All techniques
REC-0008.04
ST0001Reconnaissance
sub-technique

Business Relationships

Parent: REC-0008

Description

Threat actors map contractual and operational relationships to identify the weakest well-connected node. They enumerate primes and subs (bus, payload, ground, launch), managed service providers, ground-network operators, cloud/SaaS tenants, testing and calibration labs, logistics and customs brokers, and warranty/repair depots, plus who holds remote access, who moves money, and who approves changes. Public artifacts (press releases, procurement records, org charts, job postings, conference bios) and technical traces (email MX/DMARC, shared SSO/IdP providers, cross-domain service accounts) reveal trust bridges between enclaves. Shipment paths and integration schedules expose when and where hardware and sensitive data concentrate. Understanding these ties enables tailored phishing, invoice fraud, credential reuse, and supply-chain insertion timed to integration milestones.

Mappings

EU regulation articles

  • craAnnex I, Part II, (1)
    addresses
    moderate
    direct

    Open-source-software reconnaissance (primary mapping: Art. 13(5)) implies (1)'s SBOM obligation as the primary artifact OSS reconnaissance targets — the manufacturer's defense relies on having documented OSS components.

  • craAnnex I, Part II, (5)
    addresses
    moderate
    direct

    Open-source-software reconnaissance (primary mapping: Art. 13(5)) requires a CVD intake under (5) as the inbound channel for OSS vulnerability disclosures from upstream maintainers.

  • craArt. 13(5)
    addresses
    moderate
    derived

    Manufacturer due-diligence on supplier integration governs the contractual and operational mapping of relationships that business-recon adversaries enumerate; when manufacturers maintain documented due-diligence, the adversary's relationship-map asymmetry shrinks.

  • eu-space-actArt. 77(2)
    addresses
    moderate
    inferred

    Art. 77(2)'s human-resources security policy is domain-relevant to personnel reconnaissance, but governs internal HR security rather than interdicting the mapping of publicly available business-relationship information.

  • eu-space-actArt. 92(1)
    addresses
    moderate
    direct

    Mapping of business relationships and contractual touchpoints is squarely within 92(1)'s supply-chain risk management framework — the framework structures who-can-do-what across primes, subs, and partners.

  • nis2Art. 21(2)(d)
    addresses
    high
    direct

    Mapping primes/subs, MSPs, ground-network operators, cloud tenants, and remote-access holders is the very topology Art. 21(2)(d)'s supplier-relationship security obligation requires the entity to govern.

  • nis2Art. 21(2)(g)
    addresses
    moderate
    direct

    Tailored phishing, invoice fraud, and credential reuse leveraged off business-relationship recon are countered by basic cyber hygiene practices and cybersecurity training under Art. 21(2)(g) covering operators, finance, and engineering staff.

  • nis2Art. 21(3)
    addresses
    high
    direct

    Cross-domain trust bridges (shared SSO/IdP providers, service accounts spanning enclaves) and vetting weaknesses in low-tier suppliers are exactly the supplier-specific vulnerability profile Art. 21(3) requires the entity to factor in when sizing its third-party reliance.

  • nis2-implAnnex 10.1.1
    addresses
    moderate
    derived

    HR-security obligations bind employees and contractors to discipline around what they disclose about contractual relationships and project-team composition — the data underpinning relationship reconnaissance.

  • nis2-implAnnex 5.1.1
    addresses
    high
    derived

    Mapping primes, subs, integrators and operations partners is exactly the supply-chain topology the implementing regulation requires the entity to govern with a formal policy; that policy bounds how relationship metadata is exposed and protected.

  • nis2-implAnnex 8.1.1
    addresses
    moderate
    derived

    Cyber-hygiene awareness is the human-side defence against social engineering against the well-connected nodes a relationship-recon adversary identifies as weakest.

ENISA controls

  • Third-party risk management governs how supplier and partner relationships are assessed, the same relationships REC-0008.04 enumerates.

  • Supplier security management documents and audits the contractual security relationships REC-0008.04 maps for leverage.

  • Cybersecurity awareness and training is a governance control that governs personnel preparedness around the supplier and partner relationships REC-0008.04 enumerates; it is relevant to the technique rather than an active defence against the reconnaissance.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, REC-0008.04 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.