See the whole threat.
Decide before options close.
AEIG maintains the external threat picture around the people, assets, operations, suppliers, counterparties, and decisions that matter. We identify material changes, explain what they mean, and define who must act, by when, and against which threshold.
AEIG Threat Intelligence is broader than cyber threat intelligence. The practice integrates physical, digital, geopolitical, supply-chain, counterparty, protective, and operational threat analysis. AEIG does not provide managed cyber defense, technical incident response, or protective operations under this service line.
Five domains, read as one picture.
External threats do not stay inside one function. Physical security, cyber, legal, communications, procurement, operations and outside providers each hold a piece, and exposure accumulates in the space between them. The practice is organized around what you are protecting, not around one threat category or one vendor's feed.
SELECT A DOMAIN FOR SCOPE, THE QUESTIONS IT ANSWERS, AND A WORKED SAMPLE
Geopolitical and operating-environment conditions are applied across all five domains, always tied to a named protected object and a named decision, never as a country report for its own sake. This is a lens, not a sixth domain.
PRINCIPAL AND PROTECTIVE INTELLIGENCE IS A DOMAIN WITHIN THE THREAT INTELLIGENCE PRACTICE, NOT A SEPARATE PRACTICE. IT REMAINS A COMPLETE, PREMIUM CAPABILITY DELIVERED THROUGH THE BROADER THREAT INTELLIGENCE OPERATING SYSTEM.
One ledger. Every finding owned.
The exposure ledger reads the protected object across domains as a single document: physical and site footprint, digital exposure, and counterparty surface. Every finding becomes a line item with an owner, a threshold, and a status, and the ledger is never considered closed until the actions are.
CNT / SCL · COUNTERPARTY AND SUPPLY
SAMPLE LEDGER · ENTRIES ILLUSTRATIVE · EVERY LINE CARRIES AN OWNER, A THRESHOLD, AND A VERIFIED STATUS
Diagnose, integrate, sustain.
Entry is always through a bounded, paid engagement. Nothing escalates automatically, each step is commissioned on its own merits, and a client who commissions the diagnostic and stops has received a complete product.

Integrated Threat Exposure Diagnostic
Establish the integrated threat and exposure baseline. Fixed fee, fixed scope, complete on its own terms.

Threat Intelligence Integration Sprint
Convert findings into requirements, owners, thresholds, and provider coordination.

Managed Threat Watch and Warning
Hold the baseline, warn against agreed thresholds, and brief the people who decide.
SURGE RUNS ALONGSIDE THE LADDER · INCIDENT AND CRISIS INTELLIGENCE SUPPORT IS COMMISSIONED SEPARATELY, INSIDE OR OUTSIDE A CONTRACTED COVERAGE SCHEDULE
SAMPLE COVERS · TITLES AND CODES ILLUSTRATIVE · EVERY DELIVERABLE CARRIES THE HOUSE COVER
The register of engagements.
Six primary engagement shapes and two specialist assessments. Each is fixed in scope, sourced, confidence-tagged, and passes a written acceptance gate before any work begins.
| CODE | ENGAGEMENT | SCOPE | GATE |
|---|---|---|---|
| PRIMARY ENGAGEMENT SHAPES | |||
| THR-01 | Integrated Threat Exposure Diagnostic | The integrated baseline: what you are protecting, what could reach it, and where you are exposed across all five domains, read as one picture. | FIXED SCOPE · GATED |
| THR-02 | Mission and Decision Threat Assessment | One movement, deployment, event, or window assessed against the decision it serves, with actions assigned before you commit. | PER DECISION · GATED |
| THR-03 | Threat Intelligence Integration Sprint | Findings converted into standing intelligence requirements, named owners, agreed thresholds, and coordinated provider tasking. | PROGRAMME · GATED |
| THR-04 | Managed Threat Watch and Warning | Defined-coverage monitoring against agreed indicators and thresholds, with warning routed to a named recipient on an agreed response target. | RETAINED · GATED |
| THR-05 | Fractional Threat Intelligence and Liaison Function | A standing intelligence function for organizations whose threat picture has outgrown internal capacity but does not justify an intelligence department. | RETAINED · GATED |
| THR-06 | Incident and Crisis Intelligence Support | What is known right now, how far to trust it, and what has to be decided in the next few hours. | SURGE · GATED |
| SPECIALIST ASSESSMENTS | |||
| THR-S1 | Supply-Chain Threat and Resilience Review | Suppliers, corridors, and chokepoints assessed for concentration, substitution, and the failure the client cannot absorb. | FIXED SCOPE · GATED |
| THR-S2 | Counterparty and Network Exposure Review | Ownership, control, sanctions, and network exposure around a named counterparty, anchored to a client decision. | FIXED SCOPE · GATED |
PRICING IS QUOTED PER ENGAGEMENT AGAINST DEFINED SCOPE · NO ENGAGEMENT BEGINS WITHOUT WRITTEN SCOPE AGREEMENT
One relationship per principal.
In the Principal and Protective Intelligence domain we hold one relationship per principal, full stop. No competing mandate, no adjacent engagement, no exception by fee. If we already support a principal we will not take an adverse or parallel mandate touching that principal, and we will say so. The exposure picture only works if the function that owns it answers to exactly one party, and that structure is written into the engagement before any work begins.
CROSS-PRACTICE CONFLICTS WITH MARKET OR CORPORATE AND CAPTURE INTELLIGENCE ARE DISCLOSED AND GATED BEFORE ANY COMMITMENT IS MADE
Bounded on purpose.
We do not predict threats and we do not prevent incidents. We reduce the number of decisions made without a defensible picture, and we shorten the distance between a change in conditions and an accountable response.
See where your threat picture has no owner.
Request a scoped discovery call. Thirty to forty-five minutes to establish what you are protecting, what decision is under pressure, what you already have, and where the visibility breaks. No charge, no obligation. Where there is a fit, the standard first engagement is the Integrated Threat Exposure Diagnostic.
