Back to Resources
The OSINT Standards Gap: Why Open-Source Intelligence Must Professionalise Further
OSINT

The OSINT Standards Gap: Why Open-Source Intelligence Must Professionalise Further

Electronic evidence is now routine in most investigations, and OSINT increasingly guides where investigators look before a formal evidence request is ever made. But the real problem is not speed - it is trust. Drawing on the Europol/Eurojust SIRIUS report, the EU e-Evidence package and NATO's doctrinal evolution, The Coalition of Cyber Investigators argues that OSINT must professionalise further, and sets out eight areas a globally recognised OSINT standard should cover.

Paul Wright & Neal Ysart28 August 202614 min read
Share

Electronic evidence is no longer a specialist area. It is now a routine part of most investigations.

Messages, emails, app chats, cloud records, cryptocurrency exchange data, social media posts, domain records, leaked infrastructure clues, archived pages, payment trails: these are no longer occasional extras. They are often critical to an investigation, yet the systems that support their use are under pressure.

The SIRIUS Electronic Evidence Situation Report from Europol and Eurojust makes that pressure very clear. Digital data and electronic evidence are now inseparable from criminal investigations and prosecutions, while authorities still face serious problems around speed, jurisdiction, technical access, preservation and legal process. Eurojust's work on the EU Electronic Evidence legislative package makes the same point from another angle: evidence is often held by service providers outside the jurisdiction of the investigating authority, sometimes in foreign, shifting or unknown locations.

That is an OSINT problem too since intelligence increasingly precedes a formal evidence request. OSINT helps investigators decide where to look, which account matters, which provider holds relevant data, whether a threat is credible, whether a wallet cluster is worth examining, or whether a person, company, server, advert, username or domain is part of the same pattern.

In other words, OSINT frequently guides the initial direction of an investigation, but weak or unreliable findings can compromise later work.

THE PRESSURE IS BUILDING

The SIRIUS report describes an electronic evidence landscape that is getting heavier, faster and more complex. More than half of criminal investigations now involve requests for cross-border access to electronic evidence, and the number of data requests has grown sharply compared with 2018. Emergency requests are also rising with cryptocurrency exchanges emerging as one of the most frequently contacted types of providers.

That last point matters more than it may first appear. Crypto-investigations are rarely clean, linear affairs. They involve exchanges, wallets, mixers, scams, phishing infrastructure, social engineering, fake investment platforms and victims spread across borders. The trail can be public and opaque at the same time. You can see the transaction, but not always the person. You can see the domain, but not always the operator. You can see the boast, the advert, the Telegram post, and the cloned website. But what does it all mean – how does an investigator start to build a picture from multiple fragments of information that often appear unconnected? OSINT can add real value by helping provide context and insights to enable an investigator to join the dots.

Judicial authorities also face another kind of pressure. Existing cooperation mechanisms are often seen as slow and procedurally complex, and delays can lead to the loss of critical evidence. Service providers are under pressure too, particularly as the volume of emergency requests increases.

The EU e-Evidence package is intended to improve parts of this system by making cross-border access to electronic evidence more robust, harmonised and streamlined. That would be a welcome improvement but it does not remove the need for good judgement before the request is made. A faster mechanism is only useful if the intelligence behind it and the process used to gather it are sound.

OSINT IS NOT JUST "FINDING THINGS ONLINE" ANYMORE

There is still a stubborn myth that OSINT is basically advanced Googling where a few search operators, a social media pivot, maybe a WHOIS lookup, or a breach check is all you need. That view is outdated. Worse, it is dangerous.

Modern OSINT is now woven into cybercrime investigations, fraud inquiries, safeguarding, litigation, sanctions work, asset tracing, corporate intelligence, hostile state activity, disinformation analysis and internal investigations. It touches people's livelihoods and sometimes their liberty. It can help prevent harm. However, it can also create harm if handled carelessly.

The Coalition of Cyber Investigators captures this wider reality in its own description of OSINT and cybercrime advisory work. It presents itself as a global think tank focused on investigations, cybercrime, and OSINT, combining research, advisory services, training, policy development, and procedural frameworks across multiple jurisdictions.

