The Firm

Built to prevent,
not to react.

Cerebellum Intel Group was founded on the premise that financial crime, sanctions exposure and reputational failure are almost always visible in advance — to someone who is looking properly.

§ 01Principles

01
P / 01
01

Proactive over reactive

Most compliance work happens after a trigger — a regulator, a headline, a subpoena. Our work is designed to happen before. Continuous monitoring, portfolio-level intelligence and standing engagements are the default posture.

P / 02
02

Intelligence over checklists

A database hit is a starting point, not a finding. Our analysts triangulate open source, human intelligence, corporate filings and specialist datasets to answer the actual question.

P / 03
03

Investigations over lookups

Where the answer requires it, we run investigations — with named analysts, documented methodology and evidence that can be relied upon in litigation, boardrooms and regulatory dialogue.

P / 04
04

Precision over volume

We do not maximize alert counts. We calibrate for signal, defensibility and reviewer trust. Fewer, better findings — routed to the person who can act on them.

§ 02Standards

// Confidentiality

Engagements are compartmentalized. Case teams are minimum-necessary. Client identity is treated as material non-public information internally.

// Data handling

Encrypted at rest and in transit. Jurisdiction-controlled residency by contract. Defined retention with documented destruction.

// Methodology

Written methodology per engagement. Confidence-graded findings. Distinctions between confirmed, corroborated and open leads made explicit.

// Ethics

We decline mandates that require deception, misrepresentation of identity, or unlawful access to information.

// Independence

We do not act on both sides of a dispute. Conflicts are cleared before scoping.

// Regulatory awareness

Practice leads monitor FATF, EU AMLD, FinCEN, OFAC, UK OFSI, MAS and equivalents continuously.

§ 03Principals

Operators, not personalities. Identities are compartmented by policy; call-signs are used in client communication. Full CVs disclosed under NDA where the mandate requires.

// CALL-SIGN
20 YRS

WORMWOOD

Principal · Offensive & Defensive Cyber

Twenty years across advanced red team operations, threat analysis and enterprise risk management. Full-spectrum offensive and defensive cyber capabilities. Over USD 15M in assets and resources recovered on behalf of clients. Previously served as Chief Information Security Officer for several major brands.

RED TEAMTHREAT INTELRISK MGMTRECOVERY
// CALL-SIGN
14+ YRS

ENGRAM

Principal · Intelligence & HUMINT

Over 14 years across military cyber intelligence and fraud defense at global financial scale. Built and led detection programs credited with intercepting fraud at the billion-dollar level. Traces adversaries through their infrastructure and automates the hunt. Former intelligence team chief.

HUMINTINTELLIGENCETHREAT ANALYSISAML

"The absence of a finding is not the same as the absence of a risk. Our job is to know the difference."

— Standing Guidance to Analysts
Engage counsel