5. Intelligence Writing and Briefing

Writing Defensible Intelligence Assessments

Write bottom-line-up-front assessments that distinguish sourced facts, assumptions, analytic judgments, confidence, alternatives, and implications.

In this lesson, you will learn to:

  • Write a bottom-line-up-front assessment that clearly separates sourced facts, assumptions, analytic judgments, confidence, alternatives, implications, and recommended decisions.

Writing Defensible Intelligence Assessments

Lead with the judgment and decision relevance

A defensible intelligence assessment lets a consumer understand the main judgment quickly and lets an authorized reviewer trace how the analyst reached it. It is concise without hiding uncertainty, evidence, or alternatives.

Begin with the bottom line up front, often abbreviated BLUF. The opening should answer:

  • What do we assess?
  • How likely is it?
  • How confident are we, and why?
  • Why does it matter to this consumer now?
  • Which decision or action does it inform?

A useful pattern is:

We assess [judgment] is [likelihood], with [confidence], because [most diagnostic evidence and limitation]. This matters because [implication for the named decision].

The pattern is a drafting aid, not mandatory wording. A finished assessment should sound natural and put the consumer’s need before the analyst’s process.

Compare weak and strong openings

Weak opening:

This report provides an overview of recent suspicious activity involving several finance workstations and discusses potential implications.

The sentence announces a document but communicates no intelligence.

Stronger opening:

We assess at least two Northbridge finance workstations were likely affected by a coordinated intrusion attempt, with moderate confidence. Similar targeted attachments, matching process behavior, and distinct host records support a common malicious cause, but the payload and the third workstation’s status remain unresolved. The incident lead should use this assessment to decide whether to widen identity investigation and containment beyond the confirmed hosts.

The stronger opening supplies a bounded judgment, likelihood, confidence, supporting evidence, limitations, and decision relevance. It does not force the consumer to read chronologically through every observation before reaching the conclusion.

Write for a specific consumer

The same assessment may require different emphasis for different readers:

Consumer Lead with Supporting detail
Incident commander Current scope, leading explanation, confidence, immediate implications, and decision deadline Affected systems, alternatives, gaps, containment options, next update trigger
Detection engineer Observable behavior, telemetry, analytic logic, and limitations Process relationships, data sources, test conditions, false-positive considerations
Security leader Organizational exposure, plausible impact, priority, and choices Recurring pathways, control gaps, evidence strength, resource implications
Executive or risk owner Business consequence, time horizon, uncertainty, and available decisions Scenario assumptions, affected services, reversibility, and risk trade-offs
Legal, privacy, or communications lead Established facts, bounded judgments, affected parties, and disclosure constraints Provenance, unresolved questions, handling, and review status

Audience adaptation must not change the underlying judgment. It changes vocabulary, detail, order, and emphasis. If two products state materially different conclusions from the same analysis, reconcile the discrepancy rather than explaining it as tailoring.

Separate sourced facts from analytic judgments

Readers should be able to distinguish what was observed from what the analyst inferred.

Use clear signals:

  • Sourced fact or claim: “Endpoint records show the same interpreter command on two hosts.”
  • Source limitation: “The third host did not retain equivalent endpoint records.”
  • Assumption: “This assessment assumes the host clocks are comparable within two minutes.”
  • Analytic judgment: “We assess the events were likely related.”
  • Alternative: “An authorized deployment remains plausible but is less consistent with the targeted messages and absence of a matching change record.”
  • Implication: “If the events share a cause, investigation limited to one workstation may miss affected identities or systems.”
  • Recommendation or option: “The incident lead should consider a bounded search across finance identities before restoring access.”

Do not mark every sentence with a label. Use structure and consistent estimative language so distinctions remain clear without making the prose mechanical.

Avoid wording that disguises judgment as fact:

  • “The threat actor established persistence” when only task creation was observed.
  • “The malicious domain” when the domain’s role remains assessed rather than established.
  • “The campaign targeted finance” when finance recipients may reflect collection bias or limited scope.
  • “Credentials were stolen” when the evidence shows only access to a credential store.

Prefer bounded formulations:

  • “A scheduled task referencing the extracted script was created on one host; we assess it was likely intended to preserve access.”
  • “The domain served as a download destination in two investigated intrusions during 3–7 May.”
  • “Available messages were sent to finance personnel, but current evidence is insufficient to determine whether targeting extended to other teams.”
  • “A process accessed browser credential stores; successful extraction is unconfirmed.”

