Executive Summary
This study empirically evaluates the effectiveness of public Open-Source Intelligence (OSINT) feeds for critical infrastructure (CI) defense. Analyzing 54 confirmed CI cyberattacks and 12 null-control cases from 2010-2024, it categorizes OSINT sources into three operational profiles: precursor, disclosure-exposure, and broad-coverage. The research identifies optimal source portfolios for maximizing attack coverage and lead time.
Why It Matters
This document provides critical empirical evidence for defense and geopolitical analysts on which OSINT sources are most effective for anticipating and defending against cyberattacks on critical infrastructure, enabling better resource allocation and strategic intelligence gathering.
Key Takeaways
- Public OSINT sources can be empirically categorized into 'precursor,' 'disclosure-exposure,' and 'broad-coverage' profiles based on their effectiveness in signaling actual attacks versus general vulnerabilities.
- A portfolio of just two or three carefully selected OSINT sources can cover over 90% of confirmed critical infrastructure cyberattacks, significantly outperforming random selections.
- Many widely used sources for industrial control system defense are primarily 'disclosure-exposure' rather than 'precursor,' meaning they are better for patch management than anticipating attacks.
Strategic Relevance
This research offers a data-driven framework for optimizing OSINT collection and analysis for critical infrastructure protection. It directly informs strategic decisions on intelligence resource allocation, enhances early warning capabilities against cyber threats, and helps prioritize intelligence feeds to counter nation-state and cybercriminal activities targeting vital systems.