The administrative attack surface

../../_images/administrative-attack-surface.png

The risk is not that any one publication exposes a secret. None does. The risk is what a few weeks of patient cross-reading turn that publication regime into: a targeting picture for a foreign service, search narrowing for a sabotage planner, queue ordering for a pre-conflict state. Collection is expensive and sometimes detectable. Correlation is cheap, legal, and increasingly automated. The runway between an analyst and a running pipeline has become short.

An open-data aggregation study built from real public records sits below: the method, three worked Dutch cases, and a correlation proof-of-concept design. Entirely Dutch context, but the pattern is likely similar elsewhere in Europe. The strategic frame follows from them: why standard classification and security frameworks miss aggregation risk, whose remit it falls into, and the organisational reasons the gap stays open. The cases are the evidence; the frame is an exploration of what to do with it.

Where the same logic reassembles a person rather than a site, see green’s de-anonymisation model. Where it reads a municipality’s software estate rather than a site’s physical supports, see red’s OSINT of a municipal stack. The defensive counterpart, organised by who is doing the defending, can be found in defensive strategies.

Last updated: 18 July 2026