A government-conference study measured ten OSINT feeds against 54 real attacks. Two sources cover 92.6% of them, and the feeds everyone calls canonical are mostly noise
The feeds sort by mission, not quality. Six precursor sources fire before attacks with zero false firings; three canonical ICS sources fire on disclosures, not attacks. A chosen two cover almost everything.
By Parminder Kumar Sharma · · 6 min read

What the study did
Defenders of critical infrastructure subscribe to a lot of open-source intelligence feeds. Almost nobody has an empirical basis for which of those feeds actually precede attacks rather than just describe them afterwards. On 21 August 2026, four researchers published A Case-Control Measurement Study of OSINT Source Effectiveness for Critical Infrastructure Defense (arXiv:2608.21471, accepted at IEEE CNS 2026), and provided one.
They assembled 54 confirmed critical-infrastructure cyberattacks from 2010 to 2024, across twelve named sectors plus a cross-sector category, and paired them with 12 null-control vulnerability cases drawn from the same source space. Then they audited ten public OSINT source classes on three things: how often each fired ahead of a real attack, how often it fired on the null controls, and how much lead time it gave.
The finding: feeds fall into three jobs, and two of them are not warning you
The sources did not sort by quality. They sorted by mission, into three operationally distinct profiles, and the separation is not a close call: pooled Fisher exact p = 3.4 x 10⁻⁸.
OSINT sources by what they actually do
- Precursor (six classes) fired ahead of attacks and produced zero null firings at coverage of 5% or more. These are the feeds that genuinely warn you.
- Disclosure-exposure (three classes) had null contamination that met or exceeded their attack coverage. They fire when a vulnerability is disclosed or an exposure is catalogued, which is not the same as an attack being imminent. As a warning signal they are close to noise.
- Broad-coverage (one class) mixes the two, but still held 91.3% within-corpus precision, so it earns its place.
The classification held up when the corpus was split at 2019, and when it was split into US versus non-US cases. It is not an artefact of one period or one region.
The sentence that should change a procurement decision
Here is the line that matters, in the authors' framing: several source classes widely treated as canonical for industrial control system defence fall into the disclosure-exposure profile by operational mission, not by quality.
Read that carefully, because it is easy to misread as an attack on those feeds. It is not. A disclosure feed is excellent at what it does, cataloguing disclosures. The error is on the buyer's side: treating a catalogue of what became public as a warning of what is about to happen. The feed is fine. The job you assigned it was wrong.
You are probably paying for redundancy
The other half of the result is about quantity, and it is blunt.
92.6%
of attacks, from two sources
One broad-coverage and one precursor source cover almost all of the corpus.
96.3%
from three sources
A third source takes coverage to nearly everything measured.
+39.8pts
a chosen three beats a random three
The greedy three-source portfolio over the mean random three-source subset.
3.4e-8
the profiles are real
Pooled Fisher exact p for the three-way mission separation.
Two well-chosen sources cover 92.6% of these attacks. Three cover 96.3%. And a deliberately selected trio of feeds beats a randomly chosen trio by 39.8 percentage points of coverage. So the value is almost entirely in which feeds, not how many. A stack of ten subscriptions is mostly paying for overlap and for sources doing a job you did not need.
What to do with this
Take this with you
For anyone buying or running an OSINT feed stack
- Ask of each feed you pay for: does it fire before attacks, or does it catalogue what became public? The second is useful for patching priority and useless as an early warning, and the two are priced the same.
- Do not equate canonical with predictive. The paper is explicit that several ICS-canonical sources are disclosure-exposure by mission. Reputation is not the measure; lead time and null contamination are.
- Cut for redundancy, not for cost. If two or three well-chosen sources cover most of your threat surface, the rest of the stack is overlap you can stop paying attention to, which is worth more than the subscription saving.
- Build the portfolio for your context. The paper finds per-sector, per-actor and per-jurisdiction portfolios diverge in rank order even though they share a top source. A generic best-feeds list is not your best-feeds list.
- Treat the corpus as testable. The authors released the corpus, the linkage protocol and the classification rules. You can run your own feeds against the same method rather than trusting a vendor comparison.
The position
This is the same defect this site keeps finding, now in the intelligence-buying decision itself. A feed subscription is an accurate artefact, it truthfully reports what it reports, and it answers a narrower question than the buyer thinks. "We monitor ten OSINT sources" sounds like coverage. Measured against whether those sources actually precede attacks, most of the ten are describing the past, and two are doing nearly all the warning.
It also lands exactly where this site's cyber threat intelligence guide placed the whole discipline: the test of intelligence is whether it changes a decision in time to matter. A disclosure catalogue arriving after an exposure is public changes a patching queue, which is worth having, but it is not the early warning it is often bought as. The useful move is not more feeds. It is knowing which two of yours are the precursor sources, and being honest that the rest are doing a different job.
Sources
- PrimaryA Case-Control Measurement Study of OSINT Source Effectiveness for CI Defense, Emeksiz et al., 21 August 2026arXivaccessed 2026-08-25


