Back to Search Start Over

Open-source intelligence for risk assessment

Authors :
Francesco Cappa
Darren Hayes
Source :
Business Horizons. 61:689-697
Publication Year :
2018
Publisher :
Elsevier BV, 2018.

Abstract

Advances in information technology (IT) have prompted tremendous growth in security issues for companies. Increasingly, cyberattacks represent a threat to companies and national security; to prevent them, firms should routinely perform risk assessments of their IT infrastructure and employees. This article highlights the importance of open-source intelligence (OSINT) tools in conducting risk assessments to prevent cyberattacks. More specifically, we performed a vulnerability assessment on the critical infrastructure of a company operating on the U.S. electrical grid. We successfully profiled the company’s network software, hardware, and key IT personnel—using OSINT—and detailed potential vulnerabilities associated with these findings. The results of our study provide empirical evidence for the efficacy of OSINT in improving the security posture of organizations. Our research findings were subsequently used to produce tactical and strategic recommendations for organizations based on the use of OSINT to identify vulnerabilities, mitigate risks, and formulate more robust security policies to prevent cyberattacks.

Details

ISSN :
00076813
Volume :
61
Database :
OpenAIRE
Journal :
Business Horizons
Accession number :
edsair.doi.dedup.....c0739ab8ed8e9a0f0d87a8aaf3d91c20