Hello Team
Small company, need a simple solution/notification if my company/customers/partners have been hacked/breached. Found https://havewebeenleaked.io/ Is it valid ? would you recommend something different ?
Is there any value of such services ?
Thanks
There are a number of services that offer a database of known breaches (usernames/emails with or without cracked passwords). They can be part of the monitoring mosaic if you want, but their role at best is minor. No matter the circumstance, you should assume every online service you use will be breached at some point. A practice I have long applied is to use different email addresses for different services as a way of tracking who gets compromised or at least who sells or trades my contact information. It doesn't matter the size of the company, its mission, etc., nearly all get sloppy or breached.
As a small company, you are asking a good question. As we've erased the perimeter around our data and resources, security responsibility has moved from a centralized element to something shared by every employee. If you read about most attacks today, many of them come down to some employee having their credentials compromised by a phishing scam or the like. While monitoring has value, I'd prioritize good security training. Follow the SANS Internet Storm Center daily summaries or podcast and occasionally pull out one or two to share with your company and partners.