Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementSecurity Leadership and ManagementLogical SecuritySecurity & Business Resilience

Stay a step ahead with the missing link in cybercrime defense: OSINT

By Michael McLaughlin
Human brain formed from connections

Image via Unsplash

April 15, 2024

Chief Information Security Officers (CISOs) require a comprehensive set of tools, services and skilled people to succeed in the never-ending battle against cybercrime. They stand as the last line of defense to protect their organizations from losing data, money, reputation and, in extreme cases, the business itself. Adding OSINT-driven threat intelligence to the CISO toolkit can be a game-changer, delivering insights that enable a more proactive rather than reactive approach to cybercrime defenses.

Whether launched by criminal syndicates, nation-states or their proxies, ransomware and other forms of cybercrime have become a constant threat that requires real-time analysis and defense to effectively identify, mitigate and counter these attacks. To minimize risks and avoid surprises, CISOs must utilize technical tools and expertise, as well as threat intelligence to gain predictive insights on cybercrimes.

CISOs commonly adopt a two-pronged strategy. The first approach is to use technical tools and expertise, sometimes as a security operations center (SOC), either internally or as a service. The second is to educate and develop IT personnel and other staff who should be able to detect phishing and business email compromise (BEC) attacks in their day-to-day work. Open-source intelligence (OSINT) can be the missing third prong of an effective cybersecurity strategy. 

The intersection of OSINT and cybersecurity

OSINT is the process of collecting, filtering and analyzing publicly and commercially available data from across the surface web, the deep web and the dark web. It has recently grown in popularity as a primary intelligence discipline in national security and defense circles due to the need to quickly detect risks across overwhelming and exponentially increasing volumes of online data and is now being adopted in the corporate sector as well for similar reasons. 

The open web consists of the sites people use daily, which everyone can access, such as public websites, social media sites, chat groups and discussion forums. The deep web constitutes the hidden part of the web that is not indexed by traditional search engines, including sites are secured with some form of protection, such as passwords or additional security measures to ensure only authorized people can gain access. The dark web has a mystical aura but is simply a part of the encrypted internet and is only accessible with specialized tools, such as The Onion Router, or “Tor.” What gives the dark web its aura are the criminal actors that take advantage of its anonymity to share information and plan attacks.

With specialized OSINT capabilities, SOC teams scan the dark web chatter between cybercriminals, extracting volumes of information on their activities. The discussions range from what new or improved tools and techniques are available to which companies or industries are in the spotlight, new data on supply chain vulnerabilities to exploit and more. It is also possible to identify breaches almost immediately after they occur when people boast about their achievements or release personal information or intellectual property.

Large volumes of data are collected in this manner and analyzed to deliver usable information. The growth of artificial intelligence (AI) augments this analysis as algorithms can pick up trends and indicators that are undetectable by human analysts. 

Cybercrime insights hidden in plain sight

Many ransomware gangs are starting to post data stolen from their victims on the open web to encourage them to pay up because their data is potentially exposed to over 2 billion people using the web each day. Although unfortunate for the victims, this situation can provide valuable data analysis and intelligence-gathering information. It highlights compromised companies, information, passwords and newly found vulnerabilities.

OSINT threat intelligence also aids in supply chain risk management, delivering relevant insights about partners, service providers and other companies along the supply chain. A cloud provider, for example, could be under attack, which, if successful, will impact its customers’ ability to operate. Similarly, compromised downstream partners, such as retail outlets or resellers, can pose unique threats to an organization’s operations.

Without OSINT threat intelligence to enhance their cybersecurity strategies, corporations lose a critical edge in their proactive defense posture, leaving them at risk of data loss, brand reputation damage, compliance fines, revenue loss and more.

Pre-emptive defense strategies – the role of OSINT

The need for OSINT is not secondary to cybercrime tools, education and skills; it supplements, supports and enhances cybersecurity strategy with intelligence on attackers’ targets, malware, motivations, methods and more. Effective OSINT solutions enable the practical use of AI-enabled analytics by filtering mountains of data to identify and alert suspicious activities that may indicate an imminent breach.

