Key takeaway

A defensible assessment connects each material finding to its source, uncertainty, a plausible scenario and a realistic safeguard — without bypassing controls or carrying out the attack.

01

The question an assessment should answer

A defensible assignment supports a decision: Which public information makes social engineering more credible? Which roles are exposed because of authority and visibility? Which publications reveal unnecessary detail about relationships or routines?

A finding matters only when it connects to a credible scenario, an affected role and a realistic safeguard. A general internet search or collection of embarrassing discoveries is not enough.

02

1. Define purpose, protected assets and exclusions

Before research begins, document the assignment, legitimate purpose, organisational units, roles, time period and protected assets. Scope can include public structures, domains, communication channels, locations, supplier relationships or time-bound changes.

Exclusions are equally important. They keep a bounded defensive review from turning into unrestricted research about people.

  • Which decision should the review support?
  • Which roles and information classes are in scope?
  • Which sources and methods are permitted?
  • Who may receive the results?
  • Which retention and deletion rules apply?
03

2. Define sources and collection limits

This model uses passive research in lawfully usable open sources: official websites, public documents, media pages, professional networks, public registers and generally accessible technical information.

Without separate written authorisation and review, it does not bypass logins, contact people under false identities, access private accounts, actively scan systems or purchase questionable datasets. Active testing requires a separate, explicit scope.

04

3. Verify individual findings

Publicly discoverable does not mean current or correct. Material findings retain their source, retrieval time and context and are checked against independent signals where possible.

A useful finding separates direct observation, professional assessment, remaining uncertainty and the conclusion that cannot responsibly be drawn. That prevents a namesake, stale page or isolated screenshot from becoming an unsupported certainty.

05

4. Connect information into plausible attack paths

Practical relevance often emerges from a chain: a project supplies context, a profile indicates authority, an event provides timing and a known supplier offers a credible identity to imitate.

Prioritisation should be qualitative: evidential strength, recency, usefulness in the scenario and potential impact. An opaque overall score would suggest precision that open-source evidence often cannot support.

  1. 01
    Context

    Which visible information establishes the scenario?

  2. 02
    Role

    Who could be approached credibly?

  3. 03
    Action

    Which approval, payment or disclosure would be requested?

  4. 04
    Control

    Which existing safeguard should interrupt the attempt?

06

5. Report outcomes and safeguards

A useful report contains an executive summary, agreed scope, prioritised scenarios, traceable sources and retrieval times, visible uncertainty, short- and medium-term measures and clear owners.

A safeguard is not automatically an instruction to remove information. Visibility may be necessary for recruitment, sales, leadership or media work. Call-backs through a known channel, dual approval, clear reporting routes or role-specific awareness are often stronger.

07

What the assessment does not do

A digital exposure assessment does not prove that an attack will occur, guarantee complete discovery or replace a penetration test, vulnerability scan, legal advice or data protection impact assessment.

It does not assess people through protected characteristics, make automated employment or security decisions, or provide continuous monitoring unless separately agreed. Necessity, purpose limitation and data minimisation remain part of the assignment.

Decision check

Questions before you act

  1. 01

    Which decision or safeguard should the assessment support?

  2. 02

    Which units, roles and time periods are in scope?

  3. 03

    Which sources and methods are expressly authorised?

  4. 04

    Who may see findings and approve action?

  5. 05

    Which retention and deletion rules apply?

Sources

Primary and authoritative references

  1. Reconnaissance, TA0043MITRE ATT&CK
  2. Gather Victim Organization Information, T1591MITRE ATT&CK
  3. NIST SP 800-30 Rev. 1: Guide for Conducting Risk AssessmentsNational Institute of Standards and Technology
  4. External Attack Surface Management buyer’s guideUK National Cyber Security Centre
  5. General Data Protection Regulation — Articles 5 and 6EUR-Lex
Apply this perspective

Discuss a digital exposure assessment

Define the defensive perspective, scope, permitted sources and intended outcome before research begins.

View service