The service

Target analysis & open source research on employees

We identify which employees, due to their role, responsibilities, visibility, or access, present an attractive target for external actors, and what an external actor can do with that information.

6
Research areas
5
Steps in the process
100%
Public sources
In brief

The human entry point, mapped

Through specialized open source research we map what information about your key personnel is publicly available, what risks arise, and how this information can be used for targeted approaches.

The results provide insight into potential risks for both the individual employee and the organization, and support targeted measures to strengthen your organization's resilience, safety, and continuity.

The investigation answers

  • Which employees are an attractive target due to their role?
  • What information about them is publicly available?
  • What risks arise from that information?
  • How could that information be used against them?
  • Which measures reduce the risk most effectively?
Step 1 · Map it

What we investigate

Public sources paint a surprisingly complete picture. We map it in a structured, traceable way.

For executives and other key personnel, the investigation can, on request, also extend to the publicly visible information surrounding their immediate circle. The line between work and private life has blurred online. That is exactly where adversaries look for a way in.

Identity & role

Name, job title, area of responsibility, and position within the organization, often explicitly visible on public profiles and the company website.

Network & relationships

Managers, colleagues, professional contacts, and, where publicly visible, personal relationships that could serve as leverage.

Locations & routines

Home city, work locations, recurring patterns, and attendance at conferences, lectures, or events, derivable from public posts.

Contact details

Business and personal email addresses and phone numbers, including from past data breaches in which the individual appears.

Visual material

Photos and videos in which the person is recognizable, including metadata and backgrounds that reveal location or context.

Publications & statements

Interviews, presentations, press releases, and public positions that give an actor insight into character, interests, and points of approach.

Step 2 · Assess risks

How public information is used against people

We translate findings into concrete exploitation scenarios, making clear what you are defending against.

Influence

Targeted influence

Knowledge of interests, relationships, and pressure points makes it possible to subtly steer decision-making or put a person under pressure.

Intimidation · threats

Intimidation & threats

Residential or location data, routines, or information about family members can be used to instill fear, coerce behavior, or physically threaten a person and those closest to them.

Social engineering

Social engineering

Details about role, colleagues, and projects provide the material for a convincing story, the basis of phishing and CEO fraud.

Targeted approach

Other targeted approaches

From approaching via a fake identity to exploiting access rights: one person can be the entry point to the entire organization.

Special attention

Executives, key personnel and their immediate circle

The physical security around top executives is often well arranged. The digital back door, the publicly visible information about an executive and their family, too often remains open. That is exactly where adversaries look for a way in.

Why the top is a target

Adversaries avoid well-protected systems and focus on people. When an executive's corporate environment is watertight, attention shifts to the private sphere and the family, where security is often less tight.

What is publicly visible

Routines, home and stay locations, holiday destinations, the children's school, a sports club, a running app, or the name of a pet. Seemingly harmless information together forms a blueprint for anyone with bad intentions.

The risks this creates

This information is the basis for targeted social engineering, extortion, intimidation, and in the most extreme case physical threats against the executive or their family.

How we address it

We map this publicly visible footprint defensively, through the attacker's eyes and using public sources only, within the boundaries of the GDPR. This allows the information to be shielded before it can be misused.

How online information turns into physical and digital threats: view the case studies

Step 3 · Result

A report you can act on

No raw data dump, a structured, readable insight directly translatable into policy and measures.

Overview per role profile

What is publicly findable about the investigated person, structured by source category.

Risk assessment

Which threats arise from the findings, prioritized by severity and likelihood.

Exploitation scenarios

How an actor would concretely use the information: from phishing to intimidation and CEO fraud.

Recommendations

Targeted, feasible measures to reduce the risk, prioritized and immediately actionable.

Verbal debrief

A confidential discussion of the findings, with room for questions and next steps.

For whom

The report serves both the individual employee and the organization (policy, security, and continuity).

HR & Leadership Security / CISO Board & executives
The process

How an investigation works

Intake & scope

In a confidential conversation we determine the research question, the roles and individuals to be investigated, and the desired level of depth.

Open source research

We systematically collect all publicly available information per profile, following a fixed, traceable methodology.

Analysis & assessment

We identify the risks and develop the possible exploitation scenarios, taking into account the specific context of your organization.

Report

You receive a clear, confidential report with findings, risk assessment, and prioritized recommendations.

Debrief & follow-up

We walk through the results and can assist with implementing measures and periodic repetition.

Public sources only, legal & GDPR-compliant

CI-IT works exclusively with publicly available information and operates within the applicable legal framework, including GDPR. Findings are treated confidentially and shared exclusively with the client. The purpose is defensive: knowing what an outsider sees in order to protect your people.

Start with insight into your most vulnerable roles

In a no-obligation consultation we determine together where the investigation delivers the most value.

Schedule intake