A password has a surprisingly active social life. Before it opens a company account, it may be copied, bundled, advertised and sold. The company’s security team sees the login. Somewhere else, someone has already seen the listing. ReliaQuest Threat Research concerns itself with the awkward distance between those two observations.
- ReliaQuest bought Digital Shadows for $160 million in 2022, adding external intelligence to its security operations business.
- Its research team studies criminal forums, hunts threats and analyzes incidents. GreyMatter helps customers turn findings into action.
- The buyer is an enterprise security team with several tools to coordinate. Public research is available to everyone.
- The practical lesson: give every important finding an owner and a response. A dashboard cannot make that decision for you.
The name needs a little unpacking. ReliaQuest Threat Research is the research function of ReliaQuest, whose platform is called GreyMatter. Digital Shadows, the business behind the older social accounts and SearchLight name, became part of ReliaQuest in 2022. The company story therefore has two beginnings and one increasingly shared workflow. Treating all three names as interchangeable would make a handsome spreadsheet and a terrible explanation.
A $160 million change of perspective
ReliaQuest founder Brian Murphy started his company in 2007. In his account of the early years, he and his wife used credit card debt and a second mortgage to keep it going. A Florida Funders interview describes a Department of Defense contract helping the business pivot from IT into cybersecurity. The origin has less to do with a sudden flash of genius than with finding work a customer needed badly enough to pay for.

Digital Shadows had its own beginning in 2011, with Alastair Paterson and James Chappell. Its territory was the material enterprises left outside their walls: exposed data, stolen credentials, fraudulent brands and the places criminals discussed them. SearchLight made those scattered traces legible to security teams.
In June 2022, ReliaQuest announced a $160 million agreement to buy the business. The closing followed that summer. ReliaQuest described the combination in geographical terms: its existing network, cloud and endpoint detection supplied an inside view; Digital Shadows supplied the outside view. The purchase addressed a practical weakness. An organization could monitor its infrastructure while missing preparations for an attack beyond its perimeter.
By November, ReliaQuest had launched GreyMatter Digital Risk Protection. In June 2025, DRP functions including alert triage, asset management, risk search and managed takedowns were brought directly into the GreyMatter interface. Those dates matter. Buying intelligence and making it convenient to use are separate pieces of work.
Criminal forums
Exposed credentials
Impersonation
Identity activity
Endpoint signals
Cloud events
Contain an account · block an indicator · request a takedown
Conceptual workflow; actions depend on connected tools, permissions and the customer’s configuration.
The analyst who reads the room
Threat research is an unusual company occupation. Part of the work involves watching people who would rather not be watched. ReliaQuest’s public research hub describes monitoring dark-web forums, performing customer threat hunts and analyzing wider cybersecurity trends. The output includes reports, blog posts and profiles of threat actors. ShadowTalk, its weekly podcast, translates some of that work into a conversation a practitioner can listen to between other duties.
The inherited Photon research operation brought more than ten years of data and analyst expertise in over 20 languages, according to the 2022 integration account. Language is an operational detail here. A criminal advertisement is a claim made in a particular community, with its own manners and incentives. Reading the words is the start; judging what they mean is the work.
ReliaQuest’s June 2026 featured AI research is instructively unromantic. It describes AI helping attackers carry out familiar sequences faster: writing convincing lures, adapting components and reaching more victims. The company’s defensive guidance emphasizes authentication, consent and suspicious session behavior. A polished phishing message can still lead to a recognizable misuse of an account.
For a reader, the useful question is how a finding changes a decision. Does it justify investigating a login, resetting access or prioritizing a vulnerability? Intelligence without that connection risks becoming another enjoyable thing to read while the queue grows.
The tools were talking past each other
GreyMatter occupies the space between an enterprise’s existing security technologies. ReliaQuest markets integrations across SIEM systems, endpoint tools, networks and cloud environments, with more than 300 technology partners listed on its current integration page. The proposition is to coordinate detection and response across that collection, while letting customers keep the technologies they choose.

This matters to companies whose security estate resembles a committee. The endpoint product sees one event; the identity system sees another; the cloud tool has a third opinion. Someone must assemble the evidence and decide whether to intervene. ReliaQuest sells software and managed operations around that coordination problem.
“Before ReliaQuest, we lacked visibility into our data, tools or a unified view of current threats.”
Mike Novak, Hard Rock
Customer account published by ReliaQuest
Named customers include Auto Club Group, Hard Rock, APi Group and lighting manufacturer Signify. In ReliaQuest’s Signify account, unifying security across IT, cloud and operational technology produced an 81% reduction in alert noise and saved 1,000 analyst hours annually. Those are vendor-published customer results, rather than a forecast for the next buyer.
The competitive choice depends on the job. A company seeking external intelligence can evaluate specialist providers such as Recorded Future or Flashpoint. A company buying managed detection and response may consider Arctic Wolf or CrowdStrike’s managed offering. GreyMatter’s pitch puts research and external risk alongside operations across a mixed technology stack. A useful comparison begins with the coverage and actions required, then the product names.
The bill, and the business behind it
Public research is the accessible front door. Enterprise subscriptions and managed services are the business behind it; managed takedowns can be an additional DRP service. A report reader and a platform customer are buying very different amounts of responsibility.
A June 2025 Forrester study commissioned by ReliaQuest modeled a $5 billion-revenue composite enterprise from four customer interviews. It estimated roughly $1.6 million in three-year present-value costs against $5.2 million in benefits. That is an economic model, not a quote. Its interviewees described fragmented tools, manual work and slow notifications as reasons to change. The purchase was meant to improve the handling of existing information.
The parent company has attracted considerable money of its own. FTV Capital’s first institutional commitment was $30 million in 2016. KKR led more than $300 million in growth financing in 2020; it had already used ReliaQuest as a customer. In March 2025, a round of more than $500 million led by EQT, KKR and FTV valued ReliaQuest at $3.4 billion. These are parent-company figures, not a research team’s funding history.
A useful alert has a next verb
ReliaQuest’s February 2026 report release put average observed attacker lateral movement at 34 minutes in 2025, down from 48 minutes in 2024. The population is the company’s observations, not every attack everywhere. Nevertheless, a process requiring several handoffs before anyone can disable an account has an obvious timing problem.
Speed has to respect the business it protects. ReliaQuest’s manufacturing offering says its OT Engineer investigates autonomously but leaves containment in production environments to human approval. Stopping a suspicious machine and stopping a production line are decisions with different consequences. Automation needs that distinction written into its permissions.
A team can copy the underlying discipline without purchasing GreyMatter. Keep an accurate list of assets and identities. Give important findings a named owner. Rehearse the response, including approvals for disruptive actions. Measure the time until a threat is contained, as well as the time until a ticket is closed. Use public research to check whether your detections address the behavior being described.
The approach depends on visibility, working integrations and permission to act. An unconnected system cannot contribute its evidence; an unapproved response cannot happen merely because the alert is urgent. ReliaQuest’s interesting wager is that putting external intelligence and internal operations together makes those decisions easier. The stolen password still has its social life. The security team gets a better chance to interrupt it.
Follow the investigation
Explore the research, inspect the product, or hear the people behind the work.