That blend is important. OSINT is not a bag of tricks anymore. It is becoming a professional discipline, and it needs to develop accordingly. The Coalition's article, The Evolution of Modern Investigations: AI, OSINT and the Cross-Border Intelligence Challenge, points to the direction of travel: AI-driven tools, multilingual research, crowdsourced espionage, local context, and the continued importance of human judgement. That last phrase, human judgement, is critical and should be uppermost in an investigator's mind: increasingly powerful investigative tools require more careful and precise judgement.

THE REAL PROBLEM IS NOT SPEED. IT IS TRUST.

Investigators are not short of tools. There are platforms for blockchain analytics, social media monitoring, leaked credential searches, domain enrichment, dark web monitoring, image verification, corporate records, vessel tracking, aviation data, litigation searches, sanctions screening and more.

Some are excellent. Some are overmarketed. Some are black boxes that provide limited transparency about how their findings are produced.

“The real problem is not speed. It is trust.”

The problem is not that OSINT cannot identify information. The issue is whether the information can be trusted, explained, reproduced, preserved and ultimately withstand scrutiny.

A screenshot without context is fragile. A username match without corroboration is risky. A tool-generated "likely match" without a confidence explanation is not a conclusion. An AI summary of online findings, however fluent and compelling, is not evidence. It might be useful or even brilliant, but it might also be wrong in a very polished way. The key concern is that often, OSINT can look convincing, before it has been shown to be reliable.

WHY STANDARDS MATTER

One of the common arguments against standards is that it could stifle investigative creativity and ingenuity. This is not the case. Globally recognised OSINT standards would provide a framework within which practitioners could operate consistently, ethically and in a compliant manner, regardless of their jurisdiction.

Globally agreed standards would help answer basic but essential questions:

QuestionWhy it matters
What was collected?The source material must be identifiable and reviewable.
When was it observed?Online material changes, disappears, or is edited.
How was it preserved?Screenshots alone may not be enough.
What is fact and what is inference?Decision-makers need to know the difference.
How confident is the assessment?Weak signals should not be dressed up as certainty.
What legal or ethical limits applied?Publicly accessible does not automatically mean freely usable.
Can another competent person understand the method?Repeatability is central to defensibility.

This is not bureaucracy for its own sake. It is the difference between intelligence that helps and intelligence that contaminates.

A useful example that bridges the argument from "standards are necessary" to "what should those standards actually cover?" comes from the North Atlantic Treaty Organisation's (NATO) own doctrinal evolution. Research examining The NATO Evolving Landscape in OSINT describes how OSINT has moved from preliminary guidance in the 2001 NATO OSINT Handbook, through its recognition as a primary collection discipline, to its treatment as an independent intelligence collection discipline. The report notes that NATO's formalisation of OSINT brought "standardised procedures, dedicated resources and a clearer mandate" across the Alliance, and sets out recommended tactics, techniques and procedures for a standardised OSINT process at the operational level.

That is important but limited: these are primarily NATO joint command and headquarters guidelines, not a global professional standard for law enforcement, private investigators, journalists, lawyers, NGOs, corporations and courts. The NATO example therefore strengthens the case for a broader framework.

If OSINT can be standardised within a military alliance, the wider investigative community can and should develop shared standards for preservation, verification, attribution, reporting, legality, AI use, and professional competence.

While some see standards as frustrating because they may appear to slow an investigation and require questions to be answered before a decision is made, that extra check or safeguard is often what stops a bad conclusion from becoming a formal but incorrect finding.

A GLOBAL STANDARD SHOULD COVER MORE THAN TECHNIQUE

A meaningful OSINT standard should not simply be a static checklist of recommended tools that practitioners are expected to use. Tools are constantly changing. Platforms change their interfaces, APIs can be discontinued, privacy settings shift, archives break, usernames are recycled, AI-generated personas multiply, and entire communities can migrate from one platform to another almost overnight. OSINT can be dynamic in nature so any effective standard must be flexible enough to accommodate change.

The NATO article also reinforces a point that should sit at the centre of any global OSINT standards debate: OSINT must be integrated into the intelligence cycle, not bolted on at the end as a colourful appendix. NATO describes OSINT as contributing to the collection, processing, exploitation, and dissemination, and as capable of bridging classified intelligence and publicly available information. That framing is valuable because it moves OSINT away from isolated discovery and towards more disciplined intelligence production. Standards should therefore govern not only what an investigator finds, but how that material is tasked, collected, processed, analysed, disseminated and reviewed.

