CASE FILES OPENVOL.07 / Q4 · 2026

What you can’t seeis what matters.

Threat intelligence written for boards. Methodology peer-reviewed. Sources cited.

02 / THE PRACTICE
SCRYER · FOUNDING PRINCIPLE · 2019

The Practice

SCRYER is a research firm. Not a vendor, not a SOC, not a platform.1 We produce written analysis for boards and general counsel.

Our subscribers are CISOs at Fortune 100 firms, federal department heads, and the audit committees of three of the largest sovereign wealth funds.2

Every briefing is peer-reviewed before it leaves the building. Every claim is sourced. We will not publish what we cannot defend in a deposition.

If your security posture depends on what you can see, we exist to widen the field of view.3

1 SCRYER does not sell software, manage SOC operations, or provide technology products of any kind.

2 Client identities are never disclosed. Sector and type disclosed by consent only.

3 From the SCRYER client engagement principles, revision 7, 2025.

02 / CAPABILITIES

What We Do

Threat Intelligence

Standing intelligence on the adversaries that matter to your industry. Quarterly written deliverables, monthly update calls, on-demand analyst access.

CITED · DEFENSE NEWS · Q3 2026

Strategic Advisory

Long-form board memos and audit-committee briefings. Translation of technical exposure into governance, regulatory, and capital-allocation language.

CITED · FOREIGN AFFAIRS · Q2 2026

Adversary Profiling

Custom dossiers on operators of interest. Tradecraft history, OPSEC discipline, predicted next moves, attribution confidence.

CITED · WIRED · Q1 2026

Geopolitical Risk

Sector and region briefings tying cyber operations to statecraft, sanctions, and supply-chain pressure. Where the geopolitics intersects the keyboard.

CITED · THE ECONOMIST · Q4 2025

Incident Forensics

Independent technical investigation under privilege. Evidence preserved to forensic standard. Findings publishable in regulatory or litigation contexts.

CITED · LAWFARE · Q3 2025
03 / METHODOLOGY

Tradecraft

Six principles govern every engagement at SCRYER. These are not guidelines. They are the conditions under which our analysts are permitted to publish.

Source requirement
Operational security
Analytical standard

6 PRINCIPLES · ALL MANDATORY

Source Triangulation

No claim survives this firm on a single source. Every assertion is corroborated across at least three independent streams: technical telemetry, primary documents, and human-source verification.

SCRYER METHODOLOGY CHARTER · SECTION 2.1

Peer Review

Every briefing is read by two analysts not on the engagement before it leaves the firm. Disagreement is documented, not flattened. We sign what we publish.

SCRYER METHODOLOGY CHARTER · SECTION 3.4

Adversary Modeling

We do not chase indicators. We model operators: their training, their constraints, their tempo, their politics. Indicators are downstream of intent.

SCRYER METHODOLOGY CHARTER · SECTION 4.2

Counter-Intelligence Hygiene

Operations security applies to us, too. Source identities are compartmented, draft documents are watermarked, and our research infrastructure is treated as a target.

SCRYER METHODOLOGY CHARTER · SECTION 5.1

Long-Horizon Tracking

Adversaries operate in years. Our threat profiles run on multi-year timelines, with continuity across analyst tenure. We refuse the seduction of the latest IOC.

SCRYER METHODOLOGY CHARTER · SECTION 6.3

Assumption Stress-Testing

Every assessment includes a red-team review of its own premises. Where we are guessing, we say so. Confidence levels are explicit, not performative.

SCRYER METHODOLOGY CHARTER · SECTION 7.1
04 / RECENT BRIEFINGS

From the Archive

SUBSCRIBER
BRIEFING 0341-A

Adversary Attribution: APT-LANTERN Targeting US Defense Contractor

North America · EurasiaDefense / AerospaceQ3 2026

Multi-stage credential harvesting campaign targeting senior engineering staff at a tier-one US defense contractor. Operation infrastructure overlaps with previously documented APT-LANTERN tradecraft. Attribution carries 87% confidence.

87%Confidence
412Targets
94 daysDwell time
11 mappedTTPs
Read briefing
BRIEFING 0298-CSUBSCRIBER

Energy Sector Supply Chain: Software Implant Pre-Positioning

Discovery of stage-zero implants pre-positioned in third-party software widely deployed across European energy operators.

Western EuropeQ2 2026
BRIEFING 0276-APUBLIC

Financial Services: Insider-Enabled Data Exfiltration Pattern

Recurring exfiltration pattern across three regional banks suggesting recruited or coerced insider access.

Asia-PacificQ1 2026
BRIEFING 0211-BPUBLIC

Political Influence Campaign: Synthetic Media Amplification

Coordinated synthetic-media campaign timed to a national electoral cycle. Source attribution and platform amplification mechanics documented.

South AmericaQ4 2025
BRIEFING ARCHIVE · VOL. 07 · 2019 PRESENTView all briefings

Cited In  ·  Quoted In  ·  Testified Before

06 / SUBSCRIPTIONS

Intelligence Tiers

Watchpoint

For boards beginning to ask the right questions.

$24,000/year
  • Quarterly written executive briefings
  • Threat advisory feed (weekly summary, monthly long-form)
  • One advisory call per quarter with the lead analyst
  • Custom alerts for your sector or region
  • Subscriber-only briefing archive access
Subscribe
RECOMMENDED

Vantage

For boards that already know enough to be worried.

$72,000/year
  • Monthly written executive briefings (12 / year)
  • Threat advisory feed (daily summary, weekly long-form)
  • Dedicated lead analyst, on-demand
  • Two custom adversary profile dossiers per year
  • Quarterly board-presentation deck (your branding)
  • Direct line to the Director of Threat Intelligence
Subscribe

Forensic

For when something has already happened.

Custom
  • Independent technical investigation under privilege
  • Forensic-grade evidence preservation
  • Findings publishable in regulatory or litigation
  • Senior partner engagement throughout
  • 72-hour response window from initial call
  • Congressional testimony support if required
Inquire

All tiers include a complimentary 30-minute scoping call with a senior analyst before commitment. Pricing reflects annual retainer. Discounts available for multi-year and multi-seat arrangements.

07 / INQUIRY

Request a private briefing.

We respond within one business day. All communication is encrypted and discretion is default.

SCRYER Intelligence Group
Washington D.C. · London · Singapore
All inquiries handled by a senior analyst

Encrypted · Confidential · No unsolicited follow-up