Threat intelligence
Actors and campaigns targeting your sector and region, translated into actions for IT and OT teams.
Threat intelligence →Critical infrastructure OSINT shows an operator what an attacker, an activist or a saboteur can already see: control systems indexed by search engines, substation layouts in planning files, staff badges on social media, a supplier breach discussed on a forum. We find it, verify it and tell you what to close first. We observe; we never log in, test or exploit.
Critical infrastructure OSINT is the use of public sources, such as internet-device search engines, certificate logs, planning documents, social media, forums and supplier news, to assess risks to energy, water, transport and other essential services. OSINT-S maps exposed assets, monitors threats to sites and staff, and researches suppliers, using observation only, so operators can fix exposure before someone else uses it.
Operators want to know what of theirs is visible from outside, who is talking about their sites, and which suppliers bring risk into the network.
US agencies put disconnecting OT from the public internet first among their primary mitigations, because attackers find exposed devices with search engine tools.
CISA, the FBI, the EPA and the Department of Energy list five primary mitigations for operational technology. The first is to "Remove OT connections to the public internet", and the guidance warns that "OT devices are easy targets when connected to the internet." Attackers find them "by searching for open ports on public IP ranges with search engine tools" (CISA, Primary Mitigations). CISA's exposure reduction guidance names Shodan and Censys among the platforms that index connected devices, including industrial control systems, and tells owners to identify what is reachable and remove what does not need to be (CISA, Internet Exposure Reduction Guidance).
Our exposure mapping uses those indexes, certificate transparency logs, DNS records and public documents to build a list of assets that appear to belong to you, with the evidence for each attribution. We do not connect to devices, try credentials or run active scans. If you want active testing, it belongs in an authorized engagement such as red team OSINT reconnaissance with written permission from the asset owner.
Sabotage, protest and terrorist threats to sites often surface in public channels before they happen, and so does the information used to plan them.
The EU's Critical Entities Resilience Directive covers eleven sectors, including energy, transport, drinking water and digital infrastructure, and aims to strengthen resilience against "natural hazards, terrorist attacks, insider threats, or sabotage", as well as public health emergencies (European Commission). Open sources help on two sides:
We monitor events and threats, not lawful protesters as individuals. Profiles are built only when a specific person makes a credible threat, and that becomes a documented case.
Vendors with remote access or critical spares are part of your attack surface; open sources show changes in their ownership, security and stability.
| Signal | Where it appears | Why it matters |
|---|---|---|
| Breach or ransomware listing | Leak sites, criminal forums, breach notices | Remote access credentials or site data may be exposed |
| Ownership change | Registries, deal news, filings | New owners may bring sanctions or foreign-control questions |
| Financial distress | Insolvency notices, court claims, layoffs | Risk to spares, support and patching |
| Exposed vendor assets | Device indexes, code repositories | Weak points in the vendor's own remote access path |
For in-depth checks on a single supplier, see company investigations; for continuing leak coverage, dark web monitoring.
Insider cases are handled on a specific allegation, proportionately and with HR and legal, not by watching staff online.
Insiders are named as a risk in EU resilience law for good reason: a contractor or employee with site access can do more damage than most outsiders. Open-source work fits two moments. Before access is granted, lawful pre-hire checks through employee screening, within FCRA and data protection rules. After an incident, research on a specific allegation, such as site photos or schematics appearing online, to establish where material surfaced and which public accounts link to it. We do not run blanket monitoring of employees' personal accounts or record union and political activity.
NIS2 and CER are in force; national laws and critical-entity lists are still arriving in some countries, and both expect operators to know their risks.
OSINT does not make an operator compliant. It supplies evidence for risk assessments, supplier reviews and early warning, and it shows boards what outsiders can see. Your compliance team decides how it fits national rules.
Programs usually combine exposure mapping, threat monitoring and supplier research, with investigations on demand.
Actors and campaigns targeting your sector and region, translated into actions for IT and OT teams.
Threat intelligence →What the internet shows about your sites, systems and key staff, with a fix list.
Digital footprint assessment →Platform updates hourly, analysts verify threats to plants, lines and staff before they reach you.
OSINT monitoring →Political and security context for assets and projects in exposed regions.
Geopolitical risk →Credentials, access offers and documents linked to you or your vendors.
Dark web monitoring →Ownership, stability and links of suppliers and contractors with site access.
Company investigations →Start with a baseline of what is exposed, fix the worst items, then monitor for change.
A focused baseline starts from 10 business days, and a full multi-site estate can take up to about a month. Urgent work, for example after a threat against a site, costs 50% more. The fee goes down if we miss the agreed date.
Illustrative patterns, not specific clients.
A device index shows a pump station web interface on a public address. Attribution evidence goes to the OT team, who take it offline.
Local posts show repeated drone flights over a substation. Analysts verify dates and locations and alert site security.
A maintenance contractor appears on a ransomware leak site. The operator rotates the vendor's remote access the same day.
Send your sites, ranges and key vendors. We return a scope and a fixed quote under NDA, then a ranked list of what outsiders can see. For other sectors, see our OSINT services for essential service operators and OSINT for government.
We would not touch them. We look at what is already public: device search engine records, certificates, DNS, planning and procurement documents, job posts, staff social media, leak sites and vendor news. Each finding comes with the evidence that links it to you and a severity rating, so your OT team can act. We never connect to devices or test credentials; active testing needs a separate authorized engagement.
Usually yes. We compare the ranges with registry and routing records, certificate details, hostnames, banners already indexed by search engines, and any public documents that mention the equipment. That often shows whether the assets belong to you, a contractor or someone else entirely. We report the confidence level and the evidence, and leave any active verification to your team or an authorized tester.
Yes. We monitor the event: date, location, expected numbers, routes, and any public calls for sabotage or violence, with alerts to your site security team. We do not profile lawful protesters or record their political views. If a specific person makes a credible threat to staff or equipment, that becomes a separate, documented case, and we will advise involving police where warranted.
It helps, but it is not compliance on its own. OSINT supplies evidence on vendors: breaches, leak-site listings, ownership changes, financial distress and exposed remote access paths. That feeds your supplier risk assessments and contract reviews. NIS2 obligations are set by national transposition law, and your compliance team decides how our findings fit. Some member states were still finalizing transposition in 2026, so check your national rules.
Yes, that is the right scope. We research where the drawings appeared, when, which accounts posted or shared them and whether public information links those accounts to a person. Findings are graded by confidence and documented for HR, legal or police. We do not monitor other employees' personal accounts or access private content. Your lawyers decide on any action against the individual.
A focused baseline starts from 10 business days, which fits a three-week window if the scope is agreed early. We need site names, known IP ranges and domains, key vendors and a contact in your OT team. If the scope grows or the date moves closer, urgent delivery costs 50% more. The report ranks findings by severity, so the board sees the top fixes first.
Sources checked 7 October 2026. Figures about third-party firms and tools are as published by them or by the cited source on that date.