Active ransomware, extortion or account takeover? Start emergency intake →
How I Help Credentials Case Files Process Pricing FAQ Get confidential help
Netherlands based · Worldwide cases

When something digital becomes personal.

Cyber stalking, extortion, a stolen account, online fraud or a business under attack can become overwhelming fast. I investigate what happened, preserve evidence, reduce the immediate risk and give you a clear route forward — without drowning you in technical jargon.

Free 30-minute triage NDA available Emergency response available
Publicly verifiable professional background
20+ yearsCybersecurity experience
Accenture SecurityFormer Associate Director
VerizonFormer Principal Cyber Analyst
MT Next 50Leadership recognition, 2019
Help without the jargon

Start with the problem. I will handle the technical complexity.

Most visitors do not need to know whether their case is OSINT, forensics, threat intelligence or incident response. They need to know whether the situation can be investigated and what to do next.

Stalking, threats or impersonation

Identify patterns, preserve evidence, map accounts and reduce exposure.

Start this intake →

Account takeover or identity theft

Contain the compromise, document access paths and build a recovery plan.

Start this intake →

Online fraud or stolen cryptocurrency

Trace flows, preserve transaction evidence and support legal or exchange escalation.

Start this intake →

Ransomware, breach or active intrusion

Contain the incident, protect evidence, establish scope and coordinate recovery.

Start emergency intake →

Romance or investment scam

Validate identities, infrastructure and money trails before more damage is done.

Start this intake →

Executive, insider or brand threat

Investigate exposure, impersonation, insider concerns and targeted threats.

Start this intake →

Data exposed on the dark web

Determine what is exposed, where it is circulating and what action is proportionate.

Start this intake →

Evidence for legal proceedings

Structure digital findings, timelines and technical evidence for counsel or litigation.

Start this intake →
One expert, two client journeys

Personal crisis and corporate incidents need different conversations.

For private individuals

A calm, discreet investigation focused on safety, evidence and practical next steps — not a corporate security lecture.

  • Stalking & harassment
  • Account recovery
  • Identity theft
  • Fraud & crypto tracing
  • Doxxing / impersonation
  • Evidence preservation
Discuss a personal case

For organisations & counsel

Fast containment and investigation for executives, security teams, law firms and organisations that need senior-level cyber support.

  • Incident response
  • Ransomware & extortion
  • Insider investigations
  • Executive exposure
  • Threat intelligence
  • Litigation support
Discuss a business incident
Trust you can verify

Do not take the website’s word for it.

High-trust cyber work should be backed by a public professional record. These links point to independent profiles, coverage or published interviews.

MT / Sprout

MT Next Leadership 50 profile

Independent Dutch profile describing cybersecurity leadership work, including Accenture and NATO-related experience.

Open source
LinkedIn

Professional history & recommendations

Public profile showing roles including Accenture Security and Verizon, plus professional recommendations.

Open profile
UCCR Interview

Interview on Vatican cyber defence

Published interview about the Vatican Cyber Volunteers and continuous threat monitoring.

Read interview
America Magazine

Independent coverage of Vatican cyber work

Coverage naming Joseph Shenouda in connection with the volunteer cyber initiative established in 2022.

Read coverage
Public professional recommendation
“I would hire Joe again without hesitation…”
Bjørn Dijkstra · recommendation visible on Joseph Shenouda’s LinkedIn profile
What happens after you contact me

A clear process lowers stress and avoids surprises.

01

Triage

A confidential 30-minute call to understand what happened, urgency and what evidence already exists.

Free · 30 minutes
02

Scope

You receive a concise plan with objective, deliverables, timing and the agreed fee before billable work starts.

No surprise billing
03

Investigate & contain

Evidence preservation, OSINT, forensic review, tracing, takedown or containment — only what the case actually needs.

Updates in plain language
04

Outcome & next steps

A practical close-out: findings, preserved evidence, recovery actions and recommendations for legal or security follow-up.

Evidence-led close-out
Pricing clarity

You should know what you are agreeing to before work starts.

Cyber cases vary too much for a credible one-price-fits-all tariff. The commitment is simple: triage first, scope second, agreed fee third, work fourth.

