OSINT for Energy and Critical Infrastructure

Critical infrastructure OSINT shows an operator what an attacker, an activist or a saboteur can already see: control systems indexed by search engines, substation layouts in planning files, staff badges on social media, a supplier breach discussed on a forum. We find it, verify it and tell you what to close first. We observe; we never log in, test or exploit.

  • Internet-exposed OT and ICS assets
  • Threats and protests at sites
  • Supplier and vendor risk
  • Insider-risk cases, handled proportionately
Short answer

Critical infrastructure OSINT is the use of public sources, such as internet-device search engines, certificate logs, planning documents, social media, forums and supplier news, to assess risks to energy, water, transport and other essential services. OSINT-S maps exposed assets, monitors threats to sites and staff, and researches suppliers, using observation only, so operators can fix exposure before someone else uses it.

Critical Infrastructure OSINT: What Operators Ask

Operators want to know what of theirs is visible from outside, who is talking about their sites, and which suppliers bring risk into the network.

  • Are any of our control systems, remote access gateways or engineering workstations visible on the public internet?
  • Which documents, photos and job posts reveal site layouts, equipment models or security routines?
  • Is anyone calling for action against our plants, pipelines or substations, and is it credible?
  • Has a vendor with remote access to our sites been breached, sold or sanctioned?
  • When we suspect a leak or sabotage from inside, what does the public record show?

Internet-Exposed OT and ICS Assets

US agencies put disconnecting OT from the public internet first among their primary mitigations, because attackers find exposed devices with search engine tools.

CISA, the FBI, the EPA and the Department of Energy list five primary mitigations for operational technology. The first is to "Remove OT connections to the public internet", and the guidance warns that "OT devices are easy targets when connected to the internet." Attackers find them "by searching for open ports on public IP ranges with search engine tools" (CISA, Primary Mitigations). CISA's exposure reduction guidance names Shodan and Censys among the platforms that index connected devices, including industrial control systems, and tells owners to identify what is reachable and remove what does not need to be (CISA, Internet Exposure Reduction Guidance).

Our exposure mapping uses those indexes, certificate transparency logs, DNS records and public documents to build a list of assets that appear to belong to you, with the evidence for each attribution. We do not connect to devices, try credentials or run active scans. If you want active testing, it belongs in an authorized engagement such as red team OSINT reconnaissance with written permission from the asset owner.

Physical Threats to Sites and Staff

Sabotage, protest and terrorist threats to sites often surface in public channels before they happen, and so does the information used to plan them.

The EU's Critical Entities Resilience Directive covers eleven sectors, including energy, transport, drinking water and digital infrastructure, and aims to strengthen resilience against "natural hazards, terrorist attacks, insider threats, or sabotage", as well as public health emergencies (European Commission). Open sources help on two sides:

  • Threat signals. Calls for action against named sites, protest plans, posts about drones near facilities, and chatter in extremist channels, verified and escalated by analysts.
  • Site exposure. Floor plans in planning portals, photos of control rooms in recruitment posts, contractor uploads of site walkthroughs and staff routines visible on fitness apps.

We monitor events and threats, not lawful protesters as individuals. Profiles are built only when a specific person makes a credible threat, and that becomes a documented case.

Supply-Chain and Vendor Risk

Vendors with remote access or critical spares are part of your attack surface; open sources show changes in their ownership, security and stability.

SignalWhere it appearsWhy it matters
Breach or ransomware listingLeak sites, criminal forums, breach noticesRemote access credentials or site data may be exposed
Ownership changeRegistries, deal news, filingsNew owners may bring sanctions or foreign-control questions
Financial distressInsolvency notices, court claims, layoffsRisk to spares, support and patching
Exposed vendor assetsDevice indexes, code repositoriesWeak points in the vendor's own remote access path

For in-depth checks on a single supplier, see company investigations; for continuing leak coverage, dark web monitoring.

Insider Risk at Critical Sites

Insider cases are handled on a specific allegation, proportionately and with HR and legal, not by watching staff online.

Insiders are named as a risk in EU resilience law for good reason: a contractor or employee with site access can do more damage than most outsiders. Open-source work fits two moments. Before access is granted, lawful pre-hire checks through employee screening, within FCRA and data protection rules. After an incident, research on a specific allegation, such as site photos or schematics appearing online, to establish where material surfaced and which public accounts link to it. We do not run blanket monitoring of employees' personal accounts or record union and political activity.

NIS2, CER and What Regulators Expect

NIS2 and CER are in force; national laws and critical-entity lists are still arriving in some countries, and both expect operators to know their risks.

  • NIS2. Member states had until 17 October 2024 to transpose the directive. The Commission has since referred Ireland, Spain, France and the Netherlands to the Court of Justice for failing to notify transposition measures. NIS2 also makes top management accountable for cybersecurity risk management (European Commission).
  • Incident reporting. Under NIS2, an early warning on a significant incident is due "within 24 hours" and an incident notification within 72 hours of becoming aware of it (Directive (EU) 2022/2555).
  • CER. Member states must identify critical entities by 17 July 2026, based on national risk assessments due by 17 January 2026 (European Commission).

