All penetration tests and assessments / OSINT assessment

OSINT assessment

What can an attacker find out about your organisation?

Open Source Intelligence, or OSINT, is investigation using public sources. We examine what information about your organisation is available, how it is connected and what an attacker might do with it.

From question to insight

What we clarify

  • What relevant information is publicly available?
  • What does that information mean in your context?
  • Which publicly available information poses a risk?

When is this relevant?

Start with what you want to know.

You want to look at your organisation from the outside. For example, before an attack simulation, when your external environment changes or to understand information shared unintentionally.

The approach

From scenario to insight.

01

Defining the question and boundaries

We agree which parts of the organisation, domains and assessment questions are in scope. We collect only information relevant to that objective.

02

Investigating and checking sources

We investigate public technical and organisational information. We compare sources, check the context and make clear what is a fact and what remains a hypothesis.

03

Meaning and measures

You receive relevant findings with source references, context and practical advice. If a possible attack path requires further investigation, we identify that separately.

What you receive

Insight you can act on.

An evidence-based picture of relevant public information and the risks that may arise from it. This helps you make targeted removals or changes, or define a technical follow-up assessment.

This assessment concerns public sources. Actively entering or testing systems falls under a separately agreed technical assessment.

Discuss your assessment.

Tell us what you want assessed. We will help you find an approach that moves you forward.