Investigative & Advisory Services
Delivered

nDiligence delivers investigative and security services under one practice. Investigative work supports complex, high-risk, and cross-border matters for counsel, boards, investors, and risk owners. Security and intelligence work covers advisory, assessment, authorized testing, and incident response. Most matters need both, and we staff them as one team. Bring us the question you need answered and we will scope the work around it.
Request a Briefing
Two Practices

One Firm, Two Practices

Engagements draw on either practice, or both, depending on what the matter requires.
Intelligence Services
Support for complex, high-risk, and cross-border matters, for counsel, boards, investors, and risk owners.
  • Entity, individual, and network investigation
  • Beneficial ownership and financial flow analysis
  • Supply chain, procurement, and third-party risk
  • Adversarial influence and threat actor profiling
  • Background, vetting, and insider threat analysis
  • Reach back to subject matter expert networks
Security Services
Advisory, assessment, authorized testing, and incident work across enterprise and infrastructure environments.
  • Security consulting and advisory
  • Security program and policy assessment
  • Technical due diligence
  • Breach investigation and digital forensics
  • Penetration testing and active security testing
  • Security system evaluation and hardening
Core Services

Diligence and Investigative Work

Every service is designed to cut through complexity and reveal what others miss.
Enhanced Diligence
Pre-transaction and ongoing diligence on companies, executives, investors, and acquisition targets: beneficial ownership, financial integrity, and patterns of influence. Worked through Equity Chain Mapping, a recursive approach to resolving ownership and control across an opaque network.
Third-Party Risk & Vetting
Onboarding and continuous vetting of employees, suppliers, partners, and capital sources: KYx, compliance, and AML/CTF analysis across the long tail of relationships.
Supply Chain Integrity
End-to-end visibility into multi-tier supplier networks across all five classes of exposure, with continuous monitoring for changes in ownership, jurisdiction, and influence.
Intellectual Property Defense
Protection of trade secrets against IP exfiltration vectors: foreign capital exposure, opaque licensing chains, open-source compromise, insider risk, and adversarial M&A.
Corporate Espionage Defense
Counterintelligence-grade detection of insider threat, placement and access operations, hidden affiliations, embedded providers, and proxy investors.
eDiscovery & Litigation Support
Electronic discovery, digital forensics, and investigative research with chain-of-custody discipline and attribution that meets evidentiary standards.
Threat & Competitive Intelligence
Threat intelligence and investigative engagements: deep research, competitive intelligence, tracking, and asset discovery.
Geopolitical Risk Advisory
Strategic advisory on jurisdictional exposure, sanctions and export-control posture, and cross-border dynamics, translated into decision-ready guidance.
Security Engagements

Security and Intelligence Work

Assessment, testing, and incident work, scoped and authorized in writing before anything begins.
Security Consulting & Advisory
Advice to counsel and client leadership on security matters, including review of existing policies, procedures, environments, and operating practices. Frequently used to define and scope subsequent work.
Security Program & Policy Assessment
Assessment of governance, policy, standards, procedure, and control coverage against a defined framework, with maturity observations and prioritized recommendations for the program as a whole.
Technical Due Diligence
Diligence on a target or counterparty technology environment: security posture, engineering practice, licensing, technical debt, hosting and infrastructure dependency, and disclosed or undisclosed security history.
Digital Supply Chain & Third-Party Risk
Mapping and analysis of software, hardware, service, and data dependency across multiple tiers, including vendor and sub-processor chains, technology provenance, infrastructure ownership, and jurisdictional exposure.
Breach & Incident Investigation
Investigation of suspected or confirmed security incidents: scoping, evidence preservation, forensic analysis, reconstruction of attacker activity, and impact and exposure assessment in support of counsel.
Digital Forensics & Evidence Handling
Forensically sound acquisition, preservation, and examination of endpoints, servers, cloud tenants, mobile devices, and log sources under documented chain of custody, prepared for use by counsel.
Penetration Testing & Active Testing
Authorized testing of network, application, wireless, cloud, and identity systems, including external and internal testing, assumed-breach and red team exercises, and social engineering where expressly scoped.
Security System Evaluation & Hardening
Evaluation of deployed security systems, tooling, and configuration against intended function and current threat conditions, with hardening and architecture recommendations and validation of remediation.
Physical & Electronic Security
Assessment of facilities, perimeters, access control, surveillance, alarm and monitoring systems, credential management, and site operating practice, including on-site walkthrough where authorized.
Insider Threat & Personnel Risk
Analysis of insider risk exposure, including access and entitlement review, behavioral and network indicators, departing employee and contractor risk, and investigation of specific reported conduct.
Investigative & Intelligence Services
Entity, individual, and network investigation, beneficial ownership and financial flow analysis, adversarial actor profiling, and structured intelligence assessment supporting legal and transactional decisions.
Litigation Support & Testimony
Support to counsel in litigation, arbitration, and regulatory proceedings, including declarations, expert reports, exhibit preparation, deposition and trial testimony, and rebuttal analysis.
Expertise

