture a fashion e-commerce company in Bengaluru, the way an attacker sees it from the internet:

  • its domain names and internet addresses
  • servers that anyone on the internet can reach
  • the names of its employees
  • its employees' passwords, leaked in old breaches
  • fake websites pretending to be the company

The company has never made a list of most of this. An attacker spends the first week of an attack making exactly that list.

The company as an attacker sees it: its domain names and internet addresses, servers anyone can reach, the names of its employees, passwords leaked in old breaches, fake websites pretending to be the company, and its mobile apps with the secrets inside them. CloudSEK, RiskProfiler, ZeroFox and Foresiet make this list for the defender.The company as an attacker sees it: its domain names and internet addresses, servers anyone can reach, the names of its employees, passwords leaked in old breaches, fake websites pretending to be the company, and its mobile apps with the secrets inside them. CloudSEK, RiskProfiler, ZeroFox and Foresiet make this list for the defender.

The companies in this Market Segment make the list for the defender instead. They find the forgotten server and the look-alike domain. They watch the criminal forums where a company's stolen passwords are sold. They track the attacker groups, and the techniques those groups are using right now. And they apply the same checks to the company's suppliers, through whom a growing share of breaches now arrive. Their buyers are the security teams of companies like the e-commerce company.

This is a small Market Segment. Companies founded in Bengaluru lead it, and India's own threat-intelligence companies are covered here. The largest global names in this category are not covered in this Market Segment.

Every company named here has posted software engineering jobs in India. Famous companies that don't actively hire software engineers in India are left out.

This Market Segment has two sub-segments:

The company as the attacker sees it: mapping everything the company exposes to the internet, watching the dark web, and protecting the brand. Intelligence about the world beyond: information about attackers, and the risk that comes from suppliers. Looking outward in two directions. The first sub-segment maps the company as the attacker sees it: what is exposed, what has leaked and who pretends to be it (CloudSEK, ZeroFox, RiskProfiler, Foresiet). The second reads the world beyond: the attackers, public sources and the risk that comes through suppliers (Accrete, SecureOS, Ontic).Looking outward in two directions. The first sub-segment maps the company as the attacker sees it: what is exposed, what has leaked and who pretends to be it (CloudSEK, ZeroFox, RiskProfiler, Foresiet). The second reads the world beyond: the attackers, public sources and the risk that comes through suppliers (Accrete, SecureOS, Ontic).

Keep reading, free

Two more sections are on this page: The company as the attacker sees it and Intelligence about the world beyond. Sign in to read them here, in full.

Continue with Google
  • The company as the attacker sees it
  • Intelligence about the world beyond
The company as the attacker sees it External attack-surface management, dark-web monitoring, digital risk protection, brand protection

Back to the e-commerce company from the start of this Market Segment. The companies in this sub-segment map it from the outside. The work has three parts:

External attack-surface management (EASM)finding everything the company exposes to the internet, including what nobody inside has listed. Dark-web monitoringwatching the dark web, the parts of the internet reachable only with special software, where criminals trade stolen data and passwords. Digital risk protection and brand protectionfinding fake websites, look-alike domains and fake social media accounts that pretend to be the company, and getting them taken down. CloudSEKa Bengaluru company, splits the job into two products. XVigil watches the dark web, code repositories and social platforms for a company's leaked data, leaked passwords and fake accounts. BeVigil finds the company's exposed assets that nobody inside had listed. These include its mobile apps, and the secrets built into them, like passwords and API keys left in the app's code. RiskProfilerfrom South Carolina with engineers in Delhi NCR, sells the same set as a bundle: the external attack surface, dark-web intelligence, brand monitoring and a risk score. It adds vendor-risk management, which reaches into the next sub-segment. ZeroFoxthe American digital-risk-protection company, has engineers in Bengaluru. Its product is the take-down as much as the detection. Once it finds a fake account or a phishing site, it gets it removed. Foresietis a young Bengaluru company. Its product, Foresiet Xtreme, covers digital risk protection and the attack surface.

This sub-segment is where two things from earlier Market Segments get found first:

  • The fake login page from Market Segment 4.1, Email security and anti-phishing, is found before the phishing email arrives.
  • The forgotten server from Market Segment 4.11, Vulnerability management and penetration testing, is found by someone other than the attacker.
Intelligence about the world beyond Threat intelligence, open-source intelligence, third-party and supply-chain risk

Back to the e-commerce company from the start of this Market Segment. The first sub-segment read the company itself. This one reads the world around it:

Threat intelligenceinformation about attacker groups, their tools and their targets. Open-source intelligenceinformation gathered from public sources, such as news and social media. Here, open source means public information, not open-source software. Third-party and supply-chain riskthe risk that an attack arrives through a supplier, such as the company's delivery partner or payment provider. Accretefrom New York with engineers in Mumbai, builds a product called Argus. It draws threat intelligence from public sources, and tracks the stories and threats spreading on social platforms. It also scores the risk in a supply chain. Alongside it, Accrete sells a compliance product that checks whether a supplier is owned or controlled from abroad. It is this Market Segment's example of intelligence sold as a product in its own right, rather than as a feature of a monitoring service. (More on it in Market Segment 30.4, Shipment tracking and supply chain visibility platforms, in Industry Vertical 30, Supply chain and logistics.)

One company covered mainly in another Market Segment carries the supplier half:

SecureOSis a young company that sells vendor-risk management: the questionnaires and evidence a company uses to assess its suppliers. It is here because that assessment now often uses the outside-in scans this Market Segment produces. (More on it in Market Segment 4.14, Governance, risk and compliance (GRC).)

Safe Security's supplier score answers the same supplier question with a number. (More on it in Market Segment 4.11, Vulnerability management and penetration testing.)

One company here watches for a different kind of threat instead:

Onticbuilds protective intelligence for companies' security teams: watching for threats against executives, offices and events. It has teams in Pune and Delhi. It is a reminder that watching the outside world is older than the internet. (More on it in Market Segment 4.15, Physical security, surveillance and trust and safety.) The supplier as the way in.

More and more breaches now arrive through a supplier, a software library the company depends on, or a contractor. That has made supplier risk the fastest-growing question in this Market Segment. The products here are moving towards the same answer. Scan the supplier from the outside, the way you scan yourself, and stop trusting the questionnaire the supplier filled in.

So the e-commerce company from the start of this Market Segment can see itself the way an attacker does. It can also watch the attackers, and the suppliers an attack might come through.
Who they hire

Who these companies hire, and for what, is on What cybersecurity hires for.

Privacy Terms Refunds and cancellation Shipping and delivery © 2026 ingrid.fyi · Payments by Razorpay
You're browsing as a guest. Sign in free to follow links for five minutes, once an hour.