Skip to main content
Proactive Assessment Intake

Proactive Assessment Intake

1 Assessment trigger

1.1 What triggered this assessment?
1.2 What is the specific intelligence or event driving urgency?
Exact report name, advisory number, incident description — do not paraphrase
1.3 When was the trigger received?
Date:Source:Reliability (Admiralty A–F):
1.4 Is the threat actor or campaign believed to be currently active?

2 Organization profile

2.1 Sector and sub-sector?
2.2 What are the crown jewels — the 3–5 most critical assets?
What would trigger regulatory notification or cause irreversible harm if compromised?
2.3 Why is this organization an attractive target?
IP, customer data, market position, government contracts, critical infrastructure designation
2.4 Geographic and geopolitical exposure?
Nation-state actors with documented interest in this sector/geography

3 Current detection posture

3.1 Detection and prevention tools deployed?
SIEM
EDR
Email security
Network monitoring
Cloud security
3.2 Log sources currently ingested into SIEM?
3.3 Date of last threat assessment or red team exercise?
Date:Findings available:
3.4 Known detection gaps?
Log sources not ingested, detection rules not deployed, known blind spots

4 Scope and mandate

4.1 Who commissioned this assessment?
Name:Role:Authority:
4.2 Expected deliverable?
4.3 Hard deadline?
4.4 Engineering capacity for detection backlog?
Engineer-days or sprint slots available to act on findings

5 Threat context

5.1 Threat actors of concern?
Nation-state clusters, criminal groups, insider threat, hacktivists — name or describe
5.2 Prior incidents or near-misses in this organization?
5.3 Threat intel sources available?
5.4 Relevant advisories or peer incident reports available?
List advisory numbers, incident names, or report titles

6 Regulatory and compliance context

6.1 Applicable regulations?
RegulationApplicable?Upcoming deadline
INCD (Israeli critical infrastructure)
BoI-CD 362 (Israeli financial)
GDPR
PCI-DSS
6.2 Upcoming compliance audit or regulatory review?

7 Analyst assessment

7.1 Initial threat relevance to this organization?
7.2 Top 3 risks to investigate first?
1.
2.
3.
7.3 Recommended immediate actions (72h)?
Quick wins: block known IoCs, enable log source, patch specific CVE, add detection rule

8 Analyst notes

Free-form notes from the intake call — raw, unprocessed

9 Next actions

#ActionOwnerDue
1
2
3
4