OSINT does not make an operator compliant. It supplies evidence for risk assessments, supplier reviews and early warning, and it shows boards what outsiders can see. Your compliance team decides how it fits national rules.

OSINT for Utilities and Energy Operators: Services

Programs usually combine exposure mapping, threat monitoring and supplier research, with investigations on demand.

Cyber

Threat intelligence

Actors and campaigns targeting your sector and region, translated into actions for IT and OT teams.

Threat intelligence →
Sites

OSINT monitoring

Platform updates hourly, analysts verify threats to plants, lines and staff before they reach you.

OSINT monitoring →
Region

Geopolitical risk intelligence

Political and security context for assets and projects in exposed regions.

Geopolitical risk →
Leaks

Dark web monitoring

Credentials, access offers and documents linked to you or your vendors.

Dark web monitoring →
Vendors

Company investigations

Ownership, stability and links of suppliers and contractors with site access.

Company investigations →

Running a Critical Infrastructure Risk OSINT Program

Start with a baseline of what is exposed, fix the worst items, then monitor for change.

  1. Define the estateSites, IP ranges, domains, brands, key staff and critical vendors, each with an owner.
  2. Baseline exposureA first report on exposed assets, revealing documents and leaked data, ranked by severity.
  3. RemediateYour teams close or restrict what does not need to be public; we re-check the fixes.
  4. MonitorHourly platform updates with analyst review for threats, new exposure and vendor events.
  5. Investigate on demandSpecific incidents, threats or allegations become scoped cases.
  6. Report to the boardPeriodic summaries that support risk assessments and supplier reviews.

A focused baseline starts from 10 business days, and a full multi-site estate can take up to about a month. Urgent work, for example after a threat against a site, costs 50% more. The fee goes down if we miss the agreed date.

Typical Scenarios at Energy and Water Sites

Illustrative patterns, not specific clients.

OT

A forgotten interface

A device index shows a pump station web interface on a public address. Attribution evidence goes to the OT team, who take it offline.

Site

Drone posts near a plant

Local posts show repeated drone flights over a substation. Analysts verify dates and locations and alert site security.

Vendor

Supplier on a leak site

A maintenance contractor appears on a ransomware leak site. The operator rotates the vendor's remote access the same day.

Start With an Exposure Baseline

Send your sites, ranges and key vendors. We return a scope and a fixed quote under NDA, then a ranked list of what outsiders can see. For other sectors, see our OSINT services for essential service operators and OSINT for government.

Critical Infrastructure OSINT FAQ

We run a regional water utility and our board asked for a critical infrastructure OSINT assessment — what would you actually look at, and would you touch any of our control systems?

We would not touch them. We look at what is already public: device search engine records, certificates, DNS, planning and procurement documents, job posts, staff social media, leak sites and vendor news. Each finding comes with the evidence that links it to you and a severity rating, so your OT team can act. We never connect to devices or test credentials; active testing needs a separate authorized engagement.

Shodan shows a few devices on IP ranges that might be ours, but our OT team says they're not — can you confirm who owns them without scanning or logging in?

Usually yes. We compare the ranges with registry and routing records, certificate details, hostnames, banners already indexed by search engines, and any public documents that mention the equipment. That often shows whether the assets belong to you, a contractor or someone else entirely. We report the confidence level and the evidence, and leave any active verification to your team or an authorized tester.

Activists have announced a blockade of our gas terminal next month — can you monitor the planning without building files on every protester?

Yes. We monitor the event: date, location, expected numbers, routes, and any public calls for sabotage or violence, with alerts to your site security team. We do not profile lawful protesters or record their political views. If a specific person makes a credible threat to staff or equipment, that becomes a separate, documented case, and we will advise involving police where warranted.

Our company falls under NIS2 as an essential entity — can OSINT help us meet the supply-chain security part, and does it count as compliance on its own?

It helps, but it is not compliance on its own. OSINT supplies evidence on vendors: breaches, leak-site listings, ownership changes, financial distress and exposed remote access paths. That feeds your supplier risk assessments and contract reviews. NIS2 obligations are set by national transposition law, and your compliance team decides how our findings fit. Some member states were still finalizing transposition in 2026, so check your national rules.

We think an engineer leaked substation drawings to a forum after he was dismissed — can you investigate without monitoring the rest of our staff?

Yes, that is the right scope. We research where the drawings appeared, when, which accounts posted or shared them and whether public information links those accounts to a person. Findings are graded by confidence and documented for HR, legal or police. We do not monitor other employees' personal accounts or access private content. Your lawyers decide on any action against the individual.

How quickly can you deliver an exposure baseline for five power plants and our corporate network if the board meets in three weeks?

A focused baseline starts from 10 business days, which fits a three-week window if the scope is agreed early. We need site names, known IP ranges and domains, key vendors and a contact in your OT team. If the scope grows or the date moves closer, urgent delivery costs 50% more. The report ranks findings by severity, so the board sees the top fixes first.