Workshop
One focused day for a shared baseline: safe searching, verification habits and recording what you find. Suits mixed groups.
Corporate OSINT training gives your own people the skills to find, verify and document open-source information without outside help on every case. We build each course around the work your team already does, so the first real case after the training goes better than the last one before it.
Corporate OSINT training is a practical course that teaches an in-house team to collect, verify, document and report open-source information lawfully. OSINT-S runs formats from an 8-hour workshop to an advanced program of up to 40 hours, online or in person. Exercises use scenarios drawn from your own cases, and every module covers the legal limits that apply to your sector.
Training changes what your team can do on its own; consulting changes one decision or one plan. Many organizations need one, not both.
Training is for teams that run open-source checks every week and want faster searches, fewer false matches and findings that survive a challenge from a lawyer or auditor. The output is people who work differently, plus templates and checklists they keep.
If you need an expert to frame a question, review a report from another provider or advise on one decision, that is OSINT consulting. If you need one urgent answer about a person or company, commission an OSINT investigation and keep training for later.
Formats run from a one-day workshop of about 8 hours to an advanced program of up to 40 hours, delivered online, in person or as a mix of both.
One focused day for a shared baseline: safe searching, verification habits and recording what you find. Suits mixed groups.
Shorter sessions spread over weeks, so participants apply each module to live work in between.
For teams that investigate people and companies: ownership structures, online footprints, document verification and full case reports.
Live online sessions, in-person training at your premises, or both. Material is written for your sector and jurisdictions.
Six core modules: search and collection, verification, documentation and evidence, operational security, legal limits and reporting. We weight them to your team's work.
| Module | What participants practice | What they leave with |
|---|---|---|
| Search and collection | Registries, court records, media archives, social platforms, domain and image searches; planning before searching | A collection plan template and a source list for your jurisdictions |
| Verification | Separating namesakes, checking dates and places, testing images and documents, grading sources | A verification checklist and a confidence scale for findings |
| Documentation and evidence | Capturing pages with time and URL, notes a colleague can follow, preserving material | An evidence log format your lawyers can accept |
| Operational security | Researching without alerting the subject, separate accounts, risky links and files | An OPSEC baseline for your team's devices and accounts |
| Legal limits | Data protection, proportionality, employment-screening rules and the methods that are off limits | A short decision guide: when to stop, ask or escalate |
| Reporting | Separating fact, inference and gap; answering the question asked | A report template and worked examples |
Experienced teams can skip modules and spend the time on harder work, such as tracing beneficial owners across several registries.
Before the course we ask for typical cases your team handles, then turn them into anonymized exercises, so participants practice on problems they will meet again.
Generic exercises teach tools; your own cases teach judgment. During scoping we ask for a few typical files, such as a supplier procurement could not verify, a claim that looked wrong or a counterparty with an unclear owner. We remove details that identify real people and build exercises with the same structure and the same traps.
Live research on real individuals is used only with a lawful purpose and your written agreement; otherwise exercises run on prepared material.
An advanced program ends with a practical task reviewed against the curriculum, so you see where the team is strong and where it needs support. It is a skills check, not a certificate.
Courses for public bodies add the authorization rules that govern online research by the state, alongside the same practical modules.
Public-sector teams work under stricter rules than most companies. In the UK, the Home Office code of practice on covert surveillance says that simple reconnaissance of public websites is unlikely to interfere with a reasonable expectation of privacy, but that systematically collecting and recording information about a particular person or group may need a directed surveillance authorization (Covert Surveillance and Property Interference Code of Practice, 2018). Our government OSINT training courses teach analysts to recognize that line and escalate before crossing it.
In the United States, the intelligence community's own strategy calls for common OSINT tradecraft and training standards and for clear training pathways from the foundational to the expert level (IC OSINT Strategy 2024–2026). We follow the same idea: a baseline for everyone, deeper modules for full-time analysts.
See also OSINT for government and OSINT for law enforcement.
Any team that relies on open-source checks as part of its job, most often compliance, security, fraud, legal and communications teams.
Adverse media that finds the right person, ownership beyond the registry extract, audit-ready files.
KYC and AML support →Threat assessment, executive exposure and researching hostile accounts safely.
Corporate security →Checking claimants and suppliers, spotting fabricated documents, linking accounts.
OSINT for insurers →Preserving online evidence and briefing outside investigators with a lawful scope.
What may be checked about candidates, and when a regulated background check is required.
Verifying viral claims and images before responding to them.
Six steps from a scoping call to follow-up material, with a written proposal and fixed quote before any teaching starts.
Participants learn which methods are lawful, which need a documented basis, and which are off limits whatever the reason.
For ethics and preservation we draw on the Berkeley Protocol on Digital Open Source Investigations, published by the UN Human Rights Office and UC Berkeley in 2022, which sets standards for collecting, verifying and preserving online information.
When the question is urgent, one-off or legally sensitive, an experienced analyst is faster and safer than a newly trained team.
Many teams combine training for routine checks with outside analysts for complex cases, drawn from the rest of our OSINT services.
Focused versions of osint training for specific subjects, deals and situations.
Role-based OSINT courses for officers, analysts and supervisors: safe research, attribution, capture for disclosure and data protection rules.
Read more →OSINT courses for KYC, EDD and third-party teams: adverse media, ownership tracing, source of wealth, namesake checks and audit-ready file notes.
Read more →Tell us who will attend, what they research and what goes wrong today. We reply with a proposed format, modules and a fixed quote.
Yes. Most gains come from method rather than tools: planning searches, separating namesakes, checking ownership across more than one registry and recording sources as you go. We build the course on anonymized versions of your team's own checks. Where a paid tool would make a clear difference we say so, but the course does not depend on any product.
Yes. Courses for public bodies add a module on authorization rules for online research by the state, such as the UK code of practice on covert surveillance, which treats systematic collection about a particular person differently from simple reconnaissance. We build it around your framework and internal policy, and teach analysts to record their reasoning and escalate before a search becomes monitoring.
Yes. Online delivery uses live sessions with practical exercises in every module: participants research prepared scenarios and compare results with the trainer and each other. For distributed teams we usually split the course into shorter sessions over several weeks, so people apply each module to live work in between. In-person or mixed formats are available too.
We anonymize the cases before they become exercises: names, identifiers and details pointing to real people are removed or replaced, while the structure and traps of the case stay. Live research on a real individual is used only with a lawful purpose and your written agreement. Everything you share is kept confidential, and we can sign your NDA before scoping.
Yes. The legal module explains where informal online checks end and regulated background checks begin. In the US, reports bought from a third party for hiring decisions fall under the Fair Credit Reporting Act, with disclosure, consent and adverse-action steps. We also cover the risk of seeing protected information online and how to keep a consistent, job-related process.
Look at volume and stakes. If your team runs open-source checks every week, training pays back because every case improves. If checks come up a few times a year, or matters are contested and may reach court, outside analysts are faster and safer. Many organizations do both. If the choice is still unclear, a short consulting session settles it.
There is no formal certification. An advanced program ends with a practical task reviewed against the curriculum, with feedback for each participant and a summary for the team lead. To test lasting impact, repeat a similar task a few months later or review a sample of real case files against the course checklists.
Sources checked 7 October 2026. Figures about third-party firms and tools are as published by them or by the cited source on that date.