The standard should focus on principles, competence and documentation. It should cover at least eight significant areas.

1. Lawful Purpose and Proportionality

Every OSINT task should begin with a clear purpose. What is the question? Why is OSINT appropriate? Who authorised the work? What are the limits?

This matters because OSINT often raises difficult legal and ethical questions. The information may be publicly accessible, but the subject may still have privacy rights. The data may be easy to collect, but disproportionate to the task. The investigator may be under pressure, but needs to recognise that urgency does not erase legality.

A global standard should require practitioners to record the mandate, scope, and legal basis for their work, and this is where the NATO article is also useful, as it does not treat OSINT as a law-free zone. It recognises that legal and ethical compliance, including privacy standards, remain central when using publicly available information.

That point deserves emphasis.

Public access is not the same as unrestricted use. A person may post information openly, a platform may expose metadata, or a website may leak useful clues, but investigators still need a lawful purpose, a proportionate method and a defensible reason for collecting, retaining and sharing what they find.

2. Preservation and Continuity

Online evidence can be fragile and dynamic. A post can vanish. A profile can change. A website can be edited. A crypto scam page can disappear and return under another domain. A cached page can become the only trace of something important. OSINT therefore needs preservation discipline at its core.

At a minimum, practitioners should record source URLs, timestamps, access conditions, capture methods, relevant metadata and contextual material. Where appropriate, they should use hashing, structured evidence logs and secure, controlled storage. They should also distinguish between viewing, collecting, downloading and processing.

That distinction matters. Especially when dealing with leaked, hacked, harmful or sensitive material.

3. Verification and Corroboration

OSINT should be allergic to single-source certainty. One signal may suggest. Two may support. Three may still mislead. An experienced investigator will aim for as much verification as is possible.

Standards should also require investigators to separate observed facts from interpretations. For example, an investigator may confirm that a profile exists, a domain resolved to an IP address at a specific time, a wallet received funds, or a photograph appeared on a public page. These are observations.

However, identity, control, intent and culpability are usually inferences or conclusions drawn from those observations and require additional evidence before they can be treated as established facts. This distinction matters most when a case is moving quickly and there is pressure to reach a conclusion.

4. Attribution Discipline

Attribution is where OSINT can do serious good and go seriously wrong.

A shared username does not prove identity. A reused profile picture does not prove control. A domain registration email may be historical, false, compromised or privacy-protected. A wallet interaction does not necessarily prove ownership, and a phone number on a scam page may belong to the scammer, a mule, a victim, or someone entirely unrelated.

Standards should require careful language.

  • "Associated with" is not the same as "controlled by."
  • "Linked to" is not the same as "owned by."
  • "Consistent with" is not the same as "proves."

These distinctions matter because more precise language helps investigators avoid presenting weak connections as established facts.

5. Tool and AI Transparency

AI has changed the texture of OSINT. It can translate, cluster, summarise, classify, detect patterns and speed up repetitive work. It can also hallucinate, flatten nuances and create a false sense of completeness.

The Coalition of Cyber Investigators' discussion of AI, OSINT and cross-border intelligence challenges is relevant here, particularly its emphasis on local context and human judgement in technology-enabled investigations.

A global OSINT standard should require practitioners to document the use of AI-assisted tools. Not every keystroke needs to be disclosed, but if an automated system shaped the finding, ranked the lead, generated the link analysis, translated critical material or summarised evidence, that should be recorded and reviewed.

AI can assist the investigator, but it should not become the investigator.

“AI can assist the investigator, but it should not become the investigator.”

6. Language Assurance, AI Platforms and Intelligence Grading

The NATO article also opens the door to a more practical standards issue: multilingual assurance.

It highlights the importance of multilingual research, local context, training, interoperability, legal and ethical compliance, and standardised OSINT processes. In cross-border investigations, translation is not merely an administrative step; it can alter meaning, intent and risk assessment. Tools and workflows such as GAI Translate and a Safe Language Verifier (SLV) capability could provide a formal assurance framework for multilingual intelligence before information is published, distributed or relied upon. Crucially, this would not mean claiming that an AI translation model itself is certified.

The assurance would apply to the workflow: defined linguistic, terminology, traceability and quality controls around the translation process. Combined with AI-powered OSINT platforms such as Tesari AI, which help analysts collect, structure, analyse and interpret open-source information more efficiently, this points to a broader requirement for source traceability, auditability, human review and clear confidence language. A global OSINT standard should also distinguish intelligence grading from intelligence classification: grading explains reliability and confidence, while classification governs sensitivity, access and dissemination.

7. Reporting That Non-Specialists Can Actually Read

A strong OSINT report should be understandable to readers without specialist platform knowledge.

Judges, lawyers, executives, safeguarding leads, compliance teams and investigators from other disciplines need to understand what was found, why it matters and how reliable it is. That means reports should be structured, plain and explanatory.

Good reporting should clearly distinguish between observations, context, inferences, assessments and limitations:

  • Observation "The account posted this message on this date."
  • Context "The account previously used the same handle on another platform."
  • Inference "The two accounts may be operated by the same person."
  • Assessment "There is moderate confidence that the accounts are connected."
  • Limitation "No independent identity confirmation was found."

This approach makes clear what was observed, what was inferred and what remains uncertain.

8. Training and Competence

The SIRIUS report identifies a need for enhanced training to help law enforcement keep pace with the evolving landscape of electronic evidence. OSINT needs the same approach and the NATO report identifies a training gap and recommends programmes for OSINT professionals to improve standardisation, knowledge and skills. That point is equally applicable outside a military setting. The wider OSINT community needs a structured professional development pathway that extends beyond tool recommendations.

Training should include legal and procedural awareness, ethics, data protection and privacy, digital preservation, source evaluation and verification. It should also build core analytical skills in attribution, platform mechanics, AI limitations, trauma-aware handling of harmful material, report writing and peer review.

The Coalition of Cyber Investigators' OSINT advisory work, including training and the development of methodologies, policies and procedures, reflects this broader professional need.

Professional OSINT depends on recognising when a tool or technique fails to provide sufficient evidence or adequate evidential safeguards.

THE E-EVIDENCE ERA RAISES THE STAKES

The EU e-Evidence package is a major development which aims to reduce friction in cross-border access to electronic evidence. But there is a catch. Faster access can amplify both good and bad investigative decisions.

If OSINT identifies the right provider, frames the right preservation request, highlights the right emergency risk and supports proportionate action, it can make the whole system work better.

However, if an investigator relying on OSINT misattributes an account, misunderstands a platform artefact, overlooks jurisdictional context, or turns a weak lead into a confident claim, it can quickly push everyone down the wrong path.

That should make the OSINT community pause for reflection. The discipline is moving into spaces where its outputs influence formal legal processes, private-sector decision-making, threat disruption, litigation strategy, and public safety decisions. It is now at the stage where clear, globally accepted standards are long overdue.

Another useful observation from the NATO report is that OSINT can help bridge classified intelligence and publicly available information. That bridge is increasingly important. In cybercrime, fraud, sanctions evasion and crisis response, public data can often be shared more easily than classified or sensitive information. OSINT can help different organisations build a shared picture without exposing protected sources. But that only works if the OSINT itself is reliable, properly sourced and clearly distinguished from speculation.

WHAT GLOBAL OSINT STANDARDS COULD LOOK LIKE

A practical standards framework should be usable under pressure. No one needs a 400-page document that sits untouched on a shared drive. It should produce five concrete things.

Five concrete deliverables
1
Common VocabularyShared definitions for collection, preservation, verification, inference, attribution, confidence and assessment — so everyone is talking the same language.
2
Minimum Documentation ModelEvery serious OSINT investigation should leave behind enough information for review: source, time, method, capture, context, limitations and analytical reasoning.
3
Competence FrameworkPractitioners assessed not only on tool use, but on judgement, legality, ethics, reporting quality and analytical discipline.
4
Reporting TemplatesReports that make uncertainty visible. A report should not bury caveats in a footnote or present speculation as fact. Transparency is essential.
5
AI Governance GuidanceRules for when AI can be used, how outputs are checked, how prompts and source material are preserved, how privacy requirements are met, and how hallucination risk is managed.

