Working Together
Breach counsel, cyber insurance brokers, and security service providers occasionally need a partner they can trust with their clients. Here is what that looks like with Unknown².
Partner Types
Each comes with a different dynamic and different expectations. We've tried to be specific about what each one looks like.
When your client calls at 2am with an active ransomware incident, you need a technical partner you can put on the phone immediately — someone who can triage the situation, preserve forensic evidence in a way that protects privilege, and brief you on what happened in terms you can use.
We work within counsel's structure. Engagement letters run through you. Forensic reports are privilege-protected. We brief you before we brief the client on anything that touches legal exposure. We don't go around you.
On the proactive side, we can support clients your firm represents who want to reduce their incident likelihood before something happens — and who benefit from having counsel already established in that relationship.
Carriers need IR vendors who respond quickly, document thoroughly, and don't pad engagements. Brokers need someone they can recommend to clients who ask — a name they can stand behind when a client is in crisis.
We work with carriers' panel requirements and their reporting expectations. We don't have a conflict of interest between selling breach insurance and responding to breaches. We don't have a forensics practice that competes with a monitoring practice that competes with a consulting practice — we do one thing well and we refer out the rest.
For brokers specifically: we're also available for pre-bind security assessments and policyholder advisory — the kind of proactive work that reduces claims and builds the relationship between you and your client before something goes wrong.
You have clients who need red team work or IR that's beyond your current scope. We're not competing with your managed services. We come in, do the engagement, and hand back to you. Your client relationship stays yours.
For adversary simulation: we can emulate threat actors specifically relevant to your clients' industries and help your detection team build or validate detection content against real TTPs. For IR: we handle the technical response and negotiation while you maintain the ongoing relationship.
We're also available for purple team work where your analysts and ours work together — which tends to produce better detection content than either team working alone.
A few things worth being explicit about before any referral relationship starts:
These aren't caveats. They're the reason the relationship works.
You're putting your name behind whoever you refer. That means the quality of the work and the professionalism of the engagement reflect on you.
Unknown² is a principal-led practice. When you refer a client, they work with Matticus Hunt — not a junior analyst, not an engagement manager who hands off to a delivery team, not a rotational associate. The person you spoke to is the person doing the work.
We operate with a small roster by design. That means we have capacity limitations, and we'll tell you when we're at capacity rather than overcommitting and underdelivering. A referral that goes badly is worse for both of us than one that was declined because timing wasn't right.
Start a partner conversation: hello@unknown2.com →Get in Touch
The best time to establish a referral relationship is before you have an urgent situation. Reach out to start a conversation about whether there's a fit — what your clients typically need, what your referral process looks like, and how we'd work together.
Start a Conversation →