Active Incident? 24/7 Response →

Managed Security & Compliance

Wire Fraud Protection for Real Estate Closings

Managed security, a written information security program, and wire verification for title, escrow and brokerage firms. Run by a digital-forensics practice.

The largest loss in this industry is a priority for one firm in ten

NAR’s 2025 Profile of Real Estate Firms, published 19 November 2025, asked brokers of record what they expect their biggest challenges to be over the next two years. Wire fraud was named by 10%, where it ranks seventeenth of twenty-two. Keeping client data secure was named by 8%. The same survey describes who is answering: 81% of firms operate a single office, the median single-office firm has two full-time licensees, and it closed a median of 12 transaction sides in 2024. NAR reports n=4,672, a 2.2% response rate and a confidence interval of plus or minus 1.42%.

Read that ranking the right way round. It is not evidence that wire fraud is a small problem. It is evidence that it is an unattended one, and the two are opposite findings. A firm closing twelve sides a year meets the risk twelve times, and each time the amount in motion is a multiple of everything else the firm handles that month. The sixteen items ranked above wire fraud are mostly things that cost a firm a percentage. This one is the item that can cost a firm the whole of a client’s proceeds, once, on a Tuesday. Attention has not gone where the size of the loss is, which is the condition an attacker selects for.

The tooling numbers point the same way. NAR’s 2025 Technology Survey, published 18 September 2025, reports that 19% of REALTORS® use cyber security tools such as antivirus or VPN. That is the survey’s own scope, antivirus and VPN, rather than a measure of security tooling in general, and it is quoted narrowly for that reason.

What the loss actually costs you is the client, and it costs you the client even when the money comes back. CertifID’s 2026 State of Wire Fraud Report, published 9 March 2026, a survey of roughly 1,200 consumers and written by a vendor that sells wire protection, found that “56% of consumers said they would not work with a title company or real estate firm again after a wire fraud incident, even if all of their funds were fully recovered.” 68% say a guarantee of protection strongly influences which provider they choose. The same report puts the share who would pay extra for it at 85%, and that figure travels only alongside its own qualifier, that 71% would pay $51 or more.

How often it arrives. ALTA and CertifID surveyed 360 title companies about calendar 2023 and published on 27 February 2025, with CertifID sponsoring the work: more than 40% received at least one wiring-change email a month, 7% wired funds to a fraudulent account, and 13% had a customer do so. Earlier, in an ALTA survey of March 2021 of nearly 550 title agents, attempts touched about a third of transactions. That third is agent perception rather than a counted rate, and the more useful numbers from the same March 2021 survey are that funds actually reached a fraudulent account in “a little over 8%” of attempts, that full recovery followed in 29% of cases, and that 81% of respondents worked at firms of ten or fewer people. That last figure is this reader.

One correction worth making, because getting it wrong is how a firm ends up quoting a number that argues against itself. IC3’s 2025 Internet Crime Report counts its Real Estate category at 12,368 complaints and $275,110,419, and IC3’s own glossary scopes that category to a real estate investment or fraud involving rental or timeshare property. Closing wire fraud is not in it. Closing wire fraud is counted under Business Email Compromise, at $3,046,598,558 across 24,768 complaints, and Appendix C of the same report states that “Each complaint will only have one crime type”, so the two lines cannot be added. IC3 makes the point itself: its 2025 case study describes buyers who wired $449,000 after an attorney-impersonation email at closing, and files it as a BEC incident.

A word on the fine, since that is what most compliance pages sell. There probably is not one. The FTC has obtained no monetary penalty under the Safeguards Rule against a firm in this industry, and its own legal library lists no GLBA enforcement action of any kind since 2020. The honest other half is that a state regulator can, and one did: the New York Department of Financial Services penalised First American Title Insurance $1,000,000 under 23 NYCRR 500 over a breach discovered in 2019. If you are an appointed title agent, the regulator with the shortest route to you is your state insurance department, not the FTC. And the realistic exposure is still none of the above. It is the wire, and the client who does not come back.

