Emerging Risks
An emerging risk is not a risk that nobody has described. It is one for which the organisation still has no reference data, no established procedure and no clear internal owner. Automated content generation, uncrewed aerial systems, connected devices and dependence on a handful of technology providers all share that condition today.
This area exists to prevent two symmetrical errors: dismissing a change because no incident has happened yet, and buying a solution for a threat that has not been characterised. The work consists of describing what is already documented, what is plausible, and what is merely marketing.
What the discipline covers
- Applied artificial intelligence: automated content generation, voice and video cloning, and scaled-up social engineering.
- Uncrewed aerial systems: overflight of facilities, unauthorised observation, and the regulatory framework governing response.
- Connected devices and operational technology reaching the corporate network without being inventoried.
- Technological and supply concentration: single points of failure in providers, models, components or certificates.
- Regulatory shifts that turn an accepted practice into an obligation, a liability or a sanction.
Scope
The scope is deliberately conservative: characterising a change, distinguishing documented capability from projection, and translating both into decisions the organisation can actually take this year.
- Assessment of a specific emerging risk in the organisation's own context, not in the abstract.
- Review of exposure to a new vector: overflight, voice impersonation, unmanaged connected devices, provider dependency.
- Analysis of the applicable regulatory framework and of the obligations it introduces, with dates.
- Explicit exclusions: no technological forecasting, no adversarial testing, no capability claimed without public evidence.
Main risks and threats
- Voice or video impersonation of an executive used to authorise a payment or a change of instructions.
- Convincing, personalised fraudulent content produced at a volume that defeats manual review.
- Unauthorised overflight of facilities, with observation, disruption or reputational consequences.
- Connected devices installed without inventory, without updates and without an assigned owner.
- Dependence on a single provider or model whose failure, price change or withdrawal halts a process.
- Regulatory non-compliance arising from adopting a tool faster than the governance around it.
- Loss of confidential information through staff use of external tools with no defined internal policy.
Relevant indicators and warning signs
Emerging risk is usually visible first inside the organisation, in the gap between what is already being used and what has been formally approved.
- Tools adopted by teams without a policy, an owner or a record of what data they process.
- Payment or instruction changes authorised by voice or video without a second, independent verification channel.
- Absence of an up-to-date inventory of connected devices and of who is responsible for each one.
- Critical processes resting on a single provider, model or component with no tested alternative.
- Publicly documented incidents affecting comparable organisations in the same sector.
- Regulatory deadlines already published and approaching with no internal preparation under way.
- Repeated drone sightings over a facility with no recording procedure and no defined response.
Application of OSINT
- Systematic review of documented incidents affecting comparable organisations, separating verified fact from vendor narrative.
- Tracking of regulatory publications and of official guidance, with the applicable dates identified.
- Assessment of the organisation's own external exposure to the specific vector under examination.
- Mapping of technological dependencies from public information: providers, contracts, published architecture, technical job adverts.
- Explicit distinction between demonstrated capability, laboratory demonstration and commercial promise.
Zero101OSINT methodology
- Each risk described against three questions: is it documented, is it applicable here, and is it actionable now.
- Public evidence required before any capability is treated as real; nothing is inferred from a vendor claim.
- Prioritisation by realistic impact on the organisation's own processes, not by novelty or media attention.
- Recommendations expressed as procedure, ownership and verification before any purchase is considered.
- Assumptions stated openly, so the assessment can be re-examined when the underlying facts change.
- Review horizon set explicitly: an emerging-risk assessment expires and says so.
Open sources used
- Official regulatory publications, gazettes and guidance from national and European authorities.
- Public advisories from cyber-incident response bodies and from manufacturers.
- Academic and institutional research on applied artificial intelligence, uncrewed systems and connected-device security.
- Publicly documented incident reports and official statements by the organisations affected.
- Corporate technical documentation, published architecture and job adverts as evidence of technological dependency.
Applications for companies, organisations and security decision-makers
- Decide whether an emerging risk requires action now, monitoring, or nothing at all.
- Introduce independent verification for instructions that can be impersonated, before an incident forces it.
- Prepare for a published regulatory deadline with a realistic timetable and named owners.
- Review technological dependencies and identify which of them have no viable alternative.
- Give a board or risk committee an evidenced basis for approving — or declining — a security investment.
Products or analytical outputs Zero101OSINT can provide
- Emerging risk assessment for a specific vector, with documented evidence, applicability, priority and review date.
- Exposure review of a facility to unauthorised overflight, with a recording and response procedure.
- Impersonation resilience review of authorisation processes, with concrete verification controls.
- Technological dependency map with single points of failure and alternatives identified.
- Regulatory readiness summary with obligations, dates, gaps and owners.
- Internal usage policy for external tools, written so that staff can actually apply it.
Legal, ethical and reliability limitations
No intrusion testing, no adversarial exercises against systems and no interference with aerial systems is carried out: response to an unauthorised overflight is a matter for the competent authorities and for the applicable legal framework, and any recommendation stays within it.
Assessing an emerging risk means working with incomplete evidence: capability evolves faster than documentation, vendor claims are not verifiable, and every assessment has a limited useful life, which is stated in each deliverable. This work does not constitute a technological forecast, a certification, a legal opinion or a substitute for a formal technical audit.
Related articles
Why AI doesn't replace judgment in OSINT investigations
Automated tools generate noise. The value is in knowing what to look for and how to interpret it. Analysis of the real limitations of automation.
Read →Cumulative risk: how small data builds large vulnerabilities
Each piece of public data, however insignificant it may seem, contributes to a larger exposure profile. Analysis of how information accumulation generates risks that exceed the sum of their parts.
Read →Weak signals: how to detect risks before they become problems
Corporate incidents rarely appear without warning. Analysis of how weak signals in open sources enable anticipating risks conventional systems don't capture.
Read →How risk changes when the digital context changes
Corporate risk is not static. Analysis of how digital environment transformations alter the nature and scope of information threats.
Read →From data to intelligence: why collecting information is not enough
Accumulating data does not equate to understanding a situation. Analysis of why information overload without context represents a risk for corporate decision-making.
Read →Preventive intelligence: anticipating risks without waiting for incidents
Most organizations react to incidents instead of anticipating them. Analysis of the value of preventive intelligence in corporate risk management.
Read →Related areas
Need analysis in this area?
Describe the scope, the deadline and the decision the analysis has to support. You will receive the proposed approach, the limits of the assessment and the deliverable that can realistically be produced.
Get in touch