Skip to main content
Whitepapers & Guides
White Paper

Who's Watching Your Watchmen?

In 2026, three incident-response professionals were sentenced for running BlackCat ransomware on the side - one negotiated ransoms while quietly feeding his own clients' insurance limits to the attackers, costing them $75.3 million. This white paper shows how trust in a security provider fails, and hands you a six-domain framework to vet any MSSP, MDR, or IR firm - including us.

Download the White Paper
Who's Watching Your Watchmen? white paper cover
White Paper

$75.3M

lost by the clients of a single rogue ransomware negotiator

In 2026, federal courts sentenced three cybersecurity professionals for a crime the industry is still processing: while employed at respected incident response firms, they were running BlackCat ransomware attacks of their own. One negotiated ransoms for five victims while secretly feeding their insurance limits and negotiation strategy to the criminals on the other side of the table. His clients lost a combined $75.3 million.

That same month, investigative reporting exposed an offensive-security startup soliciting million-dollar exploit business while run by principals with documented fraud convictions and a history of operating companies under assumed names. Two very different failures, one lesson: a polished security vendor can be exactly the wrong thing to trust.

Your MSSP, MDR provider, or incident response firm holds more privileged access to your business than any other vendor - your endpoints, your credentials, your defensive gaps, and, in a crisis, exactly how much you can afford to pay an extortionist. So how do you know your security partner deserves that trust? This white paper gives you the answer the FBI called for: real due diligence, not a feeling.

What's inside

  • The two ways trust in a security provider fails: the insider who turns, and the vendor who was never legitimate to begin with
  • A full breakdown of the BlackCat negotiator prosecutions and what the court record reveals about unchecked provider access
  • Why references, certifications, and big brand names would not have caught any of it
  • A six-domain due diligence framework you can run on any security provider, including us
  • A one-page vendor vetting checklist your team can use before the next contract signature
Preview of the security provider due diligence checklist
Who it's for: CISOs, IT and security leaders, procurement and vendor-risk teams, and any executive responsible for choosing or renewing an MSSP, MDR, or incident response provider.

SOClogix publishes this framework because we believe clients who ask harder questions make the whole industry better. Run every check in this paper on us. We invite it.

Download the White Paper

PDF - free access

Free instant access - enter your details to download

No spam. We respect your privacy.

Put the Guides Into Practice

Our whitepapers give you the framework. Our team gives you the implementation. Schedule a consultation to discuss your specific environment.