Who this page is for

Title agencies, escrow and settlement offices, and real estate brokerages, at the size where one person carries the technology and nobody carries the paperwork. Plans start at $995 per month. Every plan price on this page is stated at the same size: up to 10 named users and 12 protected devices, on a 12 month term, billed monthly.

This is the closing-table version of our managed security and compliance offering for small regulated firms, which carries the same plans and the same evidence discipline for firms outside this industry. If you want the background reading first, we have written on how a real estate closing wire fraud is actually run and on the controls that stop a wire transfer fraud before it starts.

What actually binds you

Two firms sit at the same closing table and do not share a mandate. A settlement agent holding escrow is a financial institution under the Safeguards Rule. A brokerage doing only traditional brokerage work, on the National Association of REALTORS®’ own reading, should not be. So this section answers separately rather than once, because a page that gives you one answer is giving at least one of you the wrong one.

If you handle settlement and escrow

The Safeguards Rule reaches you by activity, not by job title. 16 CFR 314.2(h)(2)(x) gives the reasoning in full: “An entity that provides real estate settlement services is a financial institution because providing real estate settlement services is a financial activity listed in 12 CFR 225.28(b)(2)(viii).” That sits in a list the rule labels examples of financial institutions. The definition itself turns on whether you are significantly engaged in an activity that is financial in nature, so the example is how you recognise yourself, and the activity is what does the binding.

Which regulator holds the other end depends on the line of business. 15 U.S.C. 6805(a)(6) assigns enforcement for a person engaged in providing insurance to the state insurance authority of the relevant state, and it says that authority acts under State insurance law. That qualifier is doing real work and is quoted rather than dropped. A title insurance agency appointed in a state with an insurance data security statute answers to that department first, and the practical consequence is on the next heading.

Size changes what the program contains. It does not remove the program. 16 CFR 314.3(a): “You shall develop, implement, and maintain a comprehensive information security program that is written in one or more readily accessible parts.” The same sentence requires safeguards appropriate to your size and complexity, which is the accommodation a small agency actually gets.

16 CFR 314.6 is one sentence, and below five thousand consumers it removes exactly four provisions. The written risk assessment at 314.4(b)(1). The continuous monitoring, or the annual penetration test and twice-yearly vulnerability assessment, at (d)(2). The written incident response plan at (h). And the annual written report to your board or governing body at (i). Everything else stands. Encryption of customer information in transit and at rest is 16 CFR 314.4(c)(3), which lets you substitute effective alternative compensating controls where encryption is infeasible, reviewed and approved by your Qualified Individual. Multi-factor authentication is 16 CFR 314.4(c)(5), required for any individual accessing any information system unless your Qualified Individual approves reasonably equivalent or more secure access controls in writing. Neither is among the four.

One date worth getting right, because vendors get it wrong in both directions. The Safeguards Rule has bound non-bank financial institutions since May 2003. The 9 June 2023 date belongs to nine enumerated provisions of the 2021 amendments, and it is a compliance date for those provisions rather than the day the rule arrived.

If your state has adopted the NAIC model

Twenty-eight jurisdictions had adopted the NAIC Insurance Data Security Model Law, Model #668, on the NAIC adoption map dated 1 April 2026. What follows is model text, and that distinction matters more here than anywhere else on this page, because the model is law nowhere. Your legislature enacted a version of it, and the versions diverge on the exact number below.

Model #668 § 9.A(1) exempts a licensee with fewer than ten employees, including independent contractors, from Section 4 alone. Section 4 is the information security program. Sections 5 and 6, investigation of a cybersecurity event and notification to the commissioner, apply at any size, so a small agency is released from the written program and still owes the investigation and the notice. § 9.B then gives 180 days to comply once the exception is lost.

Your state’s version of the NAIC model may differ on the employee count, so read your own statute before treating the exemption as settled. Michigan enacted the exception at fewer than 25 employees and independent contractors, and Connecticut ran fewer than 20 until 30 September 2021. A Michigan licensee working from the model number gets the wrong answer about its own obligation.

