02 / Prioritise the threat

Know which threats deserve your attention.

Understand who targets businesses in your industry, what they want and how they operate. We connect that intelligence to your systems and ways of working, so your leadership and IT team can see which risks deserve attention and why.

Your exposure report shows what is visible from outside. The threat briefing explains how attackers could use it, which protections would help and what the consequences could be for your business.

See it in action

See where a control breaks the path.

The forgotten portal from the exposure report offers two ways in. The briefing connects each one to documented attacker methods, then shows which protections could interrupt each route.

Portal access scenarioFictional example
Attacker perspective / plausible scenarioWhich is easier: the password or the software?

Ransomware groups that target professional services are known to guess and reuse passwords. An unpatched login page gives them a second option.

  1. Observed exposure

    A forgotten sign-in page

    The portal is reachable from the internet, with no owner, patch record or sign-in review confirmed.

  2. Route 1 / password guessing

    Guess or reuse a password

    Automated guessing, or passwords leaked from other breaches, until one old account works.

    Break the pathRemove old accounts, require multi-factor sign-in and limit repeated failed logins.
  3. Route 2 / unpatched software or

    Exploit a known weakness

    If the software has a published flaw and nobody applied the fix, a password may not be needed.

    Break the pathIdentify the software and version, then patch it, restrict it or take it offline.
  4. Enabling condition / unverified

    Nobody notices

    If sign-in attempts and admin changes are not reviewed, access could continue for weeks.

    Break the pathSend sign-in and administration events to a named reviewer.
  5. Potential consequence

    Unauthorised access to business records

    Records in the portal could be read or changed, and any connections could lead further into the business.

Retiring the portal closes both routes at once.

Understand who, how and why.

Who might target your business, and why?

Identify attackers known to target your sector and explain what they seek, such as payment fraud, extortion, information theft or disruption. We use published reporting to assess why your information, services and relationships might be valuable to them.

What are they capable of?

Review the techniques and tools these attackers have used. Where useful, we reference MITRE ATT&CK, an established catalogue of attacker techniques, and explain what each method would require to work against your business.

Attack paths: what would they try?

Connect known attacker methods to your exposure. For example, a public login may deserve attention if relevant attackers use stolen passwords and its protections have not been checked. We explain what would make an attack possible and which protections could prevent it.

Business impact: what needs a decision?

Translate the scenarios into potential operational disruption, fraud, information loss and recovery effort. Where costs are estimated, record the inputs and assumptions so leadership can challenge them.

One assessment. Two useful views.

You receive a written assessment and a briefing tailored to the people making the decisions. We agree the audience, level of detail and any follow-up sessions before starting.

Board and leadership briefing

An executive report and briefing covering the most relevant scenarios, business consequences, current control gaps and decisions needed. Clear language supports discussion of investment, ownership and risk acceptance.

Technical threat assessment

A technical assessment connects published attacker activity to your exposure findings. Your security team or IT provider receives the supporting sources, relevant MITRE ATT&CK references and checks needed to confirm whether each attack route is possible.

Prioritised security roadmap

Prioritised actions explain which part of an attack path they address, what the work involves, who owns it and how to verify the result. The roadmap identifies dependencies and the evidence that would raise or lower each risk judgement.

Detection and response requirements

Identify which security records would help reveal each attack scenario and what your team would need to do next. This gives logging, threat hunting and response planning a clear purpose.

Fund the controls that address your risk.

A long list of weaknesses does not tell a board what to fund first. A tailored threat assessment helps you compare action against likely business impact, reuse effective controls and explain why a proposed investment deserves priority. It also gives your team a reasoned basis for deferring lower-priority work.

Before you begin

Do we need an exposure report first?

The briefing needs a reliable picture of your exposure. It normally follows our exposure report. If you have recent equivalent findings, we can review their suitability and scope any missing evidence before quoting the briefing.

Is this for directors or technical teams?

Both. We agree the audience before starting. Leadership receives the business implications and decisions; your cyber team or IT provider receives the technical reasoning and action detail. Separate sessions can be included in the agreed scope.

Can you tell us exactly who will attack?

No. Threat intelligence supports a reasoned assessment of intent, capability and opportunity. We distinguish known activity from plausible scenarios and do not present an actor profile as proof that your business is being targeted.

How long does the assessment remain useful?

It reflects the evidence and business context at the time. The report identifies review triggers, such as a new public service, a major supplier change or significant new threat intelligence. Recurring updates are separately scoped.

Start with a conversation

Bring a clearer view of risk to your next leadership discussion.

Tell us what your business needs to protect, what concerns you and which security tools you already use. We’ll help define a useful starting point and a clear scope.

We’ll only use your details to reply to your enquiry.