Cybersecurity and open-source intelligence

Understand what public information makes possible.

Principia Works helps people and organisations see what can be learned from public sources, understand how that information could be used and make better-informed security decisions.

We provide exposure assessments, security awareness training built around your organisation and evidence-backed OSINT research.

We do not need your passwords or access to your private accounts.

Public information

The pieces rarely look dangerous on their own.

  • A job title.
  • A supplier named in a tender.
  • A direct phone number in an old event programme.
  • A photograph from a conference.
  • A professional profile showing who reports to whom.
  • A company document that reveals how email addresses are structured.

Most of those details are ordinary.
The problem changes when somebody connects them.

Together, public information can reveal who has authority, how an organisation works, who is likely to trust whom and what kind of request would feel normal.

That is where our work begins.

See the connection

The same public footprint can support several different kinds of risk.

+264 81 ••• ••42

Text Message · SMS
Today 9:38

The sender is not in your contact list.
Report Junk

Hi Anna, it's Martha. This is my other number, my phone's acting up.

I'm on the panel in Swakop all morning so I can't take calls.

Can you release the Dune Line payment before 12? They'll pull the team off site otherwise.

I'll sign the paperwork when I'm back. Thanks Anna

DLDune Line AccountsTo: Anna K.  Cc: Petrus H.08:14

Updated banking details: Northside office fit-out

Good morning Anna,

As part of our group restructuring, payments for phase two of the fit-out now go to our new account. The confirmation letter is attached.

Petrus in your procurement team is copied for his records. Please update your system before this week's payment run.

Kind regards,
Dune Line Accounts

PDFBanking confirmation.pdf88 KB
FLFinance Leaders ForumTo: Martha N.Yesterday

Your speaker session on Thursday: please confirm

Dear Martha,

Thank you for joining the Finance Leaders panel in Swakopmund on Thursday.

Please sign in with your work account to confirm your session time and upload your slides by Wednesday.

Sign in to confirm

The Forum team

What is public

  • The organisation's website identifies the finance executive.
  • A conference programme shows that executive speaking outside Windhoek that morning.
  • A staff profile identifies the person who normally handles their requests.

What it reveals

Someone can work out who has authority, who acts on their instructions and when normal verification may be more difficult.

What that can enable

A message from a new number claiming to be the executive suddenly has context.

  • The name is right.
  • The timing makes sense.
  • The request reaches the right person.

The information did not create the fraud on its own.

It made the approach more believable.

One detail rarely creates the problem.
The picture appears when the pieces are brought together.

See what an Exposure Assessment covers

What we do

Three ways we work with public information.

For executives, founders, professionals, leadership teams and organisations.

Exposure Assessment

See what somebody researching you from the outside could learn.

We research information that is already publicly accessible and examine it as a connected picture rather than a collection of isolated search results.

You receive a clear assessment of what we found, why it matters and what should be prioritised.

What it can include

  • Public websites and documents
  • Search engines and archived material
  • Social and professional profiles
  • Company and organisational information
  • Publicly exposed contact information
  • Relevant breach exposure indicators where lawfully available
  • Public images, documents and associated metadata
  • Public-facing infrastructure visible without active testing
  • Relationships between findings across different sources

For organisations, leadership teams and staff.

Security Awareness Training

Build judgement, not fear.

People still need to open emails, use WhatsApp, click links, approve payments and work online after the training ends.

Our sessions help people understand how social engineering works, recognise when something deserves a second look and know what to do next.

Where appropriate, we build the training around the organisation receiving it.

Sessions can cover

  • Phishing
  • Executive impersonation
  • Payment and supplier fraud
  • WhatsApp scams
  • Credential theft
  • AI-generated messages
  • Voice cloning and synthetic media
  • Verification procedures
  • Approval processes
  • Public digital exposure
  • Reporting suspicious activity

For organisations and authorised teams that need evidence-backed research.