Two more exemptions run in the same direction and are the ones most often missed. § 9.A(3) exempts an employee, agent, representative or designee of another licensee, to the extent that person is covered by that licensee’s information security program. For a small agency appointed by an underwriter, that is the exemption most likely to apply, and it is worth asking your underwriter in writing whether its program covers you. § 9.A also exempts a licensee compliant with HIPAA that has established a program under it.

What Sections 7, 8 and 10 are, since they are sometimes listed as duties a small licensee still owes: the commissioner’s power to investigate, the confidentiality of documents the commissioner obtains, and penalties. They are not obligations you discharge. Sections 5 and 6 are.

Where the map sits for the four largest closing markets. New York runs 23 NYCRR 500, which Model #668’s own drafting note treats as compliance with the model. California runs 10 CCR §§ 2689.12 to 2689.20. Texas and Florida have neither adopted the model nor legislated an equivalent, which makes them different from the states that considered and declined, and is a reason to read the general breach statute below rather than to assume nothing applies.

If you are a real estate brokerage

NAR’s published position is that a brokerage engaged only in traditional real estate brokerage activities should not be subject to the Safeguards Rule. The hedge is NAR’s and it is kept, because an unhedged version of that sentence is a promise nobody has made to you.

Two provisions support it. 12 CFR 225.126(c) lists real estate brokerage among the activities the Federal Reserve Board determined are not so closely related to banking as to be a proper incident to it. And 12 CFR 225.86(d)(1)(iii)(D) forecloses the theory that a brokerage is a finder, in one line: “A finder may not engage in any activity that would require the company to register or obtain a license as a real estate agent or broker under applicable law.” A licensed broker is therefore the one thing a finder cannot be. Note the scope of that: it closes the finder route specifically. It is not authority for a general exclusion from 16 CFR 314.2(h).

The carve-back is where most brokerages of any size actually land. Run a title, settlement, escrow or mortgage arm and that arm is covered on its own footing. Take compensation for arranging or referring loans, which is a common affiliated-business arrangement, and you are in a different conversation about the same rule. The question is what the entity does, so the answer can differ between two brokerages on the same street.

What does reach a brokerage is the state breach-notification layer, and every state has one. Two examples rather than a national answer, because two statutes cannot give one. Fla. Stat. 501.171(2) requires reasonable measures to protect and secure personal information in electronic form. N.Y. Gen. Bus. Law § 899-bb(2)(a) requires reasonable safeguards and turns on private information, which is a narrower trigger than personal information and is worth reading before you assume your data is outside it.

On what happens if you get it wrong, stated in both directions because both overstatements are common. Florida’s headline penalty tiers at 501.171(9)(b), the ones reaching $500,000, attach to notice failures under subsections (3) and (4), per breach rather than per individual. They do not attach to the security duty. But 501.171(9)(a) does reach it: a violation of this section, which includes the security duty at subsection (2), is treated as an unfair or deceptive trade practice in an action brought by the department under s. 501.207, and (9)(b) opens “in addition to the remedies provided for in paragraph (a)”, which is the text confirming (a) is a live route. 501.207 reaches 501.2075 civil penalties of up to $10,000 per willful violation, and $15,000 where the victim is a senior citizen or a person with a handicap.

Neither statute creates a customer lawsuit of its own, at 501.171(10) and 899-bb(2)(e). New York routes around that, though: 899-bb(2)(d) deems non-compliance a violation of GBL § 349, and § 349(h) carries its own private right of action. So the accurate framing is enforcement by the attorney general under this section, rather than the reassurance that nobody can sue you.

One thing that does not bind you, said plainly because it is sometimes implied. The NAR Code of Ethics contains no occurrence of cybersecurity, data security or information security. Standard of Practice 1-9 concerns revealing and misusing confidential client information, which is a duty about your own conduct rather than a duty to protect that information from a thief.