The State of Ransomware 2023 report highlights that “an exploited vulnerability was the most common root cause of ransomware attacks (36%), followed by compromised credentials (29%).” Only 3% were due to a brute force attack — what most people define as hacking. OSINT threat intelligence, therefore, can potentially play a vital role in helping to prevent more than 50% of ransomware attacks. 

People like to talk, and cyber criminals are no different; perhaps they are even more inclined to boast when defeating a large corporation. OSINT specialists within SOCs can gain insights into what industries and companies are being targeted, newly released malware and what new vulnerabilities they exploit — even before the Cybersecurity and Infrastructure Security Agency (CISA) or law enforcement agencies release a public warning.

More than data loss

Corporate governance, risk management and compliance are critical factors affecting corporate reputation and the sentiment of stakeholders, especially investors. Similarly, cyber resilience quickly evolved into a reputational influencer. Publicly traded companies must now report material cyber breaches within four days, and annual reports must include information on the business’s cyber governance and hygiene.

Managing their organization’s cybersecurity posture and dealing with constant threats, especially ransomware, places CISOs under extreme pressure. Coping with the demands is only possible if a cybersecurity strategy complemented by OSINT is integrated into technology platforms to deliver more timely and predictive insights about potential cyber risks facing the company and its supply chain. This strategy empowers CISOs to be prepared to proactively mitigate vulnerabilities.

KEYWORDS: open source security organizational resilience organizational risks OSINT ransomware

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Michael mclaughlin headshot

Michael McLaughlin is a strategic Intelligence Advisor to Fivecast. Image courtesy of McLaughlin

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Columns
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
  • The Most Influential People in Security 2025

    Security’s Most Influential People in Security 2025

    Security Magazine’s 2025 Most Influential People in...
    Most Influential People in Security
    By: Security Staff
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • critical event management
    Sponsored byEverbridge

    Why a Unified View Across IT, Continuity, and Security Makes or Breaks Crisis Response

  • Charlotte Star Room
    Sponsored byAMAROK

    In an Uncertain Economy, Security Is a Necessity - Not an Afterthought

  • Sureview screen
    Sponsored bySureView Systems

    The Evolution of Automation in the Command Center

Popular Stories

Red laptop

Security Leaders Discuss SitusAMC Cyberattack

Cybersecurity trends of 2025

3 Top Cybersecurity Trends from 2025

Cybersecurity predictions of 2026

5 Cybersecurity Predictions for 2026

Green code

Logitech Confirms Data Breach, Security Leaders Respond

Water faucet and cup

High Water Mark: CISA Shares Foundations for Effective Cybersecurity and Risk Management

Top Cybersecurity Leaders

Events

September 18, 2025

Security Under Fire: Insights on Active Shooter Preparedness and Recovery

ON DEMAND: In today’s complex threat environment, active shooter incidents demand swift, coordinated and well-informed responses.

January 14, 2026

Is Your Organization Prepared to Navigate Interconnected Threats in 2026?

The 2026 threat environment will be louder, faster, and more interconnected. The most pressing risks, from global political volatility to emerging tech disruptions, will challenge organizations to act amid ambiguity and protect credibility in an era of accelerating uncertainty.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • cyber security

    How CISOs can stay one step ahead of 2023’s risks, threats and attacks

    See More
  • incident-response-freepik1170x658v6.jpg

    A 3-step approach to cyber defense: Before, during and after a ransomware attack

    See More
  • people working together at conference table

    Benchmarking is the missing link to cyber resilience

    See More

Related Products

See More Products
  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

  • Physical Security and Safety: A Field Guide for the Practitioner

  • physical security.webp

    Physical Security Assessment Handbook An Insider’s Guide to Securing a Business

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing