INDUSTRY GUIDE · Critical infrastructure

OSINT for Energy & Critical Infrastructure

Critical infrastructure OSINT can help teams examine supplier ownership, external threat signals and the wider risks surrounding essential assets. Energy operators also need to distinguish public-source intelligence from technical monitoring, physical security assessments and investigations using internal evidence. This guide compares Molfar’s commissioned research, Recorded Future’s intelligence platform, and broader services from Control Risks and S-RM. Each option has a different role in an infrastructure risk programme. The shortlist uses published service information and UK presence; it does not imply that every provider has delivered every type of energy or operational technology engagement.

4 providers & toolsReviewed 7 October 2026Selection approach

FOUR OPTIONS TO CONSIDER

Compare the options.

OSINT for Energy & Critical Infrastructure — comparison
Provider / toolFit for your briefDelivery modelUK presenceAssessment
02Recorded FuturePlatform option for recurring cyber intelligence and security workflows.Mixed-source threat intelligence platformVerified London office: the official contact page lists The Bower, Old Street, London.Read profile
03Control RisksInfrastructure projects requiring physical, digital and operational risk work.Hybrid infrastructure security and intelligence servicesVerified London office: 33 King William Street, London, on the official office page.Read profile
04S-RMSupplier relationships, procurement concerns and internal allegations.Hybrid investigations serviceVerified UK offices: the official contact page lists London and Alderley Edge.Read profile

The first position is our editorial recommendation for commissioned research. Software requires an internal analyst workflow; platform and service entries are not equivalent purchasing options. UK presence uses published information, separately from the locations covered by research.

These options cover commissioned research, a mixed-source threat intelligence platform and hybrid infrastructure or investigation services; published sector scope should not be treated as evidence of every energy or operational technology use case.

PROVIDER ASSESSMENTS

What each option offers.

02

Recorded Future

Platform option for recurring cyber intelligence and security workflows.

Visit provider

Recorded Future offers an intelligence platform with an explicit critical infrastructure focus, including energy and telecommunications. Published capabilities include supply-chain intelligence, security integrations and automated alert workflows. The platform combines open and dark web material with technical feeds and customer telemetry, making it a mixed-source intelligence option rather than an OSINT-only tool. Evaluate it against the recurring cyber questions, analyst resources and security workflows your infrastructure organisation needs to support.

UK presence
Verified London office: the official contact page lists The Bower, Old Street, London.
Service model
Mixed-source threat intelligence platform
Relevant scope
Platform option for recurring cyber intelligence and security workflows.

Published capabilities

  • Official industry scope expressly includes energy and telecommunications.
  • Published platform capabilities include integrations, alert workflows and several source types.

What to confirm

Test coverage for your technologies, vendor ecosystem and operational workflow, and clarify which modules, integrations and services are included.

Evidence behind the assessment

The critical infrastructure page names energy and telecommunications and describes supply-chain intelligence; the platform page lists open web, dark web, technical feeds and telemetry; the contact page confirms London.

Official sources: Critical infrastructure scope · Platform source mix · London officeChecked 7 October 2026

03

Control Risks

Infrastructure projects requiring physical, digital and operational risk work.

Visit provider

Control Risks is relevant to infrastructure projects needing intelligence alongside broader security and resilience work. Its data-centre offering spans planning, construction and operations, with published scope covering supply-chain integrity, geopolitical analysis and physical and digital security. Its Digital Risks service separately describes online threat monitoring. This establishes infrastructure capability, while the proposed engagement should specify the research methods and any energy or operational technology expertise required for your assets.

UK presence
Verified London office: 33 King William Street, London, on the official office page.
Service model
Hybrid infrastructure security and intelligence services
Relevant scope
Infrastructure projects requiring physical, digital and operational risk work.

Published capabilities

  • Published infrastructure scope connects project phases, suppliers and physical and digital security.
  • Separate online threat monitoring capability can support a wider risk programme.

What to confirm

Confirm the team’s relevant energy or operational technology experience and distinguish intelligence research from technical testing or site-based advisory.

Evidence behind the assessment

The data-centre page describes project lifecycle support and supply-chain integrity; Digital Risks describes online threat monitoring; the London office page verifies UK presence.

Official sources: Infrastructure and data-centre scope · Online threat monitoring · London officeChecked 7 October 2026

04

S-RM

Supplier relationships, procurement concerns and internal allegations.