ALTA Best Practices, Version 4.2, revision stamped 19 August 2025, says of itself that “These practices are voluntary.” Best Practice 3 asks for the written information security program this offering builds, which is why it is the most useful page of the framework for a title agency. ALTA Best Practices are voluntary, and an underwriter that requires them does so through an executed agency agreement rather than through the framework. If your underwriter has one in force, that agreement is the instrument to read, and we will read it with you.

The four plans

What each plan includes, feature by feature.
What you get
Monitor
$995 per month
Up to 10 named users and 12 protected devices
You have IT covered and your compliance paperwork is current.
Managed IT
$1,595 per month
Up to 10 named users and 12 protected devices
You want us to be your IT department, and your paperwork is current.
Monitor + Comply
$1,950 per month
Up to 10 named users and 12 protected devices
Recommended
You have IT covered but need the compliance program built and kept.
Complete
$2,495 per month
Up to 10 named users and 12 protected devices
You want one firm accountable for all of it.
Protection
Backup of every server, laptop and mailboxIncludedIncludedIncludedIncluded
Managed detection and response on every deviceIncludedIncludedIncludedIncluded
Multi-factor authentication across all five access pointsIncludedIncludedIncludedIncluded
Email filtering and security awareness trainingNot includedIncludedNot includedIncluded
Patch management to a stated targetNot includedIncludedNot includedIncluded
Proof
Dated monthly evidence pack for your recordsIncludedIncludedIncludedIncluded
Quarterly restore test, documentedIncludedIncludedIncludedIncluded
Quarterly privileged access and patch compliance reportIncludedIncludedIncludedIncluded
Cyber insurance application support, from recordsIncludedIncludedIncludedIncluded
Day-to-day IT
Helpdesk for your staffNot includedIncludedNot includedIncluded
New starters, leavers and device setupNot includedIncludedNot includedIncluded
Remediation and hardening hours included each monthNot included2 hrsNot included2 hrs
Written information security program
Written incident response program, reviewed annuallyNot includedNot includedIncludedIncluded
Customer notification decision file, including the reasons not to notifyNot includedNot includedIncludedIncluded
Vendor inventory, due diligence and written breach-notice termsNot includedNot includedIncludedIncluded
Annual tabletop exercise with written after-action reportNot includedNot includedIncludedIncluded
Records schedule, and a document pack ready for an underwriter audit or a state examinationNot includedNot includedIncludedIncluded

Getting started: deployment and a first verified restore is a one time $9,500. The written program build is a one time $12,500, required once on the two plans that include it.

Your insurance application, control by control

Must have

One carrier's own bind-condition sheet marks controls of this kind as required before it will bind coverage. These are the ones that stop a deal.

Changes the price

You can get a policy without it, but it costs more, or you get lower limits.

On the form

They ask, and the answer goes on file, but on its own it rarely stops anything.

What a cyber insurance application asks about, and which plan answers it.
What the application asksMonitorManaged ITMonitor + ComplyComplete
Must have
Two-step login (MFA) on emailCoveredCoveredCoveredCovered
Two-step login on any way in from outside the officeCoveredCoveredCoveredCovered
Security software on every laptop and serverCoveredCoveredCoveredCovered
Backups an attacker cannot reach or overwrite, and proven to restoreCoveredCoveredCoveredCovered
Calling to confirm a payment before you send it, and a second person approving large onesA must-have for the part of the policy that covers being tricked into sending money, rather than for the policy as a whole. On a closing desk it is the whole ballgame.CoveredCoveredCoveredCovered
Changes the price
Two-step login on the accounts that can change everything, and on the backup systemCoveredCoveredCoveredCovered
What share of devices are covered, and whether the software cuts an infected one off the network by itselfCoveredCoveredCoveredCovered
Backups kept apart from the day-to-day network, so one break-in cannot take bothCoveredCoveredCoveredCovered
Someone has actually restored a file from backup and written down that it workedCoveredCoveredCoveredCovered
Email screened before it arrives, and attachments opened somewhere safe firstNot coveredCoveredNot coveredCovered
How fast you install urgent security updates, and how often you hit that targetNot coveredCoveredNot coveredCovered
How many accounts can change anything, and why each one needs toCoveredCoveredCoveredCovered
On the form
Software the maker has stopped fixing, still in useCoveredCoveredCoveredCovered
Staff training, and test phishing emails sent to see who clicksNot coveredCoveredNot coveredCovered
A written plan for a break-in, rehearsed once a yearNot coveredNot coveredCoveredCovered
Checking the outside companies that touch your client dataNot coveredNot coveredCoveredCovered

These are questions from real insurance applications. Where a plan does not cover something, we say so here rather than let you find out on the form.

