Corporate OSINT audit
What an attacker sees about your company, without touching anything. Executive and technical report, 100% legal and passive.
Corporate OSINT audit
Your organisation's real exposure, as seen by an attacker
OSINT (Open Source Intelligence) is the discipline that collects, correlates and analyses publicly available information to build a profile of a target. It is the first thing any moderately serious attacker does before taking action. Knowing what you have in plain sight before someone with worse intentions uses it is elementary.
What it is
A corporate OSINT audit is intelligence work, not pentesting. We do not test vulnerabilities, we do not access your systems, we do not send pretexting emails. The only thing we do is collect, exclusively from open and legitimate sources, all the information that a motivated attacker with ten days' dedication could obtain about your organisation.
The result has two readings. The first is defensive: it shows what information is exposed without the company knowing it (leaked credentials, internal documents accidentally published, infrastructure forgotten in an old provider's cloud). The second is intelligence: it shows how an attacker would build the attack case from that information (which executive is vulnerable to social engineering, which weak supplier is the most probable path, which exposed service is the most exploitable).
The difference from an automated attack surface scan is that here there is triangulation between three families of defensive AI plus human validation by the responsible party. It is not a script executing rules. Nor is it "a human typing for 80 hours". It is the best of both. The report is written in clear language for the board and in technical language for the team, without inflating findings or hiding them behind jargon.
When you need it
After a merger, acquisition or significant organisational change. Every change brings new domains, inherited infrastructure, employees with new public profiles and inherited contracts with technology suppliers. The map changes quickly and many things are left half-integrated. An OSINT audit after the change identifies the gaps.
Before a significant corporate operation. Public exit, significant funding round, strategic contract that changes your exposure profile. The buyer's or investor's questionnaire will include questions about digital exposure. It is better to answer from a recent in-house report than from improvisation.
After an incident or suspected leak. If there was a ransomware attempt, CFO impersonation fraud, a supplier leak, or simply a phishing email that nearly got through, an OSINT audit determines whether there is information about your organisation circulating in places that warrant additional alerts.
As a recurring practice. We recommend repeating it annually, or after significant changes. Exposure is not static: every new employee, every SaaS tool contracted, every document published on the web adds surface.
How we work
Phase 1 · Scope and authorisation (days 1-2). We agree in writing on the scope: domains, brands, key management profiles, geographies and suppliers in scope. We sign a formal authorisation (necessary on our side to carry out the work with clean legal coverage) and a confidentiality agreement on yours.
Phase 2 · Collection (weeks 1-2). OSINT passive fieldwork: domain and subdomain enumeration, certificate analysis, exposed infrastructure inventory, search in public breach databases, analysis of executive presence on professional networks and forums, identification of accidentally published internal documents, review of public repositories for credential or secret leaks, identification of active impersonations (homoglyph domains, fake profiles), correlation with key technology suppliers.
Phase 3 · Analysis and prioritisation (weeks 2-3). We cross-reference the findings. An isolated leaked credential is a data point; a leaked credential of the finance director combined with a recently registered homoglyph domain is an imminent fraud scenario. We prioritise by probability of exploitation and by impact, not by volume.
Phase 4 · Delivery and presentation (week 3). We deliver two reports and present them: one executive report to management (what we found, what it means, what to do in the next ninety days) and one technical report to the team (each finding with evidence, source, capture date and specific operational recommendation).
What we deliver
- Executive report (5-8 pages) addressed to the CEO and board, with a summary of critical findings, estimated impact, prioritised mitigation plan and key messages for internal communication.
- Technical report (typically 30-60 pages depending on findings) with each finding documented: captured evidence, source, date, criticality, exploitation vector, recommended countermeasure and priority.
- 90-day mitigation plan with concrete actions, suggested owner and reasonable order of execution.
- Evidence repository delivered via secure channel, with limited access and agreed retention.
- Double presentation session: one to management, one to the technical team.
- Prioritised list of suggested continuous monitoring (homoglyph domains to watch, profiles to alert, sources to check).
