Critical Infrastructure
A critical infrastructure never fails alone: it fails together with its suppliers, its control systems and the public information that allows an outsider to understand it. This area analyses that external surface — what a third party can establish without privileged access — and what decisions it makes possible.
The usual starting point is uncomfortable: technical documentation published in good faith through tenders, annual reports, bids and job adverts which, read as a whole, reveals more than the organisation believes.
What the discipline covers
- Energy, water, transport, health, telecommunications and digital services that other sectors depend on.
- Operational technology (OT/ICS/SCADA) and its progressive convergence with the corporate network.
- Third-party dependencies: maintenance, integrators, vendor remote access, cloud services.
- The regulatory framework applicable to essential operators and their resilience and notification duties.
- Operational continuity and cascade effects between interdependent sectors.
Scope
The assessment looks at the outside of the perimeter. It states what is visible and documented externally, and it deliberately stops short of anything that would require touching a system.
- Documentary exposure: public procurement, official records, technical publications and corporate reports.
- Externally visible technical surface derived from public domain, certificate and network-allocation data.
- Supplier and integrator dependency mapping, including the suppliers' own public exposure.
- Explicit exclusions: no penetration testing, no aggressive scanning, no interaction with OT environments.
Main risks and threats
- Publicly accessible technical documentation: tender specifications, reports, drawings, network diagrams, equipment inventories.
- Job adverts that disclose the vendor, version and architecture of control systems.
- Remote access services or management interfaces reachable from the internet.
- Maintenance providers with permanent access and no verifiable segmentation.
- Excessive concentration on a single supplier or a single supply route.
- Public discourse that reveals shutdown, maintenance or migration schedules.
Relevant indicators and warning signs
- Orphaned digital assets: test environments, subdomains and panels with no assigned owner.
- Newly published tender documents containing more architectural detail than the previous edition.
- Vendor advisories affecting a product version that the organisation has publicly confirmed it uses.
- Technical staff profiles describing privileged access with an unusual level of specificity.
- A supplier with a public incident that grants indirect reach into the operator's environment.
- Certificate or DNS changes that expose an internal naming convention.
Application of OSINT
The work is always carried out from the outside and with no interaction with the systems: what is already published is collected, and the question asked is what it would allow an attacker to plan without ever attempting anything.
- Inventory of documentary exposure across procurement platforms, registers and technical publications.
- Analysis of the visible surface using public domain, certificate and network data, without intrusive scanning.
- Mapping of supplier dependencies and of the suppliers' own public exposure.
- Exposure profiling of technical staff with privileged access, applying data minimisation.
- Prioritisation by the real criticality of the function affected, not by the number of findings.
Zero101OSINT methodology
- Definition of the essential functions to protect, agreed before collection begins.
- Passive collection only: nothing is queried against the operator's own systems.
- Aggregation review: each document is assessed for what it adds when combined with the rest, not in isolation.
- Findings classified by criticality of the affected function and by remediation effort.
- Reports written so they do not themselves become a usable attack description.
- Re-measurement of the same indicators after remediation, to verify that exposure actually fell.
Open sources used
- Public procurement platforms, official bulletins and published administrative files.
- Public technical records of domains, certificates and network allocation.
- Vulnerability advisories from manufacturers and from public incident response bodies.
- Annual reports, press releases, project documentation and sector publications.
- Findings classified by criticality and remediation effort, with attached and traceable evidence.
Applications for companies, organisations and security decision-makers
- Know your own public exposure before a third party makes use of it.
- Assess the exposure of critical suppliers as part of due diligence.
- Bring external evidence to a resilience plan or to a risk committee.
- Review what technical information is published in tenders and job adverts, and at what level of detail.
- Justify security priorities to management with verifiable evidence rather than assumptions.
Products or analytical outputs Zero101OSINT can provide
- External exposure report with prioritised findings, evidence and concrete reduction measures.
- Exposure assessment of a specific supplier or integrator.
- Documentary publication review, stating what to withdraw, what to reword and what to keep.
- Follow-up dashboard to verify the effective reduction of exposure over time.
Legal, ethical and reliability limitations
No penetration testing, aggressive scanning or any interaction with third-party systems is performed. Observation is limited to already published, lawfully accessible information, and reports exclude detail that would facilitate a real attack.
An external analysis does not replace an internal technical audit or an authorised penetration test: it describes what is visible from outside, not the configuration state of the systems. Findings about individuals are handled with data minimisation and a strictly security-related purpose.
Related reports
No intelligence report published in English is directly relevant to this area yet. The available analysis is covered by the related articles below.
Related articles
The corporate digital footprint: what it really reveals about a company
Analysis of the corporate digital footprint: what information it reveals about a company, how it is generated, and why it constitutes a strategic risk if not properly managed.
Read →What your company isn't seeing: blind spots in public information analysis
Every organization has information zones it doesn't analyze or monitor. Analysis of how information blind spots become strategic vulnerabilities exploitable by third parties.
Read →Cumulative risk: how small data builds large vulnerabilities
Each piece of public data, however insignificant it may seem, contributes to a larger exposure profile. Analysis of how information accumulation generates risks that exceed the sum of their parts.
Read →Third-party evaluation: how OSINT reduces risks in business relationships
Every business relationship implies a level of trust. Analysis of how open source intelligence transforms third-party evaluation into a real analytical capability.
Read →Indirect digital footprints: what employees, suppliers and third parties reveal
An organization's digital footprint is not limited to what it publishes itself. Analysis of how third parties generate uncontrolled corporate information exposure.
Read →Invisible risks: public information companies underestimate
Analysis of corporate risks remaining invisible because companies underestimate existing public information about them. Latent threats in open sources.
Read →Related areas
Need analysis in this area?
Describe the scope, the deadline and the decision the analysis has to support. You will receive the proposed approach, the limits of the assessment and the deliverable that can realistically be produced.
Get in touch