The one control that matters at a closing

Every plan includes a written wire verification procedure. Call-backs go to a number agreed at the time of onboarding rather than to a number supplied in the request, which is the whole of the control, because the number in the request is the thing the attacker changed. Transfers above ten thousand dollars need dual control, approved by someone other than the person who initiated them, on a different device.

We write the procedure, we train your staff on it, and once a year we test that it was followed and file the dated result. We never approve or release a wire ourselves. That stays with your people, because the control only works if the person with the authority is the person doing the checking.

What we do, and how often

Every month

  • Control drift reviewProduces: A triaged, recorded list of what stopped reporting and what was escalated
  • Backup verificationProduces: Confirmation that every server, laptop and mailbox is backed up
  • Evidence packProduces: A dated snapshot of every device and user, filed to your archive

Every quarter

  • Restore testProduces: A written result for a real file set restored from backup
  • Patch compliance reportProduces: Performance against a stated target, with the rolling twelve-month rate
  • Access exception reviewProduces: A record of new devices, bypass codes and administrator accounts
  • Report to the person your firm made responsibleProduces: One page: what changed, what lapsed, what needs a decision

Every year

  • Privileged account reviewProduces: Every administrator account listed with a written reason it still exists
  • End-of-life inventoryProduces: A written statement of what protects anything the maker no longer supports
  • Insurance evidence packProduces: The control sections of your application or renewal, supported by dated records
  • Wire procedure rehearsalProduces: A dated record that the call-back and dual-control steps were tested, not assumed

The written information security program

Included in Monitor + Comply and Complete. This is the part that produces the documents themselves, not just the evidence that controls are running. The incident response program is written with its three parts kept separate and visible: assessment, containment and control, and notification. The notification decision file is a template for the decision, and a filing structure that records the reason you decided not to notify where that was the outcome, which is the part firms skip and the part that is hardest to reconstruct afterwards.

The vendor program is the inventory, the due diligence file, a written breach-notice expectation put to each provider, and a monitoring cadence. Your settlement software, your escrow accounting host and your document portal all sit on that list, and for most firms of this size they are the three that matter.

An annual tabletop exercise and a written after-action report are also included. That one is not required by any instrument we cite on this page, and we say so plainly rather than imply otherwise. It is what turns a written plan into a tested one.

An honest boundary. We prepare these documents for your firm and your counsel to review, revise and adopt. We are not your lawyers and we do not give legal or regulatory advice. Where a judgment call belongs to your firm, we set it up so the decision is easy to make and easy to evidence, and then you make it.

What this means for you

What is included, what is not, and what stays yours

We do

  • Configure, monitor and maintain every product in your plan
  • The monthly, quarterly and annual work in the service calendar above
  • Deliver a dated evidence pack to your archive every month
  • Support one insurance application or renewal each year
  • Escalate anything we find, with a written record
  • On Managed IT and Complete: helpdesk, new starters and leavers, device setup, and two hours of remediation and hardening every month

We do not

  • Helpdesk on the two Monitor plans, which stays with your own IT
  • Incident response and forensics inside the monthly fee, which is billed separately
  • Buying or owning your hardware, software licenses, phones or cabling
  • Legal, regulatory or insurance advice
  • Writing or sending your breach notifications
  • Acting as, or standing in for, the person your firm makes responsible for information security
  • Approving or releasing any wire, which stays with your own staff
  • Work on site or outside business hours, except by arrangement

You do

  • Name a primary and a backup technical contact, and tell us if that changes
  • Respond within four business hours when we escalate something urgent
  • Adopt the policies we prepare, with your counsel
  • Own the accuracy of anything you file with a regulator, an underwriter or an insurer
  • Tell us before you add people, offices, systems or vendors
  • Keep your own IT resource in place on the Monitor plans, or tell us if that ends

Written plainly here so nothing is a surprise in month three. The agreement carries the same boundaries in full.