Precision strengthens credibility. It does not weaken the assessment.

State the key judgment as one proposition

A key judgment should be specific enough to evaluate. Include the relevant subject, event or outcome, scope, and time horizon.

Weak:

Ransomware is likely to remain a threat.

Stronger:

During the next two quarters, extortion operations are likely to present Northbridge’s greatest disruption risk through compromised privileged access to critical service providers, with moderate confidence.

The stronger judgment can be tested and connected to a planning decision. Its scope also makes clear what it does not claim: it does not predict a specific incident or assert that every provider is compromised.

Avoid combining several uncertain propositions into one sentence. Separate claims about:

  • whether activity occurred;
  • whether events share a cause;
  • the probable objective;
  • likely future behavior;
  • organizational exposure;
  • attribution;
  • expected impact.

Confidence may differ across them. Northbridge may have high confidence that task creation occurred, moderate confidence that several hosts share a malicious cause, and low confidence about who operated the activity.

Explain confidence rather than decorating the prose

Attach confidence to a specific judgment and give the reason:

We assess the events were likely coordinated, with moderate confidence. Three independent evidence types support a common cause, but payload recovery is incomplete and one host lacks endpoint visibility.

Do not write:

We are moderately confident that the activity might possibly be coordinated.

The second version confuses confidence with likelihood and uses hedging that prevents the reader from understanding the assessment.

Confidence rationales should name the limiting factors most relevant to the judgment:

  • source reliability or access;
  • evidentiary independence;
  • environmental coverage;
  • timeliness;
  • contradictory reporting;
  • load-bearing assumptions;
  • analytic disagreement;
  • inability to distinguish alternatives.
Put evidence in descending order of diagnostic value

Do not reproduce the order in which evidence was collected. Lead with evidence that most strongly distinguishes the judgment from alternatives.

For the Northbridge assessment:

  1. Distinct host records show matching unusual execution after similarly constructed messages.
  2. One host created persistence referencing the extracted script.
  3. The activity was followed by a new-device sign-in involving a related service account, though linkage remains unconfirmed.
  4. The destination domain was recently registered.

The fourth observation may be true but is less diagnostic because many benign domains are newly registered. Placing it first would overstate its analytic importance.

Group evidence by argument rather than source. A paragraph might explain delivery evidence, another execution and persistence, and another identity implications. Cite or reference sources in a way that preserves traceability and handling constraints.

Represent alternatives fairly

A defensible assessment does not mention an alternative merely to dismiss it. State why it remains plausible and which evidence weighs against it.

An authorized deployment could explain the interpreter and administration-tool behavior. We consider it less likely because no matching change record or owner confirmation has been found and because the sequence followed similarly constructed attachments. A validated signed package and owner confirmation would raise this alternative substantially.

This treatment shows that the alternative was tested and names the evidence that could change the judgment.

Do not use straw alternatives such as “random coincidence” when a more specific benign or mixed explanation exists. If credible analysts disagree, explain the source of the disagreement when it matters to the consumer.

Distinguish implications from recommendations

An implication explains what may follow if the assessment is correct. A recommendation proposes what the consumer should do. They are related but not identical.

Type Example
Judgment The workstation events were likely coordinated.
Implication Investigation limited to the first host may understate affected identity and service scope.
Option Search finance identity and endpoint records for the same behavioral sequence.
Recommendation Conduct a bounded search before restoring the affected accounts because it is reversible and could reveal materially wider scope.
Decision owner The incident commander decides whether the expected value justifies the operational cost.

Analysts should understand available actions and constraints, but recommendations must be labeled. Consumers may accept the judgment and choose another option because they own operational risk, legal obligations, resources, and business priorities.

Where authority is limited, present decision options with trade-offs:

Option Benefit Cost or risk Reversibility
Monitor confirmed hosts only Lowest operational disruption May miss related identity or host activity Easily revised
Conduct a bounded search across finance Improves scope understanding Consumes analyst time and may identify benign matches Highly reversible
Isolate the finance segment Reduces some immediate pathways Material business disruption and possibly excessive scope Reversible but costly

Intelligence informs proportional action; it should not manufacture urgency through dramatic language.

Use plain, precise language

Prefer short sentences and concrete verbs. Define unavoidable technical terms. Remove phrases that add length without meaning:

  • “It is important to note that”
  • “Based on the fact that”
  • “It should be considered that”
  • “There is a possibility that”
  • “At this point in time”
  • “Various threat actors”

Replace them with the judgment or evidence directly.