First contact

Initial triage

€0

A 30-minute confidential assessment to determine whether I can help and what should happen next.

  • No obligation
  • Urgency assessed
  • Immediate next steps
Active incidents

Emergency & corporate response

Scope based

Ransomware, intrusions and multi-day investigations are priced according to urgency, technical scope and required availability.

  • Rapid activation where available
  • Clear commercial terms
  • NDA on request
Investigation fees are quoted after the free triage so the scope, deliverables and fee reflect the actual work required. You see and approve the fee before billable work starts.
Anonymised case files

Show outcomes, not just expertise.

Representative outcomes from anonymised engagements. Identifying details are withheld to protect clients; the examples show the type of work performed and the outcomes achieved.

Personal threat investigationResolved

Anonymous stalker identified in 11 days

An eight-month pattern of anonymous threats across multiple platforms was investigated using OSINT and account-linkage techniques.

11dtime to resolution
14aliases traced
Ransomware responseRecovered

Mid-market ERP restored in 4 days

A ransomware incident affecting a European manufacturer's ERP environment was contained and moved into structured recovery.

96htime to recovery
−70%ransom reduction
Crypto fraud tracingTraced

€180K fraud investigated across three chains

Transaction paths were traced through multiple chains and mixers and documented for legal follow-up.

3chains traced
62%funds recovered
Client identities and sensitive operational details are intentionally withheld. Published metrics are based on the underlying case record.
Technical depth is still here

For clients who need the details.

Technical buyers, CISOs and counsel can still see the full capability set. It simply no longer dominates the experience for a distressed private client.

Personal investigations

Identity, abuse, fraud and account-related investigations.

Cyber stalkingIdentity theftAccount rescueHarassmentRomance scamsCrypto tracing

Corporate & executive

Targeted investigation and risk work for organisations and leadership.

Insider threatExecutive protectionBrand impersonationDue diligenceM&A cyber riskFraud forensics

Dark web & intelligence

Underground monitoring, attribution and threat intelligence.

Credential leaksBreach investigationThreat actor profilingUnderground marketsRansomware intelVulnerability chatter

Incident response & forensics

Containment, evidence, recovery and post-incident hardening.

RansomwareNetwork forensicsMalware analysisSystem recoverySOC surgeExpert evidence
View the complete service catalogue
Questions before contact

The things clients usually need to know first.

If your question is not covered, use the intake form. You do not need to know which technical service to request.

Is the first conversation free?

Yes. The initial 30-minute triage is free. Its purpose is to understand the situation, urgency and whether I am the right person to help.

Will I know the fee before you start?

Yes. After triage, billable work starts only after the scope and commercial terms have been agreed. Emergency incidents may require a retainer or rapid-response arrangement.

Do you work with private individuals?

Yes. The service is designed for both private individuals and organisations. Personal cases are handled in plain language and with an emphasis on discretion and practical next steps.

Can you guarantee that a person will be identified or money recovered?

No credible investigator can guarantee a specific investigative outcome in advance. I can assess the available evidence, explain what is realistically traceable and document findings for technical, legal or law-enforcement follow-up.

Is my information confidential?

Cases are treated as confidential. An NDA can be arranged on request. Do not send passwords, seed phrases or other authentication secrets through the website form.

What should I preserve before contacting you?

Keep original messages, emails, transaction IDs, URLs, usernames, dates and screenshots. Avoid deleting accounts or wiping devices before evidence has been assessed unless doing so is necessary for immediate safety.

Do you work worldwide?

Yes, where the work can be performed lawfully and remotely or with appropriate local support. Joseph Shenouda is based in the Netherlands.

Confidential intake

Tell me what happened. Plain language is enough.

You do not need to diagnose the incident yourself. Give me the timeline, what changed, what you have already tried and what outcome matters most.

  • Free 30-minute triage before paid work
  • NDA available on request
  • Netherlands based · worldwide cases
  • Do not send passwords, private keys or seed phrases
Please do not include passwords, MFA codes, private keys or cryptocurrency seed phrases.
Verify Get help now