If a wire goes out anyway

Money is recoverable, and the variable that decides it is how fast the first call is made. In 2025 the FBI’s Recovery Asset Team acted on $1,163,919,846 and froze $679,013,183 of it, in cases where the victim reported immediately. Nothing about that machinery works retrospectively, which is why the wire procedure and the phone number for this practice belong in the same one-page document on your closing desk.

Two numbers to distrust while you are moving, because both are quoted at title agents as deadlines and neither is one. FinCEN puts the 72-hour figure on international wires through its Rapid Response Program, and frames it as when recovery is most likely. There is no FBI 72-hour rule, and no dollar floor below which IC3 declines a report. Report it regardless of the number and regardless of the hour.

Most providers hand you off at the worst possible moment. We do not. The people who protect your firm are the same people who examine the devices and the accounts, write the report, and stand behind it if it is ever challenged.

Hour one to day ten

  1. Hour one, contain and preserve. We take your call and stop the bleeding. We capture evidence to forensic standard from the first minute, with chain of custody intact. Most of what is lost in a breach is lost in the first few hours, by well-meaning people rebooting machines.
  2. Days one to five, examine. Our examiners work the images and the logs. What got in, how, what it touched, what left the building, and whether customer information was actually reached. Those are the questions your notification decision turns on.
  3. By day ten, report. A written forensic report your counsel, your underwriter, your insurer and a state regulator can all read. Written to be defensible, because we write reports that go to court.
  4. Then notify, rebuild, and if needed testify. The report feeds your notification decision and the record behind it. We rebuild the environment. If the matter is litigated, our examiners give evidence.

Who does the work

A digital forensics practice. Quinn holds a degree in cybersecurity from SANS Technology Institute and 9 active GIAC certifications across GIAC, including incident handling, intrusion analysis and mobile forensics. That credential mix is what supports qualification as an expert witness under the Daubert and Frye standards.

Two things we put in writing. Where privilege matters, and in a serious incident it usually does, we take our instructions through your lawyer rather than direct. That is the arrangement that gives the report the best chance of staying protected, and we set it up at onboarding so it is ready rather than improvised at 2am. And you can always get a second opinion: you may bring in an independent examiner at any point, for any reason, and we will hand over the images, the logs and our working papers to help them.

Chain of custody is the unbroken written record of who held a piece of evidence and when, which is what stops the other side arguing it was altered. Privilege means the other side in a lawsuit cannot demand to see a document.

Who we act for

Something you should hear from us rather than find on your own. This practice also runs wire fraud recovery work, and the people who bring us that work are sometimes buyers and sellers whose money went astray at a closing. Some of those matters end up adverse to a title company or a brokerage.

The honest description of how that works is short. We take instructions from whoever retains us. We have acted for parties on both sides of this kind of case, and we expect to keep doing so, because the examination work is the same work whichever chair it is done from. We do not have a published conflicts policy to point you at, so we are not going to imply one. What we can tell you is that conflicts are worth raising on the first call rather than the first invoice, and if you ask us at that call whether we are acting against you, you will get a straight answer.

If your firm has a live incident right now and no relationship with us, the recovery side is the right door and it does not require any of this. Read what happens in the first hours after a wire goes out and call.

The first ninety days

  1. Days 1 to 10, discovery and paperwork. We inventory every device, user, mailbox and vendor. You get our own due diligence pack: our controls, our insurance, our subprocessors, our incident plan. Your own vendor file needs one for every provider that touches customer information, so we hand ours over before you ask.
  2. Days 10 to 30, deployment. Backup, endpoint protection and monitoring on every device. Multi-factor login across all five access points. First backup taken and first restore proven, not assumed.
  3. Days 30 to 60, the program. On the Comply plans: incident response program drafted, notification templates tested, the wire verification procedure written and trained, vendor inventory built. Your counsel reviews. Your firm adopts.
  4. Days 60 to 90, proof and rehearsal. First full evidence pack delivered. First tabletop exercise run, with the written after-action report. If you are placing insurance, we assemble the control evidence for your broker.

