HOW IT WORKS

A threat-informed methodology, explained plainly.

Lowside Intelligence starts with the threats, not a generic checklist. Here is how the analysis moves from threat intelligence to practical recommendations — with a human analyst reviewing every finding.

01

Threat intelligence

We gather and organise intelligence on the threats and attack methods currently affecting organisations comparable to yours.

02

Relevant attack methods

We identify which attack methods are relevant to your sector, size and country — rather than presenting a generic checklist.

03

Security controls

We review the security measures you report, covering areas such as authentication, software updates, email security and supplier relationships.

04

Potential gaps

We compare your reported controls with the relevant attack methods and identify where your measures may not adequately address them.

05

Analyst review

A human analyst reviews the findings before anything is delivered to you. Technology supports the analysis; a person decides what reaches you.

06

Recommendations

You receive a practical, prioritised report explaining what to change, why it matters, and a suggested owner and timescale.

07

Ongoing monitoring

For customers taking an ongoing service, we continue monitoring the threat landscape and advise when new threats require changes.

THE FRAMEWORKS WE USE

MITRE ATT&CK, in plain English

MITRE ATT&CK is a widely used knowledge base documenting techniques observed in real-world cyber attacks. It helps us describe how attackers actually behave, so the analysis stays grounded in observed activity rather than assumptions.

Where relevant to businesses using artificial intelligence, MITRE ATLAS may also be used to account for attacks against AI systems.

These frameworks support the analysis, but they do not automatically determine whether your organisation is secure. A human analyst interprets the findings in the context of your business.

How we describe findings

We are careful to distinguish between different kinds of information, so you always know what a finding is based on.

Controls reported by you

Security measures you tell us about through the questionnaire.

Potential weaknesses inferred

Gaps we identify by comparing your reported measures with relevant attack methods.

Exposures observed through monitoring

Things we may identify through ongoing monitoring, where relevant to your service.

Technically verified vulnerabilities

Findings that have been confirmed through technical validation, where this applies.

See the methodology applied to your organisation.

A threat-led security assessment is one-off, with no subscription required.