A Fortify 24x7 brand. Managed device, account, and data defense for crypto-native operators.Client sign inSupport
CRYPTOSHIELD/NETWORKS
Home / Threat model
Reference · no product on this page

The chain, link by link.

Written for people who already know this material and want to see whether we do. Every stage below has a control that addresses it, a control that does not, and a plain note where the honest answer is that nothing we sell helps.

Six stagesMapped to linesBoundaries stated
01Chain

Six stages, in the order they happen.

Reconnaissance. Your team is discoverable. Conference talks, repository commits, governance forum posts, and a fund's own website supply names, roles, and addresses. Breach corpora supply the rest. Nothing here is an attack yet; it is targeting.

Delivery. A file or a link reaches somebody who can authorize something. Thread hijack from a compromised counterparty, a recruiter's take home task, a trojanized desktop client, a search advertisement above the genuine download.

Execution. The payload runs. This is the single most defensible moment in the entire chain and it is where most spending should go.

Collection. Browser profiles, cookies, extension storage, keystore files, clipboard contents, and anything recovery shaped in a downloads folder. Live session cookies are the prize, because they are the second factor already spent.

Authorization. A transaction gets signed, or an exchange withdrawal gets approved, either by the operator through a stolen session or by your own person who was shown something convincing.

Settlement. Irreversible. This stage has no defenders. Everything upstream exists because this stage cannot be argued with.

02Matrix

Which line addresses which stage.

ReconnaissanceMonthly exposure checking under inbox defense tells you which addresses are publicly discoverable and appearing in breach data. Reduces targeting quality. Does not prevent it.
DeliveryMail filtering, impersonation detection, attachment detonation, click time link checks, and web filtering under device management. Newly registered lookalike domains fail to resolve.
ExecutionDefault deny allowlisting plus behavioral detection under managed detection. The strongest link in the chain, and the cheapest one to strengthen.
CollectionEndpoint detection on process behavior, plus data discovery to reduce what is lying around to be collected in the first place.
AuthorizationPartially addressed. Training and filtering reduce the odds a person is deceived; detection may catch the collection that preceded it. The real control here is hardware wallets that display what is being signed, and internal policy on who may authorize what. Neither is something we sell.
SettlementNothing. There is no control at this stage from us or anybody else. Backup and recovery addresses the aftermath for your systems and records, not for the transfer.
03Gaps

Where nothing we sell helps.

  • Carrier port out. Number portability fraud happens at the mobile operator. Mobile threat defense protects the handset and cannot touch this. Hardware security keys and a carrier account lock are the answer, and they cost nothing from us.
  • Social platform direct messages. A mail gateway does not see chat networks. Web filtering and execution control catch what those messages try to deliver, but the message itself arrives unfiltered.
  • Governance and multisig process failures. A quorum that approves something it did not read is a policy problem. We will happily review your process during onboarding, but there is no line item for it.
  • Insider action by an authorized person. Data discovery and channel control raise the cost and improve the record. Neither prevents somebody with legitimate authority from using it.
  • Anything that has already settled. Covered plainly below.
04Boundaries

What we do not do, and will not be talked into.

  • We do not recover stolen or misdirected funds, and we do not refer you to anyone who claims they can. Recovery services are the second half of the fraud more often than not.
  • We do not perform on-chain forensics, transaction tracing, address clustering, or attribution. That is a different discipline with different tooling and different obligations.
  • We do not take custody of assets, private keys, seed phrases, or signing hardware at any point, including during incident response.
  • We do not provide investment, trading, tax, or financial advice. Nothing anywhere on this site constitutes any, and nobody on our desk is licensed to give it.
  • We do not accept payment in cryptocurrency. Subscriptions are billed by card through Stripe and the statement reads FORTIFY 24X7.
  • We do not endorse, certify, audit, or integrate with any specific chain, protocol, exchange, custodian, or token, and we decline requests to be cited as if we do.
05Sequence

If you are buying in order.

This is operational advice about control coverage. It is not advice about your capital, your positions, or your treasury policy, and it should not be read as any.

  • First, the signing hosts. Execution control plus a detection tier on the small number of machines that touch treasury tooling. This is where the ratio of risk removed to money spent is at its best.
  • Second, the inbox. Filtering with training on every mailbox that can authorize something or that corresponds with counterparties.
  • Third, the inventory. Management and web filtering across the fleet, so you know what exists and the browser path is covered.
  • Fourth, the handsets. Mobile threat defense on any phone holding an authenticator or an exchange application, paired with hardware keys you buy yourself.
  • Fifth, the directory and the records. Entra ID configuration protection and mail or file backup, so an account takeover is an afternoon rather than a week.
  • Then discovery. Once the perimeter of your estate is real, find what has been accumulating on it and clean it up.

One more time, because it is the important part

CryptoShield Networks sells managed device, account, and data protection. That is the whole catalog. If a page anywhere on this site reads as though we can retrieve something that has already moved, that page is wrong and we would like to know about it.