What we need from you to start: a named technical contact and a backup, administrative access to your Microsoft or Google tenant, a list of every vendor that touches customer information, your current policies however incomplete, your penetration test report if you have one, and your counsel’s name so the program is prepared under their review.

On the penetration test. If you have had one, the findings are a separate project scoped finding by finding against an agreed cap. We do not fold open-ended remediation into a fixed monthly fee, because that is how a fixed fee stops being fixed.

Rates, growth and the small print

Project and hourly rates

Hourly rates, standard and on a plan.
WorkStandardOn a plan
Remediation beyond the included allowance$400/hr$195/hr
Security consulting, assessment and hardening$400/hr$275/hr
Incident response, containment and rebuild$400/hr$275/hr
Forensic examination and written report$400/hr$325/hr
Deposition and trial testimony, four-hour minimum$400/hr$400/hr Same as the standard rate.
Done-for-you device forensicsfrom $2,000from $2,000 Same as the standard rate.
Refundable engagement retainer$5,000Waived

All rates per hour unless stated. There is no surge for nights, weekends or holidays, on either column. Court time is never discounted, because the hour is the same hour whoever is paying for it.

As your firm grows

Additional named user

$35/mo

Additional workstation

$25/mo

Additional server

$70/mo

New user setup

$150

User departure and offboarding

$100

New device deployment

$200

Term

Twelve months, billed monthly, renewing unless either of us gives 60 days' notice.

Your data

Your tenants are yours. On exit we return your records in a usable format within 30 days and certify what we destroyed.

Our duty to you

We are your service provider, and our agreement says so in writing. We will tell you within 72 hours of becoming aware of a breach affecting a system holding your customer information.

Insurance

We recommend you carry cyber cover and we supply the control evidence to your broker. We are not licensed in insurance and give no insurance advice.

Growth is reviewed quarterly, effective from the date of the change. Devices count by type, because a server costs several times what a laptop does. Where a vendor sells licenses in blocks, that block is invoiced in full when it is bought.

Why this work matters

A ten-person title agency moves more money in a week than most businesses its size see in a year, and it does it on the strength of an email. What an underwriter and a state regulator both want is not a promise but a dated record, and producing that record every month is the whole of this offering.

Plain terms

What we are, and what we are not

What we are

A private investigation agency in the making, with full digital forensics included. SleuthX is not yet a licensed private investigation agency; licensure is in progress. Credentialed examiners, documented chain of custody, explainable findings you can verify, and court-admissible reports under FRE 901/902. Where a matter needs field work today, whether backgrounds, locates or physical surveillance, we coordinate with licensed private investigators. Lawful, confidential, on your side.

What we are not

Spyware, stalkerware, or a way to secretly monitor another person. We do not “hack back,” promise guaranteed money recovery, or touch any account or device without its owner's lawful authorization. We decline engagements that ask us to.

Meet Your Practitioner

Quinnlan Varcoe

Founder & CEO

GIAC-certified · 9 industry certifications

With operational experience across Fortune 50 security programs and the defense industrial base, Quinnlan founded SleuthX in 2022 to provide clients with the caliber of expertise typically reserved for the largest enterprises. Her work in threat intelligence and digital forensics has earned the trust of 26,000+ cybersecurity professionals who follow her analysis.

“26,000 professionals follow my work because I say what others won't — and I can back it up technically.”

Fortune 50 BackgroundDefense IndustryThreat IntelligenceDigital PrivacyIncident Response
Quinnlan Varcoe, Founder & CEO

How We Work

A confidential, structured engagement.

01

Confidential Consultation

A direct conversation with Quinn, the founder and CEO who oversees every engagement. NDA-protected. No sales process.

