Skip to content
For UK businesses and MSPs

Public exposure checks (OSINT)
See what an attacker sees first.

Fig’s public exposure checks use open-source intelligence (OSINT) to examine information associated with your organisation, domains and brands. You receive findings with context and recommended next steps.

At a glance

Your engagement at a glance

What you receive

Relevant exposure findings, supporting source context and recommended investigative actions.

Your team’s part

Your technical and communications owners confirm relevance and coordinate the response.

Follow-up arrangements

Repeat monitoring, account investigation and takedown support are separate scopes.

A clearly defined scope. Public-source coverage is incomplete and changes over time. The review never includes unauthorised access or use of exposed credentials. Takedown services and continuous monitoring are outside this review and would require separate agreement.

For understanding your organisation’s public footprint. Discovery of an asset does not authorise a vulnerability scan or penetration test. Explore penetration testing.

Start with a scope discussion

We’ll agree a written proposal and obtain authorisation before the assessment begins.

Request an OSINT review
The scope

What do Fig public exposure checks cover?

Public exposure checks use open-source intelligence, also called OSINT, to examine information associated with agreed organisational names, domains and brands. The aim is to identify relevant exposure for investigation, not to access systems without permission.

Publicly accessible information

Look for exposed files and organisational information associated with the agreed domains and assets.

Credential exposure

Check for indications of exposed credentials within agreed, lawfully accessible sources. Findings require careful handling and validation.

Brand exposure

Look for relevant lookalike domains and other public indicators that may warrant investigation.

Assessment detail

How should you interpret an OSINT finding?

Separate the observation from the conclusion. Finding information associated with your organisation does not, by itself, prove an active threat or a compromised account. These distinctions help your team decide what to investigate.

Interpreting the relevance and age of public exposure findings
Evidence fieldWhat to recordUseful next step
Association confidenceConfirmed, uncertain or unrelated to the organisation, with the reason for that classification. A confirmed association does not establish malicious use.Confirm ownership before allocating investigation or excluding an unrelated name match.
Age and freshnessSource date, observation date and whether the information still describes the current environment. Historical material can have a confirmed association.Check whether an older asset, account or document remains relevant now.
Sensitivity and contextWhat the information reveals, its intended audience and any uncertainty about its significance.Ask the appropriate owner to determine whether publication is intentional or protective action is needed.
Action and ownershipThe person responsible, next action, dependencies and outstanding requests concerning third-party copies.Track action on the original and remaining copies separately; discovery does not guarantee removal.

A useful finding record includes the source, observation date, identifier involved, supporting context and reason for concern. Historical material can also have a confirmed association: age and confidence are separate attributes. The review concerns organisational public information such as indexed documents, domain/brand information and credential-exposure indicators in lawfully accessible sources. Source categories and any direct requests to public assets belong in the engagement scope; a public observation is not permission to scan or log in. Confirm ownership, reduce unintended exposure at the source, let authorised account owners protect affected accounts and track any third-party removal requests through the reporting channel.

When to book

A clearer view of your public exposure.

Understand what is visible, assess what matters and give the right teams a clear next step.

Visibility

Understand your public footprint

Identify information associated with agreed brands and domains that may be overlooked during an internal review. Assess relevance before acting on a finding.

Protection

Support brand and account protection

Use relevant lookalike-domain and credential-exposure findings to inform investigation and protective action. A suspicious domain is not, by itself, proof of malicious activity.

Response

Coordinate the right response

Give IT, security and communications teams a shared view of findings. Keep sensitive details restricted and decide who owns investigation, removal requests or account-protection actions.

Security benefits

Security benefits of public exposure checks

Find information your team may have overlooked

Public documents and indexed information can reveal details about an organisation’s systems or operations. Review the relevance and sensitivity of each finding before deciding whether publication is intentional or needs attention.

Put credential indicators into context

An exposed address or historical credential reference is a signal for investigation. Record the source, date and uncertainty, then let the authorised account owner assess protective action. A match alone does not show that an account is currently compromised.

Identify potential brand confusion

Lookalike domains may merit investigation where they could be confused with your organisation. Assess context and ownership before classifying a domain as malicious or requesting action; similarity is not evidence of abuse on its own.

Commercial value

The commercial value for your organisation

Support a more deliberate public presence

Review how the information associated with your organisation appears to outsiders. Findings can inform publication practices, document handling and coordination between marketing, IT and security teams.

Give response teams useful context

A report with the source, observation date and reason for concern makes investigation easier to assign. It also helps separate an action you control, such as removing your own file, from a request that depends on a third-party provider.

Set realistic expectations for brand protection

Use a defined review to decide whether further monitoring, takedown support or account investigation is needed. Those services require their own scope; discovery does not guarantee removal or prevent every impersonation attempt.

How it works

Your public exposure checks engagement

  1. Agree identifiers and boundaries

    Confirm the organisation names, domains and brands in scope, permitted sources and the handling of potentially sensitive information.

  2. Review public sources

    Examine agreed, lawfully accessible sources for relevant files, exposure indicators and lookalike domains. Source availability affects coverage.

  3. Assess relevance

    Distinguish potentially relevant findings from unrelated names or historical information. Record uncertainty rather than treating every match as a confirmed threat.

  4. Report securely

    Provide context and recommended next steps. Limit sensitive details to the people who need them and agree secure reporting arrangements.

  5. Investigate and follow up

    Your team validates findings and takes appropriate action. Takedowns, incident response and repeat checks are not included unless separately agreed.

Two colleagues reviewing findings together on a laptop at an office table

Work is authorised in writing before any assessment begins, and stays within the agreed scope.

