THE METHOD BENEATH THE WORK
Most security commentary sounds every alarm it finds. Intelligence does the opposite — it tests each one and reports the ones that hold. This is the craft beneath every DSI briefing and every assessment: not another framework, but a method-family, each part standing on shoulders we name.
The line we hold is the line between intelligence and advocacy. Advocacy marshals only confirming evidence and sounds every alarm. Analysis tests each one. A body of work in which everything confirms reads as a conclusion wearing a method’s clothes — and sophisticated readers are trained to distrust it. So we show the method, and we show where it returns a “no.”
01 · The Questions Doctrine
The security industry asks the right questions about the wrong map. Better questions reach the destination before the answers do. Every piece begins by replacing the question we were handed with the one the industry, the regulator, and the adversary are not asking. The quality of the question — not the confidence of the answer — decides where the analysis lands.
02 · The Full Threat Surface
Four dimensions — physical geography, logical architecture, governance architecture, adversarial intent — asked simultaneously about one system. Four different experts normally ask these separately and never together. We ask all four at once, and name the governance gap no single institution has the mandate to close. That intersection is where the risk actually lives.
03 · The Alarm Test
Finding a threat is easy; knowing which alarms to trust is the discipline. Before we sound a warning, we try to break it. We state the claim in its strongest, most falsifiable form; assign it a genuine adversary and search for the strongest published counter-evidence; and render a calibrated verdict in three outcomes, never two — the claim SURVIVES the attempt, its magnitude or timeline needs CALIBRATION, or a GENUINE COUNTER-case exists. Then we publish the test, not just the conclusion, because the credibility is in showing the instrument can return a “no.” This is not our invention. It is Richards J. Heuer Jr.'s Analysis of Competing Hypotheses and Karl Popper's falsification — turned on our own field's alarms, and on our own claims.
04 · The Predictions Scorecard
An analyst who never checks their own forecasts is asking for a trust they have not earned. We keep our predictions on the record and check them against what happened. Calibration beats confidence. It is the one thing hype cannot fake — and the reason “the series called it” is a fact a reader can verify rather than a claim they must take on faith.
Built on established shoulders — stated plainly
We do not replace, improve on, or rename the tradecraft we use. We apply it — and we acknowledge the debt wherever the work appears.
- Karl Popper — falsification (Conjectures and Refutations, 1963)
- Richards J. Heuer Jr. — Analysis of Competing Hypotheses (CIA, 1999)
- Heuer & Pherson — Structured Analytic Techniques
- ICD 203 — analytic standards (ODNI)
- Micah Zenko — Red Team · Philip Tetlock — Superforecasting
What this commits us to
Together the four are a single discipline with a single obligation: the method is public, the track record is checkable, and the analysis earns its authority by showing its work — including, when the evidence says so, where the alarm was overblown. Rigour you cannot inspect is just confidence with better production values. Ours you can inspect.