OSINT-led outside view before deeper diligence or authorised site access.
Digital, field and data-protection intelligence for Morocco mandates.
OSINT-visible exposure, field infrastructure, informal local processes and data-handling gaps, observed on the ground.
Thirteen years of recurring fieldwork in Morocco. Collection done in person, reporting in English and Italian.
Formatted for EDD, pre-signing diligence and corporate intelligence files. Scoped by mandate, under NDA.
Rob Pinna, CTIA
Deliverables
Annex-ready inputs for due diligence, EDD, legal and corporate intelligence files.
Ground-level observations around infrastructure, vendors and operating practice.
Assessment of data-handling gaps visible before integration or remediation planning.
Combined digital, field and data-protection layer written for insertion into a wider file.
Assessment Flow
The method joins remote visibility with field-observed operating reality.
OSINT
Visible exposure, domains, platforms, internet-facing services and passive technical indicators.
Digital Field Analysis
Wireless baseline, legacy infrastructure, visible devices, vendor marks and site-level technical conditions.
Informal Practices
Staff workflows, local administration, vendor access and trust-based operating patterns.
Data Handling
Guest, transaction and operating data flows; inherited practices; integration or legal gap indicators.
Assessment Layer
Observed, inferred and unverified findings kept distinct for the receiving due diligence, EDD, counsel or corporate intelligence file.
Public Evidence
Published samples show structure, judgement style and limits. They are not client disclosures.
From the ground
Short notes from ongoing fieldwork in Morocco, observed first-hand.
Working Standard
Passive first. Claims stay inside the evidence.
Findings use ICD-203 style confidence language, with observed, inferred and unverified material kept separate. Analysis is framed against regional threat actor tradecraft, including access brokers, fraud operators and intelligence-adjacent collectors, with MITRE ATT&CK mapping where useful. Collection is passive: no active probing, unauthorised access or credential testing. Work can be conducted under NDA and structured to a firm's house format. Client matters are not disclosed.
Discuss a Mandate
For scoped Morocco digital risk intelligence, field verification or annex support: direct@robpinna.com