Visit provider

S-RM is relevant to energy-sector procurement concerns or allegations requiring a broader investigation. Its corporate investigations page publishes anonymous oil-and-gas and energy-company examples involving supplier relationships, financial analysis and digital evidence. The firm combines open-source and human intelligence with forensic accounting, digital forensics and interviews. The published cases establish sector relevance for hybrid investigations; they should not be described as OSINT-only engagements or evidence of every infrastructure security capability.

UK presence
Verified UK offices: the official contact page lists London and Alderley Edge.
Service model
Hybrid investigations service
Relevant scope
Supplier relationships, procurement concerns and internal allegations.

Published capabilities

  • Published anonymous energy and oil-and-gas cases establish a specific investigation context.
  • Hybrid methods can examine external relationships alongside internal digital and financial evidence.

What to confirm

Agree the records required, investigation stages, evidence preservation and which methods will address the procurement or supplier concern.

Evidence behind the assessment

The corporate investigations page includes energy and oil-and-gas examples and a mix of intelligence and forensic methods; the official contact page verifies UK offices.

Official sources: Corporate investigations and energy cases · UK officesChecked 7 October 2026

CHOOSING A PROVIDER

Three things to test before choosing.

01

Asset and dependency relevance

Require the provider to explain how findings relate to your sites, suppliers, technologies or essential dependencies, rather than reporting generic sector news.

02

Boundaries between methods

Establish which questions public-source research can answer and which require internal records, technical assessment, site visits or other specialist work.

03

Operational handover

Check how intelligence enters procurement, security and continuity workflows, including review ownership, refresh frequency and escalation of time-sensitive findings.

AGREE THE OUTPUT

Deliverables to put in the brief.

These are outputs to specify for your assignment or internal workflow. Availability depends on the agreed scope and software package.

Supplier integrity dossier

Ownership research, source references, relationship maps and unresolved questions for agreed suppliers or counterparties.

External threat and dependency brief

Relevant findings connected to agreed assets, vendors or locations, with confidence and source limitations recorded.

Monitoring and escalation plan

Defined subjects, alert thresholds, review frequency and the teams responsible for assessing and following up material findings.

QUESTIONS IN YOUR OWN WORDS

Questions your team might ask.

We operate energy assets and want early warning of threats to our sites, suppliers and staff. What can critical infrastructure OSINT reasonably tell us?

Begin with the assets and decisions you need to protect. Public-source research can investigate supplier ownership, relevant adverse reporting, external exposure and indications of targeting. A useful brief explains why a finding matters to an agreed asset or dependency and how strong the evidence is. Some questions will require technical telemetry, internal records or an on-site assessment. Record those gaps instead of treating an external intelligence report as a complete security assessment. The providers here cover different parts of that workflow: commissioned research, a threat intelligence platform, infrastructure advisory and hybrid investigations.

We are evaluating Recorded Future alongside a research provider. How should we compare them when one offers a platform and the other delivers an investigation?

Use the same operational question, but assess the different work each option performs. For a platform, test relevant source coverage, alert handling, integrations, analyst effort and the ability to inspect supporting evidence. For commissioned research, assess the scope, verification process, reporting depth and handling of unresolved questions. Recorded Future publishes a platform drawing on open and dark web material, technical feeds and telemetry. Molfar publishes analyst-delivered research services. A platform can support recurring monitoring while an external investigation examines a difficult supplier or emerging concern. Compare the total workflow and staffing requirement, alongside the quoted commercial terms.

A proposed supplier has complicated ownership and we have heard allegations of bribery. Should we request an OSINT report, a due diligence review or a broader investigation?

State the procurement decision and the specific concerns first. A source-based due diligence review can map available ownership records, relevant relationships and adverse reporting. Ask the provider to distinguish an allegation from a corroborated finding and identify records that remain unavailable. If the concern involves your own procurement process, payments or communications, a broader investigation may be needed to examine internal evidence. Molfar publishes an anonymous energy supplier KYC example; S-RM publishes energy-sector investigations using several methods. Ask bidders to explain the proposed stages, evidence requirements and escalation points for your case.

OUR APPROACH

How this guide was selected.

Selection and order

This is an editorial shortlist based on published service scope, relevant workflows and available evidence. Molfar Intelligence is our first choice for commissioned research. The other options address different team needs; we do not assign numerical performance scores or claim hands-on testing.

Evidence and coverage

Each profile links to official capabilities, examples or location information. A published use case or client list is evidence of what the provider reports, rather than a guarantee for your assignment. Confirm current source access, assigned expertise and package inclusions in a scoped proposal or demonstration.