02

Scoped Engagement

A clear written proposal with defined deliverables, timeline, and pricing. No hidden costs.

03

Investigation and Findings

Forensic work conducted to court-admissible standards, with regular communication and a written summary you can act on.

Certified Expertise

GIAC

Frequently asked about wire fraud protection at a closing

We already have an IT person. Does this replace them?
Not on the Monitor plans. They keep the day to day and we sit above it, watching the controls and producing the record. That is usually the cheapest and least disruptive arrangement. On Managed IT and Complete we do take the day to day, which firms choose when their IT person leaves or when one person is carrying too much.
Can we just buy the software ourselves?
Yes, and the prices are public. The license cost is not the control, though. Running it is. In practice the firms that contain an incident are the ones with a person actually watching what the software reports, and the ones that avoid an email break-in are the ones that had multi-factor login switched on before it mattered.
What if we get breached and you missed it?
Then the record shows it. Every plan produces a dated monthly account of what was running, what drifted and what we escalated. That record protects you in an audit and it also holds us to account. We would rather be measured than trusted.
Do you work with our existing insurance broker?
Yes, and we prefer to. Your broker places the policy and advises you on it. We supply factual, dated evidence of your control environment so their questions are answered from records. We do not take a commission from any carrier and we do not recommend policies.
How quickly can you start?
Discovery within a week of signature. Full deployment inside thirty days for a firm of this size. The written program takes another thirty, because your counsel needs time to review it properly.
Are we going to be fined?
Probably not by the FTC, and we would rather tell you that than sell you fear. The FTC has obtained no monetary penalty under the Safeguards Rule against a firm in this industry, and its own legal library lists no GLBA enforcement action of any kind since 2020. A state insurance regulator is a different matter, and it is the one with the shortest route to an appointed title agent. New York's Department of Financial Services penalised First American Title Insurance $1,000,000 under 23 NYCRR 500 over a breach discovered in 2019. So the realistic exposure is three things in this order: the wire itself, the client who does not come back, and your state insurance department if you are appointed somewhere that has a cybersecurity regulation.
Does the FTC Safeguards Rule apply to our brokerage?
The National Association of REALTORS® publishes the position that a brokerage engaged only in traditional real estate brokerage activities should not be subject to it. We keep NAR's hedge because NAR wrote it that way. Two provisions support the reading: 12 CFR 225.126(c) lists real estate brokerage among activities the Federal Reserve Board found not closely related to banking, and 12 CFR 225.86(d)(1)(iii)(D) says a finder may not engage in any activity that would require a real estate agent or broker license, which closes the theory that a brokerage is a finder. Where it changes is the carve-back. A title, settlement, escrow or mortgage arm is covered on its own footing, and so is taking compensation for arranging or referring loans. The state breach-notification statutes reach you either way.
You help people sue title companies. Why would we hire you?
Because you should know this before you sign, not after. We do wire fraud recovery work, and some of it ends up adverse to a title company or a brokerage. We take instructions from whoever retains us, we have acted for parties on both sides of this kind of case, and we expect to continue. We do not have a published conflicts policy to point you at, so we will not imply that we have one. Raise it on the first call. Ask us directly whether we are acting against you, and you will get a straight answer. The reason firms hire us anyway is the same reason the other side does: the examination work is the same work, and the person who has taken these cases apart from the plaintiff's side knows exactly which record your firm will wish it had kept.
Quinnlan Varcoe, Founder & CEO
Quinnlan Varcoe
GIAC-certified · Founder & CEO

Schedule Your Session

Schedule a confidential consultation

A direct conversation with Quinn, the founder and CEO who oversees every engagement. NDA-protected. No sales process. Most engagements begin within 48 hours.

Free, confidential · NDA-protected · no obligation.

  1. 1. Book a 30-minute call — we scope your situation, no charge.
  2. 2. You get a written scope — deliverables, timeline, and price — before any work begins.
  3. 3. Approve it and we start; most engagements begin within 48 hours.

Transparent pricing

Trusted by partners across the practice

DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management
DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management