02 · Workshops & Training

Understand the method.
Apply it responsibly.

Interactive formats for people who research, verify and document open information or translate it into defensible security decisions.

Half-day to modularSmall groupsHands-onAvailable internationally

Decision guide

In 30 seconds: is a workshop right?

01

What is it?

A modular learning format for teams and leaders to practice OSINT-based decision making and information hygiene.

02

For whom?

Security teams, communication teams, HR, leadership circles and teams with operational risk responsibility.

03

Which problem is addressed?

Unclear confidence in decisions from open sources and weak handover between training and daily operations.

04

What happens concretely?

Audience-based learning objectives, practical exercises, feedback and measurable post-session transfer actions.

05

When does it fit?

When you need sustained transfer to role-based teams and practical methods the participants can use immediately.

06

Limits

No promises of instant change, no uncontrolled broad monitoring, and no sensitive target monitoring without written scope.

07

Next step

Define participants, desired outcome and available time; then we match scope, format and depth.

Training portfolio

From foundations to organisational capability.

Exercises, depth and tools are aligned with participants' roles, experience and permissible application context.

01

OSINT Fundamentals

Build a reliable foundation for professional open-source research.

Content: Research planning, search strategies, source assessment, documentation, legal and ethical guardrails.

Outcome: Research with more structure, challenge sources and document results reproducibly.

Duration
1 day
Group
8–16 people
02

Operational OSINT

Think OSINT through from the intelligence requirement to the final assessment.

Content: Scoping, methodology, operational context, analysis, quality assurance and reporting.

Outcome: Plan research, test hypotheses and derive defensible findings.

Duration
1–3 days
Group
8–14 people
03

Verification Lab

Verify digital content systematically and transparently.

Content: Images, video, profiles, websites, geolocation, chronology and source chains.

Outcome: Apply verification steps, communicate uncertainty and produce verification reports.

Duration
½–1 day
Group
6–14 people
04

OSINT for Corporate Security

Use open sources for early warning and situational assessment.

Content: Actors, mobilisation, events, locations, reputational and security risks.

Outcome: Prioritise relevant signals, enrich the situational picture and assess escalation coherently.

Duration
1–2 days
Group
8–16 people
05

Digital Exposure Workshop

Understand the organisation's publicly visible attack surface.

Content: Employees, executives, locations, suppliers, routines and digital traces.

Outcome: Map exposure, prioritise risk and define proportionate measures.

Duration
½–1 day
Group
6–12 people
06

OSINT Capability Building

Turn individual expertise into roles, processes and quality standards.

Content: Governance, operating model, workflows, documentation, training concept and success measures.

Outcome: Develop a target model, clarify accountability and create a realistic roadmap.

Duration
Modular
Group
Core team of 4–10
07

Tabletop Exercise: Deepfake or Social-Engineering Incident

Test decision-making under realistic time and information pressure.

Content: Scenario, injects, roles, escalation paths, communication decisions and a facilitated debrief.

Outcome: Validate responsibilities, identify decision gaps and record concrete improvements.

Duration
Half-day or scenario-based
Group
Leadership, communications & security
08

Train-the-Trainer / OSINT Champions

Enable internal multipliers to deliver OSINT and awareness content safely and consistently.

Content: Learning design, exercises, facilitation, guidance, quality criteria and responsible boundaries.

Outcome: Run internal formats confidently, scale knowledge and preserve common standards.

Duration
Modular
Group
6–12 multipliers

Learning design

Practise realistically. Act responsibly.

Exercises use authorised, synthetic or controlled examples. The focus is on reproducible methods, sound documentation and explicit boundaries.

Research planningSource criticismVerificationDocumentationEthics & law

Planning your OSINT training.

These topics are examples, not a fixed catalogue. Other questions and topics can be agreed. We discuss prior knowledge, group size, learning goals and available time before the workshop.

The briefing also covers your working environment, required equipment and suitable on-site, online or hybrid delivery.

Since September 2026, I have been a freelance lecturer in OSINT and digital investigations at VSW, the business security association for Hessen, Rheinland-Pfalz and Saarland. I teach the “Open Source Intelligence (OSINT)” module of its IHK certificate course “Koordinator:in – Betriebliche Ermittlungen & Interne Untersuchungen”. My teaching covers internet, person and company research, source assessment, image verification and the preservation of digital evidence.

Next step

A workshop built around the assignment.

Together we define learning objectives, experience level, permissible tools and practical transfer.

Design a workshop