Avoid sensational labels such as sophisticated, advanced, highly targeted, or unprecedented unless they are defined and supported. Sophistication should describe demonstrated capability, operational security, resource use, or technical complexity—not the analyst’s surprise.

Use layered structure

A concise assessment can still serve readers who need different depths:

  1. Title: Names the assessed issue and relevant scope.
  2. Bottom line: Gives the principal judgment, confidence, implication, and decision relevance.
  3. Key judgments: Presents a small number of distinct, prioritized conclusions.
  4. Evidence and reasoning: Explains why the judgments are favored and how alternatives compare.
  5. Implications and options: Connects the analysis to the consumer’s choices.
  6. Gaps and change conditions: States what remains unknown and what would trigger an update.
  7. Supporting detail: Provides chronology, methods, technical data, and references for authorized readers.
  8. Handling and review information: States sensitivity, dissemination boundaries, author, review status, and assessment date.

Layering allows a senior consumer to act from the first page while enabling technical reviewers to inspect the foundation.

Key takeaways
  • Lead with a bounded judgment, likelihood, confidence, implication, and decision relevance.
  • Tailor detail and vocabulary to the consumer without changing the underlying assessment.
  • Distinguish sourced claims, assumptions, judgments, implications, and recommendations.
  • State separate propositions when their evidence or confidence differs.
  • Organize evidence by diagnostic value rather than collection order.
  • Treat credible alternatives fairly and name what would change the judgment.
  • Use precise, plain language and a layered structure that supports both rapid use and review.

Analyst habit: Draft the first paragraph before the background section. If you cannot state the bottom line clearly, the analysis or requirement may still be unresolved.

Build and review a defensible assessment

A strong assessment is produced through an explicit workflow: define the requirement, develop judgments, draft for the consumer, review the evidence and reasoning, apply handling controls, deliver in time, and update when conditions change. Editing prose is only one part of quality assurance.

Start with an assessment blueprint

Before writing paragraphs, create a one-page blueprint:

Element Drafting prompt
Consumer Who owns the decision, and what do they already know?
Decision What choice must be made, by when, and under which constraints?
Requirement Which uncertainty must the product reduce?
Scope Which systems, people, behaviors, regions, and time period are included or excluded?
Key judgments What are the three to five most decision-relevant conclusions?
Evidence Which observations most strongly support or challenge each judgment?
Assumptions Which unverified conditions carry analytic weight?
Alternatives Which plausible explanations remain, and why are they less favored?
Confidence What is the confidence level for each key judgment, and what limits it?
Implications What changes for the consumer if each judgment is correct?
Options Which realistic actions are available, with what trade-offs?
Gaps and triggers What is unknown, what would change the assessment, and when should it be reviewed?
Handling Which source protections, privacy limits, and dissemination rules apply?

The blueprint prevents background material from becoming the product’s organizing principle. It also exposes when the analyst has accumulated facts but has not yet formed a decision-relevant judgment.

Draft key judgments before supporting prose

Write each key judgment as a complete, testable proposition. Then attach:

  1. likelihood;
  2. confidence and rationale;
  3. most diagnostic supporting evidence;
  4. strongest contradictory evidence or alternative;
  5. implication;
  6. change condition.

Example:

Key judgment: Activity on at least two finance workstations was likely part of one coordinated intrusion attempt, with moderate confidence. Similar targeted attachments, matching execution sequences, and distinct raw host records support a common cause. An authorized deployment remains plausible but lacks a matching change record or owner confirmation. If the judgment is correct, investigation limited to one host may miss affected identities. A validated signed deployment package would lower the assessed likelihood substantially.

If the evidence does not support a clear proposition, return to analysis. Do not conceal uncertainty with broad headings or descriptive chronology.

Build traceability without overwhelming the reader

Every material judgment should connect to its evidence record. Depending on the product and handling environment, use:

  • footnotes or endnotes;
  • source-reference identifiers;
  • links to protected internal records;
  • evidence tables in an annex;
  • inline phrases that describe source access and limitations;
  • a separate technical appendix;
  • versioned analytic notebooks or case records.

The consumer-facing product may summarize sensitive evidence, but an authorized reviewer should be able to retrieve the underlying source, provenance, timestamps, transformations, limitations, and handling rules.

