Resources

How RiksTV gains attack surface & employee risk visibility with Aftra

Written by Marta Schluneger | Sep 22, 2026, 12:32:46 PM


About RiksTV

RiksTV is a prominent Norwegian TV distributor and streaming provider. They deliver broadcast and digital streaming services to thousands of households throughout Norway. Because high availability and seamless viewer experiences are crucial for their business and brand, maintaining customer trust, system uptime, and robust cybersecurity is non-negotiable.

We were lucky enough to chat with Sverre Briskodden, IT Manager at RiskTV about how he and his team use Aftra to help manage cybersecurity with confidence.

What Aftra provides

Aftra gives RiksTV continuous exposure management by turning their risk into clear and actionable workflows.

  • The human element: Aftra reveals breached credentials and third-party email exposure, allowing the IT team to address specific password risks directly.
  • Real-time Slack alerts: The Slack integration sends newly discovered critical vulnerabilities instantly into a channel, so they can address them immediately.
  • External exposure monitoring: Aftra continuously tracks the company’s external attack surface to safeguard uptime and customer trust.

 

The story in short

Sverre is in charge of all things IT operations related at RiskTV. It’s his job to ensure that everything works for everybody, so they can do their jobs. This includes ensuring that all employees adopt password best practices and how they use their accounts online. Additionally, two other people internally manage distinct aspects of cybersecurity using Aftra. The Data Protection Officer tracks external exposure, and a Site Reliability Engineer monitors technical misconfigurations.

To gain visibility and control over their entire attack surface including the human part, RiksTV turned to Aftra for continuous exposure management, vulnerability scanning, and human footprint monitoring.

The main challenge:

Before implementing Aftra, managing employee credential risks was a process based largely on suspicion rather than concrete data. The team had limited visibility into how work email addresses were being used on external third-party platforms or if the passwords had been in a leak. This made actual password security difficult to manage. Resolving credential issues often meant manually reaching out to employees based on guesswork, relying on post-breach assumptions, or using arbitrary password rotation that disrupted workflows without truly eliminating security risks.

The solution:

RiksTV deployed Aftra to centralize exposure management, transform credential security from reactive to proactive, and bring threat alerts straight into team operations.

Employee footprint visibility and password security

Immediate visibility into employee digital footprints and confirmed password leaks, allows Sverre to have data-backed conversations with team members who might be exposed and ask them to change their passwords. He tells us that these conversations are now much more productive than before, because he can plainly state that their password was compromised. This not only results in quick action on behalf of the individual, but they also understand the importance of password security and best practices like using strong, unique passwords.

Attack surface mapping

The data protection officer at RiksTV also uses Aftra to map out their attack surface. Although he already has an idea of what’s exposed, having it “on paper” helps him to have complete visibility and manage it with confidence. Additionally, Aftra alerts them when a similar domain is created, which could be used for phishing attempts. They can then go take a look and check if it’s something suspicious.

Critical vulnerability notifications and remediation workflow

Finally, the team including the Site Reliability Engineer monitors critical vulnerabilities via our Slack integration. When Aftra finds potential misconfigurations, exposed credentials, and critical vulnerabilities, it sends notifications directly to their active Slack channel. This ensures that the team responds immediately to triage and resolve the issues.

Sverre also notes that he and his team used Aftra’s built-in self-assessment feature to double-check internal security practices. It forced them to reflect on which industry standards they follow and confirm that essential controls are enforced, such as multi-factor authentication.

What we bring to the table

Instead of treating cybersecurity as an isolated IT task, Aftra empowers three different roles across RiksTV to share responsibility for continuous exposure management.

Human element & footprints: Identifies third-party account exposures and guides employees toward secure password practices.

Privacy & data oversight: Monitors external data exposures to ensure compliance and data privacy.

Infrastructure and critical vulnerabilities:
Directs technical configuration alerts to SRE workflows via automated notifications.

The work we’re proud of

With Aftra’s help, RiksTV have built a modern, frictionless security operation that connects threat intelligence directly to practical daily workflows.

  • Seamless tool integration: Bringing security notifications directly into Slack enabled RiksTV to eliminate isolated dashboard silos and cut resolution times for critical findings.
  • Collaborative security ownership: By equipping IT, DPO, and SRE team members with specialized visibility, security became a shared, multi-disciplinary priority across the business.
  • Executive-level clarity: Simplifying complex technical risk data into transparent reporting metrics allows Sverre and the team to articulate security priorities clearly to executive leadership.

Why RiskTV sticks with Aftra

For a TV streaming provider where downtime directly impacts viewer satisfaction and brand trust, RiksTV uses Aftra to assist in holding a resilient security posture. By combining human-focused credential protection, real-time notifications of critical issues, and external exposure mapping, Aftra gives Sverre Briskodden and his team full visibility over their attack surface without slowing down business operations.

Here’s how we support RiksTV in short

Continuous footprint visibility: Tracks third-party employee credential usage and password leaks in real-time.

Slack integration: Brings security findings directly into daily communication channels for instant resolution.

Self-assessment verification: Serves as a reliable double-check to confirm best practices and security goals are being met.

Role-based security ownership: Distributes exposure management seamlessly across IT, DPO, and SRE team members.