Qualification
Qualifying the request: surfaces, controls, owners
For CIO, CISO, security and brand roles, the request form works best from a concrete account of current controls rather than a generic brief. It should name which surfaces have prevention, whether email is at enforcement, and who owns each. With that, dotNice can separate a one-off surface review from a prevention build, a DMARC-to-enforcement project or a detection-and-takedown retainer — and recommend clearly which surface to harden first.
The review is most valuable when the buyer can describe the current shape: whether the programme is takedown-only, which surface recurs most, whether any surface has no owner. A request is qualified when it states the surfaces, the controls and the owners. The output is a scoped prevention model — a control per surface with owners — not a service catalogue.
The cost of staying reactive belongs in the same record. A takedown-only programme means the same impersonation recurs while customers are harmed in every live window. Quantifying that — recurrence, exposure time, slow removal — is what moves anti-impersonation from a backlog item to a funded decision with an owner and a cadence.