A useful evidence table is:

Judgment ID Evidence reference Relationship Independence Limitation
KJ-1 E-04 endpoint records Supports matching execution on two hosts Direct internal telemetry Third host lacks equivalent coverage
KJ-1 E-07 email records Supports similar targeted delivery Independent system from endpoint records Message similarity does not prove execution
KJ-1 E-11 change review Weighs against authorized deployment Human and system records Informal emergency work may be absent
KJ-2 E-15 identity records Supports possible wider scope Separate identity source Link to host activity remains inferential

The table reveals that evidence items can support, challenge, or merely contextualize a judgment. It also prevents repeated reporting from appearing independent.

Separate analytic review from editorial review

A product can read beautifully and still be analytically weak. Use distinct review lenses.

Analytic review
  • Does the product answer the requirement and decision?
  • Are judgments bounded by subject, scope, and time horizon?
  • Are likelihood and confidence used correctly?
  • Does the evidence support the exact wording?
  • Are source reliability, credibility, timeliness, and independence addressed?
  • Are assumptions and alternatives visible?
  • Are contradictions and gaps represented fairly?
  • Are implications connected logically to judgments?
  • Are recommendations proportionate and clearly labeled?
  • Are change conditions and review triggers stated?
Editorial review
  • Is the bottom line immediately visible?
  • Is the structure ordered by consumer importance?
  • Are sentences concise, active, and unambiguous?
  • Are acronyms and technical terms defined or removed?
  • Do headings communicate findings rather than topics?
  • Are tables and visuals readable and necessary?
  • Are dates, units, names, and terminology consistent?
  • Does the title accurately represent the assessment?
Handling and release review
  • Are sensitivity, privacy, legal, contractual, and partner restrictions correct?
  • Are sources protected appropriately?
  • Is every recipient authorized and able to handle the product?
  • Are redactions or sanitized versions accurate rather than misleading?
  • Are retention, access logging, and onward-sharing rules applied?
  • Is the product early enough to support the decision?
  • Are author, reviewer, version, and assessment date recorded?

Different reviewers can perform these lenses, or one reviewer can use them sequentially. What matters is that style does not substitute for tradecraft and analytic rigor does not excuse unreadable communication.

Review at the claim level

For every consequential sentence, identify its type:

  • sourced fact;
  • analytic judgment;
  • assumption;
  • implication;
  • recommendation;
  • process statement.

Then test the wording against the evidence.

Original:

The attacker stole finance credentials and used them to access the payment service.

Claim-level review finds several unsupported steps. The evidence may establish only that a process accessed browser credential stores and that a later sign-in came from a new device.

Revised:

A process accessed browser credential stores on one finance workstation. A related service account later authenticated to the payment-support service from a new device. We assess the events were possibly related, with low confidence, because the sequence is consistent with credential use but direct linkage and successful extraction are unconfirmed.

The revision is longer because it restores essential distinctions. Elsewhere, editing may shorten a sentence by removing nonessential background. Brevity should reduce noise, not evidence.

Test the title and headings

Topic headings force consumers to infer the message:

  • “Threat Activity”
  • “Findings”
  • “Technical Analysis”
  • “Recommendations”

Finding-based headings communicate more:

  • “Matching host sequences support a common cause”
  • “Incomplete identity visibility limits scope confidence”
  • “Behavioral monitoring offers broader coverage than domain blocking”
  • “A bounded finance search is the most reversible next step”

A finding-based heading must still be accurate and appropriately qualified. Do not remove uncertainty to make a heading dramatic.

The title should name the assessed issue, relevant scope, and sometimes time period:

Likely coordinated intrusion activity affecting Northbridge finance systems, assessed 12 August

Avoid titles that imply confirmation or attribution beyond the evidence.

Design tables and visuals as analytic objects

Use a visual only when it makes a relationship easier to understand. Suitable forms include:

  • a timeline for event sequence and gaps;
  • a matrix for competing hypotheses;
  • a behavior path for actions and intervention points;
  • a table for options and trade-offs;
  • a confidence or evidence summary for distinct judgments;
  • a map only when geography is relevant and the data supports it.

Every visual should have:

  • a clear question or message;
  • labeled scope and time period;
  • defined units, categories, and terms;
  • visible uncertainty, missing data, and caveats;
  • source or methodology references;
  • accessible colors and readable text;
  • a written takeaway that does not require guessing.

Do not use decorative dashboards, three-dimensional charts, truncated axes, area-based comparisons that distort magnitude, or color scales that imply unsupported precision. A visual must not convert incomplete reporting into apparent prevalence.