Areas of Expertise

Every engagement is staffed from these domains, in whatever combination the matter requires.
Adversarial Influence & Information Operations
Foreign influence campaigns, proxy networks, disinformation infrastructure, and coordinated state-aligned activity within commercial environments.
AML & Financial Compliance
Anti-money laundering analysis, sanctions exposure, financial flow tracing, and illicit finance in supply chain and ownership structures.
Cryptocurrency & Digital Assets
Blockchain forensics, digital asset tracing, and decentralized infrastructure in adversarial financing and illicit capital movement.
Capital Markets & Investment Structures
Beneficial ownership, investment flow tracing, opaque capital structures, and equity chain mapping across entities, trusts, and funds.
Supply Chain & Procurement
Multi-tier supplier networks, procurement risk, counterfeiting, diversion, and physical supply chain dependency and chokepoint analysis.
Cyber & Digital Infrastructure
Technology provenance, infrastructure ownership, hosting and ISP relationships, netflow, and software dependency exposure.
Geopolitical & Regional Analysis
Adversarial actor behavior, regulatory environment, jurisdictional risk, and geopolitical dynamics for a defined region or country set.
Insider Threat & Human Networks
Individuals, relationships, and human networks used as access vectors, including employees, advisors, consultants, and board members.
Cloud & Enterprise Infrastructure
Cloud tenant, identity, endpoint, and network architecture, including entitlement, configuration, and segmentation analysis.
Digital Forensics & Incident Response
Forensic acquisition and examination, intrusion reconstruction, log and telemetry analysis, and evidence handling for use by counsel.
Offensive Security & Red Team
Authorized adversary simulation, exploitation, and social engineering, and the design of rules of engagement and safe testing boundaries.
Artificial Intelligence & Data Systems
AI and machine learning systems, data pipelines, model and training data exposure, and governance of AI-enabled tooling.
Industries

Industries Served

Technology Providers
Creators of software, hardware, technical services, and hosting infrastructure.
Critical Infrastructure
Energy, water, transportation, communications, IT, healthcare, and finance.
International Defense
Primes, sub-tier suppliers, dual-use technology, and allied programs.
Financial & Investors
Institutions and investors seeking visibility into ownership and influence.
Insurance
Underwriters, specialty and cyber carriers, and reinsurance partners.
Legal Services
Law firms, in-house counsel, and litigation teams requiring defensible intelligence.
Engagement

How We Engage

Baseline Assessment
Establish ground truth across the enterprise and every dependency it stands on.
Persistent Monitoring
Verify trust continuously, with alerts on changes in ownership, control, or influence.
Investigations & Advisory
Analyst-led support for complex, high-risk, and time-sensitive matters.
Recommendations & Policy
Findings turned into prioritized recommendations, and into the policies, procedures, and operating practices.
Assess trust. Verify continuously.
A baseline assessment establishes ground truth; persistent monitoring verifies it remains true every day. If your work demands clarity and confidence, let’s start the conversation today.