Guides · Methods · Open data
Digital intelligence resource centre
Resources built to turn a complex topic into a documented decision: practical steps, expected evidence, useful indicators and reusable controls.
- 4
- in-depth guides
- 16
- verifiable controls
- 4
- maturity levels
Updated 14 September 2026
Four guides to frame, verify and act
Each guide works independently or with the shared matrix to prepare an assessment, workshop or roadmap.
OSINT guide: produce reliable decision intelligence
A six-step method for turning scattered open sources into a traceable, nuanced and actionable brief.
Read the guideCyber exposure assessment: a prioritised checklist
Inventory what is visible, connect exposure to business assets and turn findings into a verifiable risk-reduction plan.
Read the guideAI agent governance: a production readiness guide
Frame permissions, data, tests, oversight and shutdown before an agent is trusted with a business process.
Read the guideSEO, AEO and GEO: an SXO-led roadmap
Connect indexing, direct answers, citation readiness and conversion in one measurable content architecture.
Read the guideOperational data
Digital maturity matrix — 16 verifiable controls
An open framework to assess the existence, application, evidence and management of essential controls. It is not a certification: it makes gaps easier to discuss and prioritise.
Assessment scale
No stable practice or usable evidence.
Occasional practice dependent on one person.
Documented, applied and verifiable control.
Measured, reviewed and improved control.
| Domain | Verifiable control | Minimum expected evidence |
|---|---|---|
| OSINT | Decision question defined before collection | Dated brief with scope, audience and expected decision |
| OSINT | Sources classified by origin, date and reliability | Source log and explicit scoring rule |
| OSINT | Facts, hypotheses and unknowns kept separate | Analysis note with confidence levels |
| OSINT | Sensitive information minimised and protected | Retention rule and access register |
| Cybersecurity | Inventory of exposed assets maintained | List of domains, services, accounts and owners |
| Cybersecurity | Critical access protected by resistant MFA | Coverage report and approved exceptions |
| Cybersecurity | Patches prioritised by exposure and impact | Dated remediation queue and closure evidence |
| Cybersecurity | Backups restored during a test | Report from the latest restoration test |
| AI agents | Agent purpose, limits and owner documented | System card and responsibility matrix |
| AI agents | Allowed and prohibited data identified | Data classification and applied filters |
| AI agents | Sensitive answers evaluated on a test set | Results, acceptance thresholds and known errors |
| AI agents | Logging and manual stop available | Execution logs and shutdown procedure |
| Visibility | Search intents connected to useful pages | Intent, page, action and metric map |
| Visibility | Entities, authors and dates are explicit | Consistent visible markup and structured data |
| Visibility | Mobile journeys and performance controlled | Field measurements and key action tests |
| Visibility | Conversions connected to entry content | Dashboard by page and business objective |
How to use the matrix
- 01
Score facts
Assign a level from observable evidence, not an intention or a purchased tool.
- 02
Connect to risk
Prioritise controls that protect a critical asset, sensitive decision or important customer journey.
- 03
Name an owner
Give every action an owner, due date and simple validation criterion.
- 04
Run it again
Retain evidence and reassess after major change, an incident or at least annually.