Who it is for
Organisations with significant digital presence, visible executives or exposure to social engineering. Particularly useful for:
- Companies in a corporate operation (merger, acquisition, round, public exit) that need recent and verifiable documentation of their exposure.
- Sectors with high regulatory or reputational risk (financial, health, energy, critical infrastructures, professional services with high-profile clients).
- Organisations with public or influential executives, where targeted social engineering against individuals is a relevant vector.
FAQs
Is it legal to conduct an OSINT audit on our own company?
Yes, within the scope you authorise us. We work exclusively with open sources and passive techniques. We do not access your systems or those of third parties, we do not impersonate anyone, we do not contact employees. The written authorisation we sign before starting covers us against misunderstandings and covers you against auditors who ask why a third party was collecting data about the organisation.
How long does the work take?
Three weeks from signing the formal authorisation and kick-off. If the scope is very broad (international group with dozens of subsidiaries and brands), it is segmented into waves to maintain the quality of the human analysis.
What is the difference between this and a pentest?
Pentesting actively tests vulnerabilities, touching your systems with authorisation. OSINT does not touch anything: it only collects and analyses what is already public. They are complementary; OSINT usually precedes pentesting so that the latter is focused on what truly matters.
What happens if they find something serious during the work?
We escalate immediately, without waiting for the final delivery. If there are active critical leaked credentials, a homoglyph domain in use for fraud, or sensitive information accidentally published, we notify you within 24 hours with the finding and the immediate mitigation recommendation.
Can you do it periodically as a managed service?
Yes. After the first audit we can contract a continuous monitoring service that watches relevant sources and alerts you when something changes (new leaked credential, new homoglyph domain, new mention of your organisation in illicit activity forums). We discuss this at closing if it makes sense.
What happens with personal data of employees that appear in the findings?
We handle minimum necessary information, anonymise where possible and delete evidence at the end of the project unless retention is agreed with you. We comply with GDPR as joint data controllers during the project.
Typical use cases
Case 1 · The company in the middle of an acquisition process. Industrial company with one hundred and fifty employees in the process of sale to an international group. The buyer requires cybersecurity due diligence as a condition for closing price. We carry out an OSINT audit in three weeks. Main finding: three active leaked credentials of former employees with non-revoked access, an unknown homoglyph domain in use, and sensitive documentation published in an old IT supplier's repository. The company closes the findings before the formal due diligence and delivers a clean report to the buyer.
Case 2 · The law firm after a CFO fraud attempt. Professional firm suffers a CFO impersonation fraud attempt in a transfer. The transfer was stopped in time. The OSINT audit identifies that the attacker had profiled the entire management hierarchy from public professional networks, knew the names of the main clients from press releases, and had registered a homoglyph domain two months earlier. Mitigation plan: review of executive exposure, homoglyph domain monitoring, dual-verification protocol for transfers above a threshold.
Case 3 · The international group with rapid expansion. Services group with presence in five countries and ten brands, growth through acquisitions. OSINT audit focused on mapping the real perimeter: forgotten domains from acquired brands, un-inventoried infrastructure, inherited public profiles of executives that were not updated. Result: corrected inventory with twelve domains and twenty-three previously unaccounted assets, subsequent consolidation plan.
Pricing
Defensive OSINT has two products according to depth and scope:
| Product | What it includes | Price | Timeline |
|---|---|---|---|
| OSINT Express Diagnosis | Public surface analysis on a defined perimeter (main domains + email + visible executives) + prioritised report | 490 € | 5 business days |
| Corporate OSINT Audit | Complete inventory of the real perimeter, active leaks, impersonation, sectoral threat intel, action map | 3,500 - 7,500 € | 3-4 weeks |
The Express Diagnosis is designed as a gateway product: to help you decide whether to go deeper. If after the Express you contract the Corporate Audit, the 490 € is fully deducted from the final price.
Payment terms. Express: single payment at the start. Corporate: fifty percent at the start, fifty percent upon delivery of the signed report.
How to start
The first step is a free initial diagnosis of one week. We agree on scope, tell you what we would typically find with a company of your profile and deliver a concrete proposal with no commitment. If it is not for you, we will tell you.
Write to us at info@ociria.com