Corporate OSINT audit

What an attacker sees about your company, without touching anything. Executive and technical report, 100% legal and passive.

Corporate OSINT audit

Your organisation's real exposure, as seen by an attacker

OSINT (Open Source Intelligence) is the discipline that collects, correlates and analyses publicly available information to build a profile of a target. It is the first thing any moderately serious attacker does before taking action. Knowing what you have in plain sight before someone with worse intentions uses it is elementary.


What it is

A corporate OSINT audit is intelligence work, not pentesting. We do not test vulnerabilities, we do not access your systems, we do not send pretexting emails. The only thing we do is collect, exclusively from open and legitimate sources, all the information that a motivated attacker with ten days' dedication could obtain about your organisation.

The result has two readings. The first is defensive: it shows what information is exposed without the company knowing it (leaked credentials, internal documents accidentally published, infrastructure forgotten in an old provider's cloud). The second is intelligence: it shows how an attacker would build the attack case from that information (which executive is vulnerable to social engineering, which weak supplier is the most probable path, which exposed service is the most exploitable).

The difference from an automated attack surface scan is that here there is triangulation between three families of defensive AI plus human validation by the responsible party. It is not a script executing rules. Nor is it "a human typing for 80 hours". It is the best of both. The report is written in clear language for the board and in technical language for the team, without inflating findings or hiding them behind jargon.


When you need it

After a merger, acquisition or significant organisational change. Every change brings new domains, inherited infrastructure, employees with new public profiles and inherited contracts with technology suppliers. The map changes quickly and many things are left half-integrated. An OSINT audit after the change identifies the gaps.

Before a significant corporate operation. Public exit, significant funding round, strategic contract that changes your exposure profile. The buyer's or investor's questionnaire will include questions about digital exposure. It is better to answer from a recent in-house report than from improvisation.

After an incident or suspected leak. If there was a ransomware attempt, CFO impersonation fraud, a supplier leak, or simply a phishing email that nearly got through, an OSINT audit determines whether there is information about your organisation circulating in places that warrant additional alerts.

As a recurring practice. We recommend repeating it annually, or after significant changes. Exposure is not static: every new employee, every SaaS tool contracted, every document published on the web adds surface.


How we work

Phase 1 · Scope and authorisation (days 1-2). We agree in writing on the scope: domains, brands, key management profiles, geographies and suppliers in scope. We sign a formal authorisation (necessary on our side to carry out the work with clean legal coverage) and a confidentiality agreement on yours.

Phase 2 · Collection (weeks 1-2). OSINT passive fieldwork: domain and subdomain enumeration, certificate analysis, exposed infrastructure inventory, search in public breach databases, analysis of executive presence on professional networks and forums, identification of accidentally published internal documents, review of public repositories for credential or secret leaks, identification of active impersonations (homoglyph domains, fake profiles), correlation with key technology suppliers.

Phase 3 · Analysis and prioritisation (weeks 2-3). We cross-reference the findings. An isolated leaked credential is a data point; a leaked credential of the finance director combined with a recently registered homoglyph domain is an imminent fraud scenario. We prioritise by probability of exploitation and by impact, not by volume.

Phase 4 · Delivery and presentation (week 3). We deliver two reports and present them: one executive report to management (what we found, what it means, what to do in the next ninety days) and one technical report to the team (each finding with evidence, source, capture date and specific operational recommendation).


What we deliver


Who it is for

Organisations with significant digital presence, visible executives or exposure to social engineering. Particularly useful for:


FAQs

Is it legal to conduct an OSINT audit on our own company?

Yes, within the scope you authorise us. We work exclusively with open sources and passive techniques. We do not access your systems or those of third parties, we do not impersonate anyone, we do not contact employees. The written authorisation we sign before starting covers us against misunderstandings and covers you against auditors who ask why a third party was collecting data about the organisation.

How long does the work take?

Three weeks from signing the formal authorisation and kick-off. If the scope is very broad (international group with dozens of subsidiaries and brands), it is segmented into waves to maintain the quality of the human analysis.

What is the difference between this and a pentest?

Pentesting actively tests vulnerabilities, touching your systems with authorisation. OSINT does not touch anything: it only collects and analyses what is already public. They are complementary; OSINT usually precedes pentesting so that the latter is focused on what truly matters.

What happens if they find something serious during the work?

We escalate immediately, without waiting for the final delivery. If there are active critical leaked credentials, a homoglyph domain in use for fraud, or sensitive information accidentally published, we notify you within 24 hours with the finding and the immediate mitigation recommendation.

Can you do it periodically as a managed service?

Yes. After the first audit we can contract a continuous monitoring service that watches relevant sources and alerts you when something changes (new leaked credential, new homoglyph domain, new mention of your organisation in illicit activity forums). We discuss this at closing if it makes sense.

What happens with personal data of employees that appear in the findings?

We handle minimum necessary information, anonymise where possible and delete evidence at the end of the project unless retention is agreed with you. We comply with GDPR as joint data controllers during the project.


Typical use cases

Case 1 · The company in the middle of an acquisition process. Industrial company with one hundred and fifty employees in the process of sale to an international group. The buyer requires cybersecurity due diligence as a condition for closing price. We carry out an OSINT audit in three weeks. Main finding: three active leaked credentials of former employees with non-revoked access, an unknown homoglyph domain in use, and sensitive documentation published in an old IT supplier's repository. The company closes the findings before the formal due diligence and delivers a clean report to the buyer.

Case 2 · The law firm after a CFO fraud attempt. Professional firm suffers a CFO impersonation fraud attempt in a transfer. The transfer was stopped in time. The OSINT audit identifies that the attacker had profiled the entire management hierarchy from public professional networks, knew the names of the main clients from press releases, and had registered a homoglyph domain two months earlier. Mitigation plan: review of executive exposure, homoglyph domain monitoring, dual-verification protocol for transfers above a threshold.

Case 3 · The international group with rapid expansion. Services group with presence in five countries and ten brands, growth through acquisitions. OSINT audit focused on mapping the real perimeter: forgotten domains from acquired brands, un-inventoried infrastructure, inherited public profiles of executives that were not updated. Result: corrected inventory with twelve domains and twenty-three previously unaccounted assets, subsequent consolidation plan.


Pricing

Defensive OSINT has two products according to depth and scope:

ProductWhat it includesPriceTimeline
OSINT Express DiagnosisPublic surface analysis on a defined perimeter (main domains + email + visible executives) + prioritised report490 €5 business days
Corporate OSINT AuditComplete inventory of the real perimeter, active leaks, impersonation, sectoral threat intel, action map3,500 - 7,500 €3-4 weeks

The Express Diagnosis is designed as a gateway product: to help you decide whether to go deeper. If after the Express you contract the Corporate Audit, the 490 € is fully deducted from the final price.

Payment terms. Express: single payment at the start. Corporate: fifty percent at the start, fifty percent upon delivery of the signed report.


How to start

The first step is a free initial diagnosis of one week. We agree on scope, tell you what we would typically find with a company of your profile and deliver a concrete proposal with no commitment. If it is not for you, we will tell you.

Write to us at info@ociria.com


Other services