Conduct a consumer test

Before release, ask someone unfamiliar with the drafting process to read only the title, opening, key judgments, and visuals. Then ask:

  • What do you think the main judgment is?
  • How likely is it, and how confident are we?
  • What decision does the product support?
  • Which evidence and limitation matter most?
  • What remains uncertain?
  • What action or options are presented?
  • When should the assessment be revisited?

If the reader answers differently from the analyst’s intent, revise the product. Communication quality is measured by what the authorized consumer can accurately understand, not what the analyst remembers meaning.

Use a proportionate review model

Review depth should reflect urgency and consequence.

Situation Proportionate review
Immediate incident update Rapid peer check of key judgment, evidence, confidence, scope, handling, and next-update time
Daily operational assessment Analyst self-check plus peer review of changes and action implications
Major strategic assessment Structured analytic review, source and methods check, editorial review, stakeholder relevance test, and release authority
Public or partner-facing attribution Senior analytic, legal, privacy, communications, source-protection, and policy review as applicable

A high-tempo product may be short and preliminary, but should state its status and update trigger. Do not delay an urgent decision for polish that cannot change the judgment. Do not use urgency to bypass essential checks where error or disclosure could cause serious harm.

Maintain versions and corrections

Each delivered assessment should record:

  • title and unique identifier;
  • version and publication time;
  • assessed information cutoff time;
  • author and reviewer;
  • handling and distribution;
  • superseded versions;
  • correction history;
  • next review date or trigger.

When new evidence changes the judgment, issue an update that explains the change. When an error is found, correct it promptly and notify affected consumers through the same channels used for the original product when appropriate.

Do not silently replace a consequential assessment without preserving the prior version and correction reason. Version history supports trust and analytic learning.

Worked assessment outline

Title: Likely coordinated intrusion activity affecting Northbridge finance systems

Bottom line:

We assess at least two finance workstations were likely affected by one coordinated intrusion attempt, with moderate confidence. Similar targeted attachments, matching execution sequences, and distinct host records support a common cause. The payload, third workstation, and relationship to later identity activity remain unresolved. The incident lead should use this assessment to decide whether to broaden investigation and containment before restoring affected access.

Key judgments:

  1. Matching delivery and execution behavior is more consistent with coordinated activity than with coincidence.
  2. An authorized deployment remains plausible but currently lacks a matching change record or owner confirmation.
  3. Possible identity activity could expand the affected scope, but direct linkage is unconfirmed.

Implications and options:

  • Maintain current containment while validating authorized activity.
  • Conduct a bounded behavioral search across finance hosts and identities.
  • Delay segment-wide isolation unless new evidence indicates broader active access.

Priority gaps:

  • Recover and analyze the extracted script.
  • Validate deployment status with the software owner.
  • Obtain alternate evidence for the third workstation.
  • Determine whether the new-device sign-in used credentials exposed during the host activity.

Update trigger: New payload evidence, owner confirmation, identity linkage, or completion of the bounded search—whichever occurs first.

Final publication checklist

Before release, confirm:

  • The product answers a named requirement and decision.
  • The bottom line contains the principal judgment, likelihood, confidence, and implication.
  • Every key judgment is scoped and traceable to evidence.
  • Facts, assumptions, judgments, implications, and recommendations are distinguishable.
  • Alternatives, contradictions, gaps, and change conditions are represented fairly.
  • Confidence rationales identify source, coverage, or reasoning limitations.
  • Evidence is ordered by diagnostic value.
  • Technical detail is appropriate for the consumer or moved to an annex.
  • Tables and visuals are accurate, necessary, accessible, and sourced.
  • Handling, privacy, source-protection, and dissemination controls are correct.
  • The version, author, reviewer, information cutoff, and review trigger are recorded.
  • The product will reach the consumer in time to matter.
Key takeaways
  • Build an assessment from a consumer-centered blueprint rather than a chronology of collected facts.
  • Draft distinct key judgments before writing background and supporting detail.
  • Preserve traceability from every material claim to evidence, provenance, and limitations.
  • Review analytic reasoning, editorial clarity, and handling as separate quality dimensions.
  • Test the product with a reader who did not participate in drafting.
  • Match review depth to urgency and consequence, and preserve versions and corrections.
  • Publication is complete only when the right consumer receives an understandable, controlled, timely product.

Analyst habit: Before release, point to the sentence that answers the consumer’s decision. If no sentence does, the product is not finished.