Knowledge Hub

Intelligence analysis methodology and event security, explained

Direct, practical answers on how a defensible security assessment is produced: analytic standards, source evaluation, structured analytic techniques and estimative language, applied to OSINT, threat assessment, crowd safety and VIP protective intelligence for mass gatherings.

In short

Intelligence analysis methodology is the repeatable process of turning information into a decision-ready judgement: define the requirement, run tasked collection, grade every source, test competing hypotheses with structured techniques, express the result in calibrated probability language with a separate confidence level, and report BLUF-first with assumptions, intelligence gaps and change triggers.

Methodology track

The correct methodology of intelligence analysis

The methodology below is the one Preventio applies to every briefing. It follows established analytic standards — objectivity, explicit sourcing, separation of evidence from assumption, expressed uncertainty, and consistency over time with declared changes.

The six stages of the analytic process

  1. 1 · DirectionFix the decision to support, write the requirement as a single falsifiable question, break it into essential elements of information.
  2. 2 · CollectionTask each EEI to named sources and owners; log URL, publisher, publication date and retrieval time for every item.
  3. 3 · EvaluationGrade source reliability (A-F) and information credibility (1-6) separately; trace republished claims to their origin.
  4. 4 · AnalysisApply structured analytic techniques — ACH, key assumptions check, indicators and warnings, red teaming — to disconfirm hypotheses.
  5. 5 · JudgementState outcome, calibrated probability, timeframe, and a separate confidence level with its driver.
  6. 6 · DisseminationBLUF first, then evidence, assumptions, intelligence gaps and the observations that would change the judgement.

Probability yardstick

Estimative terms are pinned to numeric bands so every reader interprets a judgement the same way.

Almost no chance
1-5%
Very unlikely
5-20%
Unlikely
20-40%
Roughly even chance
40-60%
Likely / probable
60-80%
Very likely
80-95%
Almost certain
95-99%

Source grading (Admiralty code)

Reliability of the source and credibility of the item are rated separately, so a B2 item means a usually reliable source carrying probably true information.

  • A completely reliable
  • B usually reliable
  • C fairly reliable
  • D not usually reliable
  • E unreliable
  • F cannot be judged
  • 1 confirmed
  • 2 probably true
  • 3 possibly true
  • 4 doubtful
  • 5 improbable
  • 6 cannot be judged

Structured analytic techniques used

  • Analysis of competing hypotheses (ACH) — eliminate on inconsistency, not on support.
  • Key assumptions check — surface and stress the load-bearing beliefs.
  • Indicators and warnings — pre-define what a materialising scenario looks like.
  • Red teaming / devil's advocacy — argue the rejected hypothesis on purpose.
  • What-if and premortem — assume the failure occurred, reconstruct the path.
  • Quality-of-information check — re-audit sourcing before publication.

Field guides

The methodology applied to event security

OSINT· 9 min read

OSINT for event security: a practical collection and validation workflow

How to run open-source intelligence for events: define collection requirements, work sources, validate dates and URLs, and turn findings into an actionable security briefing.

Read guide →
Threat assessment· 10 min read

Event threat assessment methodology: from raw signals to a defensible risk rating

A structured methodology for event threat assessment: scenario framing, likelihood and impact scoring, vulnerability analysis and a defensible overall risk rating.

Read guide →
Crowd safety· 8 min read

Crowd safety planning for mass gatherings: density, flow and pinch points

Crowd intelligence for mass events: density thresholds, ingress and egress flow modelling, pinch-point identification, monitoring indicators and escalation triggers.

Read guide →
Protective security· 8 min read

VIP protective intelligence: assessing risk around principals at public events

How to build protective intelligence for principals at public events: exposure mapping, movement risk, hostile surveillance indicators, and coordination with event security.

Read guide →
Threat assessment· 8 min read

Protest and disruption risk at mass events: early indicators and proportionate response

Assessing protest and activist disruption risk around public events: mobilisation indicators, tactic profiles, escalation dynamics and proportionate, rights-respecting response.

Read guide →
Planning· 8 min read

Event security plan: structure, sections and a free template

What an event security plan must contain: event overview, threat assessment, vulnerabilities, deployment, timeline and escalation procedures — with a free downloadable PDF template.

Read guide →
Intelligence· 7 min read

What is a protective intelligence platform? Capabilities and evaluation criteria

What a protective intelligence platform does, which capabilities matter — OSINT collection, threat assessment, persons of concern, briefing generation — and how to evaluate one for event and executive protection.

Read guide →

Frequently asked questions

What is intelligence analysis methodology?
Intelligence analysis methodology is the repeatable process of turning information into a decision-ready judgement: define the requirement, plan and run collection, evaluate sources for reliability and credibility, apply structured analytic techniques to test competing explanations, express findings in calibrated probability language with a stated confidence level, and report BLUF-first with assumptions, gaps and change triggers.
What are the steps of the intelligence cycle?
The intelligence cycle has five steps: direction (defining requirements), collection, processing, analysis and production, and dissemination — followed by feedback from the decision-maker, which re-tasks collection for the next cycle.
What is the difference between likelihood and confidence in an assessment?
Likelihood is the estimated probability of an outcome, written with calibrated terms such as unlikely (20-40%) or very likely (80-95%). Confidence describes how strong the sourcing and reasoning behind that estimate are, rated high, moderate or low. They are always stated separately.
How are sources graded in intelligence analysis?
Sources are graded with the NATO Admiralty code: a letter A to F for the reliability of the source and a number 1 to 6 for the credibility of the specific item. Corroboration only counts when the supporting reports come from genuinely independent origins, which excludes circular reporting.
What is OSINT in event security?
OSINT in event security is the structured collection and validation of publicly available information — institutional notices, media reporting, activist and campaign pages, public social content — used to identify protest mobilisation, threat actors, disruption and environmental factors around an event before it begins.
How do you assess the risk of a public event?
Frame the event parameters, build a set of credible scenarios, score each for likelihood and impact on fixed scales, assess how existing controls perform against them, and produce an overall rating with a BLUF judgement, confidence statement, intelligence gaps and prioritised recommendations with named owners.

Put the methodology to work

Preventio applies this workflow automatically to your event and returns a structured intelligence brief.