Scope reframing

Reframing a dual-use research pile into something defensible

A pile of threat research that could become a security knowledge base or a monitoring tool. I scoped the first and put explicit guardrails around the second.

Separated per source before anything was built on them
Facts vs assumptionsSeparated per source before anything was built on them
Curated documentation, source map, taxonomy, defensive guidance
Narrow first productCurated documentation, source map, taxonomy, defensive guidance
Monitoring, scraping and actor tracking deferred behind explicit conditions
Gated future scopeMonitoring, scraping and actor tracking deferred behind explicit conditions

The client

An internal research effort covering mobile and telecom attack surfaces, spam-call intelligence and coordinated information operations in one European market — material assembled without a defined product behind it.

The engagement

A scoping pass: read the source material, state what it actually is, define a narrow first product and place the rest behind explicit legal and ethical conditions.

The problem

A research pile with no product behind it invites the most exciting interpretation: build live monitoring, track the actors, score the risk automatically. That interpretation carries legal, evidentiary and reputational exposure — naming accounts and actors has consequences — and some of the underlying material is dual-use, describing attack techniques as well as defences. There was also a provenance problem: at least one source was a summary of an artefact that no longer existed.

What I did

I started by saying what the material actually was, which was not a project: no requirements, no backlog, no stakeholders, no approvals — a research pack. Then I reframed the problem into something buildable and defensible: a source-aware knowledge base that explains the threats, separates fact from assumption, and produces defensive recommendations people can act on. Everything resembling live monitoring, platform scraping, actor tracking or automated scoring was named explicitly and placed behind stated legal, ethical and technical conditions rather than left as an implied roadmap, because unstated future scope in this domain is how a research exercise becomes a liability. Each source was assessed individually for evidentiary weight — including the one that turned out to summarise a generated artefact nobody could produce — and the material needing editorial and source validation before publication was flagged as such rather than treated as finished.

What was built

A narrow first product — curated documentation, source mapping, a risk taxonomy and actionable defensive recommendations — with live monitoring, message-platform scraping, actor tracking and automated risk scoring explicitly deferred behind legal, ethical and technical guardrails, and each source assessed for whether it is primary evidence or a summary of something generated elsewhere.

On the table at the end

  • Source assessment: what each document is, what it contains, what it is worth as evidence
  • Reframed problem statement and narrow first scope
  • Risk taxonomy and defensive recommendations
  • Gated future scope with stated legal and ethical conditions

What it changed

Converted an ambiguous, partly dual-use research pile into a defined and defensible first deliverable, with everything that carries legal or ethical exposure moved into a deliberately gated future scope rather than drifting into the build.

How it ran

  1. 01

    Say what it is

    Not a delivery project: no requirements, backlog, approvals or architecture — a research pack, stated plainly before scoping.

  2. 02

    Assess each source

    Primary evidence, secondary summary, or unverifiable — recorded per document with the reason.

  3. 03

    Reframe to something buildable

    A source-aware knowledge base with a risk taxonomy and defensive guidance as the first product.

  4. 04

    Gate the exciting half

    Live monitoring, scraping, actor tracking and automated scoring deferred behind explicit legal, ethical and technical conditions.

  5. 05

    Flag what is not publishable yet

    Translated and dual-use material marked as needing editorial and source validation rather than passed off as finished.

Something similar on your plate?

Thirty minutes, no deck. I will tell you whether it is worth doing at all.