
The DRP Reset: Why Takedown Volume Was Never the Metric
Every digital risk protection program reports the same kind of number to leadership each quarter. Artifacts removed, average time to takedown, and cases closed have been the working vocabulary of this category since it emerged, and Sean Sosnowski's new research at SACR makes a direct argument about what those figures establish, which turns out to be considerably less than most programs assume.
The report is titled The Future of Digital Risk Protection Is External Trust Operations. Outtake sponsored it and SACR wrote it independently, so the buyer framework inside it applies across the market rather than to any single vendor. What follows covers the argument and what we think security leaders should do with it.
Three numbers from the research
The model was built for a slower internet
Digital risk protection earned its place for good reason. Organizations lost control of how their brands, domains, executives, products, and customer-facing services appeared across the public internet, and DRP brought those assets into a repeatable workflow of monitoring, investigation, escalation, and takedown. For a threat that arrived one artifact at a time, that was the correct answer.
The threat has since stopped arriving one artifact at a time. A single campaign now moves across social accounts, cloned sites, fraudulent advertisements, messaging channels, synthetic personas, mobile applications, and payment or credential- harvesting flows, and each of those surfaces is watched by a different tool, escalated to a different team, and tracked as a different case. The adversary runs one coordinated operation while the defending organization works a dozen separate tickets and never assembles the full picture.

SACR frames this as a structural problem rather than an execution problem. Programs are not underperforming because analysts are slow or because vendors are weak. They are underperforming because the thing being counted is the artifact, while the thing causing the harm is the campaign.
Three forces made this urgent
Each of these forces predates the current moment, but their combination has moved the problem beyond the reach of the architecture built to handle it.
The cost of generating an attack collapsed. Lookalike domains, fake profiles, cloned voices, translated scripts, and synthetic video now cost roughly the price of a subscription and take minutes to produce. Verizon's 2026 Data Breach Investigations Report attributed 15 percent of observed attack techniques to generative AI assistance and reported higher click rates for mobile phishing. Any operating model that assigns a person to each individual item is competing against software while paying in human hours.
Ownership of the response fragmented across teams. Security may find the fake domain while fraud sees the customer losses, brand and legal focus on the impersonating account, and communications, support, and executive protection encounter reputational damage and victim reports. Each of those teams is doing legitimate work on a real signal. The campaign becomes visible only when those perspectives are connected, and in most organizations nothing connects them.
The public enterprise became the attack surface. Security architecture begins inside the perimeter with identities, endpoints, cloud services, and data. An organization's public identity sits somewhere else entirely, distributed across registrars, app stores, advertising networks, marketplaces, search engines, messaging services, and social platforms that the enterprise does not control. Customers, partners, employees, and increasingly the automated systems acting on their behalf all infer legitimacy from whatever they encounter there, and that asymmetry is what impersonation exploits.

Three forces made this urgent
This is the section of the report most likely to prompt an uncomfortable conversation between a security team and the executives it reports to.
A completed takedown request records that a response action occurred. It does not establish that the threat ended. An account can disappear while the domain network supporting it stays live. A phishing page can be removed after the credentials have already been collected. A counterfeit listing can return through a different seller. In each of those cases the artifact is gone, the case is marked resolved, and the operation continues.
SACR maps the difference in a single diagram. Most programs recognize themselves in the top row.

The standard the research proposes instead is verified closure. A case reaches closure when the organization holds evidence that the active threat pathway was disrupted, that related assets were remediated or consciously accepted by a named owner, that every required team completed its action, and that recurrence monitoring is running. That is a considerably harder bar than filing a removal request, and it is the only bar that describes what a security leader actually wants to be true.
What External Trust Operations means in practice
SACR names the resulting operating model External Trust Operations. The label matters less than the change it describes, which is a change in what the program organizes itself around.
Rather than monitoring channels and actioning artifacts, the program protects a defined set of business entities, connects related activity into campaigns, coordinates response across the functions that own the resulting harm, and holds an evidence standard for closure. Tooling decisions follow from that structure instead of preceding it.
The report gives CISOs four tests, and they are the most portable part of the research.
Those four tests are vendor-neutral by design. Run them against your own program before you run them against anyone's product.
The 90 day plan
The closing section of the report is a 90 day buyer action plan, and it is the part that translates most directly into work.
The first month establishes a baseline. Define the highest-priority entities and the context required to protect them, map how work moves from discovery through recurrence monitoring across your teams today, and set the measures that will later show whether anything improved.
The second month tests discovery and campaign connection under realistic conditions. Run scenarios in which the adversary avoids exact keywords, hides the lure in imagery, operates in a language your analysts do not read, migrates between platforms, or separates the initial lure from the eventual fraud path.
The third month puts a bounded workflow into production and then tries to break it. One instruction in this section is worth acting on whether or not you evaluate anything: reopen cases you have already closed and check for surviving assets, platform migration, continued victim reports, or new infrastructure. Whatever percentage should never have been closed is the most honest figure your program has produced all year.
Where Outtake sits, and how to test it
Read this section as a vendor claim.
Outtake organizes protection around entities rather than keyword lists, with brands, people, locations, and products each enriched by the context that establishes legitimacy. Recon Agent expands a single suspicious artifact into a mapped network of related accounts, infrastructure, channels, and monetization paths, keeping relationships supported by evidence visibly separated from those that are inferred. Evidence, analyst decisions, takedown outcomes, and recurrence signals persist in the Digital Reservoir, so a campaign that returns is recognized as a recurrence instead of being logged as a new incident.
SACR profiles Outtake as an illustrative solution profile and states plainly that this is not validation of outcomes. The report also raises three risks that are worth repeating here. A category should not become dependent on any single vendor's language. Product direction is not the same as proven results. And no one platform replaces every adjacent category. We agree with all three, and the four tests above are how you hold us to them.

Read the research
SACR also published a convergence map of the market, built from each vendor's primary motion and its functional relevance to external trust operations. Eight containers, more than sixty vendors, and several appearing in three or four categories at once. The report explains the placement logic behind it, including where each adjacent market contributes and where it stops.

The full report covers this map in detail, along with the executive impersonation buyerscenario, the six stage operating sequence, and the complete 90 day plan.
Outtake sponsored this research. SACR wrote it independently, and its category definition and buyer framework apply across the market.