Compare approaches

OSINT, vulnerability scanning or ongoing monitoring?

Related services answer different questions. Confirm which scope you are buying before you compare quotes.

Compare the purpose and scope of related approaches
ApproachWhat it tells youScope to confirm
Public exposure checks / OSINTExamines relevant organisational information in agreed public sources.Coverage depends on available sources and identifiers; findings may be historical or uncertain.
Vulnerability scanningActively checks authorised technical targets for known weaknesses.A separate scope; discovering an asset publicly does not authorise testing it.
Monitoring and takedown servicesRepeat observation or assistance with removal requests, where contracted.Neither continuous monitoring nor removal is included in a public exposure review by default.

Illustrative example, not a client case study

An old public document reveals internal operational details

How to read a finding: evidence, decision and next action
Source and observation
An indexed document on a domain associated with the organisation. Record its location and the date it was observed.
Association confidence
Confirmed by the domain owner; an unrelated name match would be excluded.
Age and sensitivity
The document is historical but still public. Its operational details need an owner’s review before determining whether exposure is intentional.
Owner and action
The content owner confirms the material, restricts the source where appropriate and coordinates any requests concerning third-party copies. Account owners handle any exposed secrets separately.
Remaining uncertainty
Record outstanding copies and removal requests. Removing the source does not prove that every copy disappeared or that an account was compromised.

This is a teaching example of a finding record, not an extract from a customer report or a promise of a particular report template.

Cost and preparation

What affects the scope and cost?

Organisation names, domains, brands, source coverage, review depth and reporting requirements affect the quote. Include subsidiaries or historical brands explicitly. A one-off review, repeat monitoring and takedown support are different scopes.

What to prepare for your enquiry

Provide the legal and trading names, current and legacy domains, brands and relevant subsidiaries. Identify who owns technical and communications responses and agree how sensitive findings will be shared. Do not send passwords or leaked data through the enquiry form.

Plan the engagement around your deadline

Allow for access preparation, the assessment, report delivery and your team’s remediation work. Confirm the delivery format, dates and any follow-up checks in your quote so each team knows when its input is needed.

A person planning an engagement with a notebook and laptop
Questions

Public exposure checks questions

Practical answers about scope, cost and what happens next.

Compare all six security services
What are public exposure checks?

Public exposure checks use open-source intelligence, also called OSINT, to examine information associated with agreed organisational names, domains and brands. The aim is to identify relevant exposure for investigation, not to access systems without permission.

Link to this answer
Does an exposed credential prove an account is compromised?

No. An exposure finding needs validation and context. It does not by itself prove that an account is currently accessible or has been misused. Your team should assess the finding and take proportionate protective action.

Link to this answer
Will you use leaked credentials to test access?

No. Identifying a possible exposure does not authorise logging in or trying credentials. The public exposure review does not include using exposed credentials to access accounts.

Link to this answer
Can you remove exposed information or lookalike domains?

Removal and takedown work is not included by default. Findings can support your investigation and any requests to the responsible provider, but removal cannot be guaranteed.

Link to this answer
Is this continuous dark web monitoring?

No. This is a scoped public exposure review using agreed sources. It does not imply complete coverage of private sources, criminal forums or ongoing monitoring.

Link to this answer
What does OSINT stand for?

OSINT means open-source intelligence: collecting and assessing information from publicly available sources. Fig’s public exposure checks apply this to agreed organisational names, domains and brands to identify relevant exposure for investigation.

Link to this answer
Can you guarantee that all exposed information will be found?

No. Search indexes, public sources and historical records are incomplete and change over time. The report should identify the sources, identifiers and review period so you can understand what the findings cover and where uncertainty remains.

Link to this answer
How much do public exposure checks cost?

Organisation names, domains, brands, source coverage, review depth and reporting requirements affect the quote. Include subsidiaries or historical brands explicitly. A one-off review, repeat monitoring and takedown support are different scopes.

Link to this answer
Does this service provide compliance certification?

No. Security testing and reviews can help identify gaps, but certification requires a separate assessment under the relevant scheme. Buying this service does not guarantee certification.

Link to this answer
Your next step

Choose the support you need.

Explore a different assessment, manage remediation or prepare for certification.

Related service

Vulnerability scanning

Automated checks of agreed websites and systems for known weaknesses, helping you prioritise what needs attention.

Explore

Related service

Penetration testing

A qualified tester attempts to exploit weaknesses in agreed applications, APIs or networks, with written authorisation. Includes a report, fix guidance and a retest of the findings.

Explore

Software

The Fig platform

Manage compliance gaps, remediation and supporting evidence.

Explore

Certification

Cyber Essentials

Explore certification options for your organisation.

Explore
Further reading

Understand the methods behind the review.

Hands using a laptop at a wooden desk
OWASP · Web Security Testing Guide

Search-engine discovery and information leakage

Explains how publicly indexed material can expose organisational and technical information.

Read the OWASP guide Independent technical guidance. Stock photograph for illustration.
Accountability

Working with Fig

Work with Fig directly or through your MSP. Your proposal identifies the contracting entity, assessment scope and delivery responsibilities.

The companies

Meet the companies behind Fig

See the entities, licences and people behind the platform and our assessments.

Explore

MSP partners

Security services for MSP partners

Offer these services under your own brand and retain the client relationship.

Explore

Published evidence

Company details and published evidence

Verify our company details, licences and the claims we make in public.

Explore

Let’s agree the right scope.

Tell us what you need from public exposure checks (osint), the systems involved and any deadline. We’ll discuss the options and provide a quote.

Request an OSINT review