Principia Intelligence

OSINT research for questions that need more than a search result.

Principia Intelligence is our analyst-led open-source intelligence service.

Clients bring us a question. We research relevant lawful public sources, connect the information we find and return a structured assessment supported by evidence.

Our technology helps us search, organise and analyse information. A person reviews what reaches the client.

Your public footprint

What could somebody understand without contacting you?

What this means

None of these automatically means you have a security problem.

The important question is what they reveal when combined.

That is what an Exposure Assessment is designed to establish.

Assess our exposure
  • Your organisation publicly names its leadership team.

    This can help someone understand authority and reporting relationships. That is often necessary business information, not automatically a problem.

  • Staff roles are easy to identify online.

    Job titles can reveal who handles finance, procurement, technology, recruitment, executive support and other useful functions.

  • Supplier, partner or project information appears in public documents.

    This can provide context for impersonation or payment fraud involving relationships that genuinely exist.

  • Leadership appearances or travel are announced publicly.

    Events and public engagements can explain when somebody is away, busy or harder to reach through normal channels.

  • Old documents expose direct contact information.

    Phone numbers, personal email addresses and other details sometimes remain online long after their original purpose has ended.

  • Your organisation has years of public PDFs, reports and documents online.

    Documents can reveal names, signatures, contact details, internal terminology, document formats and other useful context.

Awareness without fear

People should leave training more capable, not more suspicious of everything.

Generic warnings often tell people what not to do. That approach does not reflect how people actually work.

  1. Instead of: Do not click links.

    Know what a normal request looks like, so an unusual one stands out.

  2. Instead of: Do not trust messages.

    Verify through a channel you already have, not one the message gives you.

  3. Instead of: Do not use public Wi-Fi.

    Focus on the risks that actually apply to your role.

  4. Instead of: Do not respond to unusual requests.

    Pause when urgency, authority or a changed payment detail appears.

The objective is not permanent suspicion.It is better judgement.

Our aim is different.

We teach people how an attack is put together, what makes it convincing and which decisions interrupt it.

Plan a training session

The process

Clear scope before any research begins.

  1. Understand the question

    We start with what you are trying to solve.

    That might be a concern about public exposure, a training requirement or an investigative question.

  2. Agree the work

    We define the purpose, scope, boundaries, expected output, timeline and fee in writing.

    Where additional authority or consent is required, that is addressed before research begins.

  3. Research and analyse

    We gather relevant information, compare sources, connect findings and document significant evidence.

    Automation may assist the work, but it does not replace analyst judgement.

  4. Explain the result

    You receive findings in a form you can use.

    We explain what was established, what remains uncertain, why it matters and what should happen next where recommendations form part of the engagement.

How we work

About Principia Works

Built in Namibia around a simple idea.

Public information can reveal far more than people realise once the pieces are connected.

Principia Works was created to help clients understand that picture clearly and use that understanding to make better security and investigative decisions.

About Principia Works

Questions

What people usually want to know first.

Read all questions

Do you need access to our systems?

No.

Our exposure and OSINT work begins from the outside.

We do not need your passwords, one-time codes or access to private accounts.

Is this a penetration test?

No.

A penetration test actively evaluates technical systems.

Our Exposure Assessments focus on what can be learned from publicly accessible information and what that information could make possible.

Do you investigate anyone who asks?

No.

Investigative work requires a legitimate purpose, appropriate authority or basis and an agreed scope.

Is Principia Intelligence just an automated tool?

No.

Technology supports the research process, but significant findings are reviewed by a person before they reach the client.

Do you work only in Namibia?

Principia Works is based in Namibia.

Research and remote engagements can also be delivered more widely where the scope, legal requirements and nature of the work allow it.

Start with the problem, not the service.

You do not need to know exactly what you need before contacting us.

Tell us what happened, what concerns you or what you are trying to understand.

We will tell you whether Principia Works is the right fit and what the next step would involve.