Adhering to standards is work that may seem less glamorous than attending a demonstration of the latest OSINT tool, but it provides the basic controls needed to prevent errors and maintain confidence in the output of an investigation.

A NOTE ON PUBLIC TRUST

There is also a public trust issue here, and it should not be treated as decoration. OSINT can be extraordinarily powerful. It can identify fraud networks, locate missing people, expose malicious activity, protect children, support victims, and help investigators move quickly in moments when time matters.

But it can also be misused. It can become surveillance by another name. It can turn suspicion into certainty too quickly. It can drag innocent people into investigations because a username matched, a photograph looked similar, or an OSINT platform said "high confidence" with no adequate explanation or corroboration.

That is why standards are not the enemy of OSINT. They are what will enable OSINT to remain legitimate.

The Coalition of Cyber Investigators' work on safeguarding and OSINT, including its discussion of how schools can move from scattered warning signs to a governed, intelligence-led safeguarding capability, points to the same principle: information must be received, graded, corroborated, shared, and acted on lawfully.

CONCLUSION: OSINT NEEDS CONSISTENT STANDARDS AND ACCOUNTABILITY

The electronic evidence landscape is changing rapidly. Investigators are handling more data requests, often under urgent conditions, while cryptocurrency exchanges, global platforms and cloud services have become routine sources of evidence. Jurisdictional problems remain difficult, and legal reform alone will not resolve them. OSINT must develop alongside these changes, with stronger methods, standards and professional practice.

That does not mean turning investigators into clerks or killing professional curiosity. Nor does it mean replacing instinct with paperwork. The best OSINT work still depends on imagination, curiosity, lateral thinking, language skills, cultural awareness and the ability to notice the small, odd thing everyone else missed. But the field needs a clear baseline: consistent standards, clear documentation and professional accountability.

Globally recognised OSINT standards would help make open-source intelligence more reliable and consistent, more ethical and more defensible. Standards would help investigators work quickly without sacrificing care. They would also help courts and organisations distinguish between what OSINT actually proves, what it suggests, and what it cannot reliably establish.

In an age where electronic evidence is everywhere, OSINT cannot continue to be performed according to standards that vary between investigators, organisations and jurisdictions.

It is time to professionalise the practice and establish clear standards before the gap between capability and accountability becomes too wide to close.

Authored by: The Coalition of Cyber Investigators,

Paul Wright (United Kingdom) & Neal Ysart (Philippines).

©2026 The Coalition of Cyber Investigators. All rights reserved.

The Coalition of Cyber Investigators is a collaboration between Paul Wright (United Kingdom) - Experienced Cybercrime, Intelligence (OSINT & HUMINT) and Digital Forensics Investigator; Neal Ysart (Philippines) - Elite Investigator & Strategic Risk Advisor, Ex-Big 4 Forensic Leader; and Lajos Antal (Hungary) - Highly experienced expert in cyberforensics, investigations, and cybercrime.

The Coalition unites leading experts to deliver cutting-edge research, OSINT, Investigations, & Cybercrime Advisory Services worldwide.

Our co-founders, Paul Wright and Neal Ysart, offer over 80 years of combined professional experience. Their careers span law enforcement, cyber investigations, open-source intelligence, risk management, and strategic risk advisory roles across multiple continents.

They have been instrumental in establishing foundational legal precedents and case law in cybercrime investigations and in contributing to the development of globally accepted guidance and standards for handling digital evidence. Their leadership and expertise form the foundation of the Coalition's commitment to excellence and ethical practice.

Alongside them, Lajos Antal, a founding member of our Boiler Room Investment Fraud Practice, brings deep expertise in cybercrime investigations, digital forensics, and cyber response, further strengthening our team's capabilities and reach.

The Coalition of Cyber Investigators, with decades of hands-on experience in cyber investigations and OSINT, is uniquely positioned to support organisations facing complex or high-risk investigations.

Our team's expertise is not just theoretical - it's built on years of real-world investigations, a deep understanding of the dynamic nature of digital intelligence, and a commitment to the highest evidential standards.