Reg. No. 40203410806 VAT LV40203410806

Theme

Book a consultation Book

3.05 Reconnaissance

OSINT & Open Data Analysis

A structured assessment of publicly available information about your organisation, employees, technology and suppliers, with prioritised actions to reduce exposure.

Organisations leave public traces through domains, employee profiles, documents, code repositories, procurement records and infrastructure metadata. Adversaries use the same information to select targets and prepare attacks.

The assessment covers the organisation’s digital footprint, employee exposure, technical information leakage, third-party relationships and metadata in public documents. Findings are validated and translated into concrete remediation actions.

01

How it works

  1. 01

    Scope definition

    Set assessment parameters and priority areas with your teams.

  2. 02

    Data collection

    Gather public intel from search engines, social media, code repos, public databases and the dark web.

  3. 03

    Expert analysis

    Identify critical exposure points and high-risk leakage.

  4. 04

    Reporting

    Executive summary, risk-rated findings, visual evidence and step-by-step remediation.

  5. 05

    Remediation consultation

    Expert-led session to guide implementation.

02

Supported by our own threat-intelligence platform

Your digital footprint is exactly what our platform maps every day. With us, that intelligence is included in the analysis — not a separate subscription.

03

Experience this scenario interactively

A hands-on 3D simulation of this threat, followed by an explanation of how we test it in a real engagement.

04

Frequently asked questions

How is OSINT analysis different from a penetration test?

Penetration testing interacts with systems and may validate vulnerabilities through controlled exploitation. OSINT analysis instead examines information available from public and lawfully accessible sources, showing what an attacker could learn before directly engaging with the target.

Will this analysis disrupt our business operations?

OSINT work is predominantly passive and uses public or lawfully accessible sources. Where a check could interact with a target-controlled system, that activity is identified and agreed during scoping rather than being assumed to be risk-free.

What do we need to provide for the assessment?

We primarily need your organization’s name, primary domain names, and brands to begin. Additional context about specific concerns or focus areas helps us tailor the assessment to your needs.

Will you notify us if you find something critical during the assessment?

Yes. Critical exposures that create an immediate risk are reported through the agreed escalation channel as soon as they are validated, without waiting for the final report.

How often should we conduct OSINT analysis?

We recommend quarterly assessments for most organizations, with more frequent analysis for high-risk industries or during significant organizational changes (mergers, acquisitions, major product launches, etc.).

05

Helpful tools

06

All services

Scope a test

[email protected] +371 2256 5353

Direct access to a senior specialist · Reply within 24 hours · NDA available on request