01Methodology

Structured
Observation

Every Cyber Analysis report follows a consistent analytical methodology.

The purpose of the methodology is not to produce predetermined answers or predetermined levels of risk. Its purpose is to ensure that every investigation follows the same structured process, allowing observations to be examined carefully before conclusions are reached.

Cybersecurity is rarely defined by a single weakness. Risk often emerges through the relationship between technology, governance, operational practice and organisational decision-making. The Cyber Analysis Methodology is designed to examine those relationships through evidence-led analysis.

02Analytical Framework

The Methodology

The Cyber Analysis Methodology is designed to examine the relationships between technology, governance, operational practice and organisational decision-making through evidence-led analysis.

C/01

Threat Surface

Every assessment begins by understanding what is exposed. This includes systems, identities, cloud services, applications, external services and the broader technology environment. The objective is not simply to identify assets, but to understand where potential exposure exists and how that exposure influences organisational risk.

C/02

Security Controls

Security controls reduce risk only when they are implemented, maintained and understood. This stage examines the security measures that protect organisational systems and considers how those controls contribute to the overall security posture.

C/03

Governance

Technology alone does not determine cybersecurity. Governance influences priorities, accountability, decision-making and oversight. This stage examines how cybersecurity responsibilities are organised and how security decisions are supported across the organisation.

C/04

Resilience

No organisation can eliminate every cybersecurity risk. Resilience considers how well an organisation prepares for disruption, responds to security incidents and recovers when unexpected events occur.

C/05

Third-Party Exposure

Modern organisations depend upon suppliers, software vendors, cloud providers and external services. Understanding how those relationships influence cybersecurity is an essential part of every assessment.

C/06

Operational Security

Everyday operational practices often have a greater influence on security than technology alone. Processes, communication, access management, change management and routine activities all contribute to an organisation's overall security posture.

C/07

Implications

Only after each area has been examined are observations considered together. This final stage identifies patterns, relationships and potential implications that may not be visible when individual findings are viewed in isolation.

The objective is not simply to identify issues. It is to develop a balanced understanding of organisational cybersecurity through structured analysis.

03Principles

Analytical Principles

Every Cyber Analysis report is guided by a common set of principles. These principles help ensure that every report remains consistent, transparent and focused on improving organisational understanding rather than supporting predetermined outcomes.

  • Evidence before assumption.
  • Observation before conclusion.
  • Context before judgement.
  • Independence before influence.
  • Clarity before complexity.
04Consistency

A Consistent Method

The Cyber Analysis Methodology is intended to provide consistency rather than certainty. Organisations differ. Technologies change. Risks evolve.

Applying the same structured approach to every investigation helps produce reports that are transparent, repeatable and grounded in careful analysis.

Every report begins in the same place. With observation. Every conclusion is expected to follow from the evidence examined throughout the investigation.