Area of expertise · A.10

    Emerging Risks

    Weak signals, emerging technologies (AI, UAS) and risks without consolidated doctrine.

    Intelligence reports

    No reports published in this area yet.

    Related publications

    24 Jun 20266 min

    Drones and perimeter security: the regulatory framework the private security sector cannot ignore

    Analysis of the UAS regulatory framework applied to critical infrastructure security. Specific category, SORA, SAIL and counter-UAS protocols for private security operators.

    Read analysis →
    May 20266 min

    The digitalisation that does not protect you alone

    When you digitalise your security operation without managing your digital exposure, you leave the back door open. Collaborative post with Juan Carlos Mejia Alarcon (SILVER GROUP EC).

    Read analysis →
    April 20269 min

    Claude Mythos: when AI finds what no one saw in 27 years

    Claude Mythos found a 27-year-old flaw in OpenBSD in a single session. What it means for critical infrastructure and what your organisation should be doing right now.

    Read analysis →
    April 202616 min

    What Spain can do and doesn't: operational catalogue against Morocco

    Eight legal, technical and diplomatic instruments to reverse the asymmetry with Morocco without disproportionate costs: financial intelligence, public attribution, European sanctions, EU financial leverage and MCCE capabilities.

    Read analysis →
    April 202613 min

    Why Spain doesn't respond to Morocco: anatomy of a managed asymmetry

    Diagnosis of the six structural and six political factors that explain Spanish inaction against espionage and sustained southern-flank pressure after Pegasus and the Western Sahara pivot.

    Read analysis →
    April 202614 min

    Spain cyberwar Morocco: defence analysis southern flank

    Critical analysis of the Spanish defensive position facing Morocco: real MCCE capabilities, NIS2 delay, critical infrastructure, grey zone and plausible scenarios over 12-36 months.

    Read analysis →
    April 202610 min

    Social engineering fraud and bank claims: what really happens when the customer authorises the operation

    Why banks reject fraud claims when the customer authorises the operation: the key difference between technical authorisation and real consent, the role of the central bank and realistic options.

    Read analysis →
    April 202618 min

    How we dismantled an international fraud network using open sources

    Real case: complete OSINT investigation of a Pig Butchering network with 7 domains, European bank mules and blockchain traceability. Reported to FBI, GoDaddy and Bybit.

    Read analysis →
    April 20269 min

    Preventive intelligence: anticipating risks without waiting for incidents

    Most organizations react to incidents instead of anticipating them. Analysis of the value of preventive intelligence in corporate risk management.

    Read analysis →
    April 20269 min

    The digital environment as a system: understanding relationships, not just data

    Analyzing isolated data produces incomplete conclusions. Analysis of why systemic understanding of the digital environment is essential for corporate intelligence.

    Read analysis →
    April 20269 min

    The illusion of transparency: why seeing information doesn't mean understanding it

    Access to information doesn't guarantee its comprehension. Analysis of how the illusion of transparency generates false certainties in corporate decision-making.

    Read analysis →
    April 20269 min

    Time as a variable in OSINT: how the value of information changes

    Information doesn't have a constant value. Analysis of how the temporal dimension transforms the relevance and risk associated with corporate public data.

    Read analysis →
    April 20269 min

    Confirmation bias in public information analysis

    Confirmation bias distorts the interpretation of open data. Analysis of how cognitive biases compromise the quality of corporate intelligence.

    Read analysis →
    April 20269 min

    The human factor in OSINT: why people are the main information vector

    People, not systems, are the main source of exploitable information. Analysis of the human factor as a critical vector in corporate information exposure.

    Read analysis →
    April 202610 min

    OSINT in investment processes: reducing uncertainty before deciding

    Investment decisions are made with partial information. Analysis of how open source intelligence reduces uncertainty in investment processes.

    Read analysis →
    April 20269 min

    How to evaluate the reliability of public information in business environments

    Not all public information is reliable or verifiable. Analysis of the criteria for evaluating the quality of open data in corporate intelligence contexts.

    Read analysis →
    April 202610 min

    OSINT and compliance: the role of intelligence in legal risk prevention

    Compliance programs that don't integrate open source intelligence operate with a partial view of risk. Analysis of OSINT's role in extended due diligence and third-party evaluation.

    Read analysis →
    April 202610 min

    Advanced social engineering: how public information enables corporate attacks

    The most sophisticated attacks don't exploit technical vulnerabilities. They exploit trust built with information the organization itself left accessible.

    Read analysis →
    April 202610 min

    How cybercriminals use OSINT to prepare targeted attacks against companies

    The most effective attacks don't start with malicious code. They start with public information that no one controlled. Analysis of the reconnaissance process prior to a targeted cyberattack.

    Read analysis →
    March 202610 min

    Whaling: the cyberattack targeting senior management that companies must anticipate

    Whaling is a sophisticated phishing variant designed to compromise executive profiles such as CEOs, CFOs, or legal directors, leveraging their digital exposure.

    Read analysis →
    September 202511 min

    When your digital reputation precedes (and hurts) you

    Cases where public information negatively affected negotiations, hiring, or business relationships. Analysis of common patterns.

    Read analysis →
    September 202510 min

    Digital due diligence: beyond the commercial registry

    What public information can reveal about a partner, supplier, or candidate before signing. Methodology and legal limits.

    Read analysis →
    November 20258 min

    Why AI doesn't replace judgment in OSINT investigations

    Automated tools generate noise. The value is in knowing what to look for and how to interpret it. Analysis of the real limitations of automation.

    Read analysis →