Skip to main content

Methodology

SafetyLens's assessment process is adapted from the SAFETAG framework, a professional methodology for digital-security assessments with at-risk organizations and independent media. This page is a plain-language overview; the full methodology documentation is being prepared.

Assessment methodology adapted from the SAFETAG framework.

The assessment in broad strokes

  1. Context

    Before any technical questions, the assessment captures who the organization is, where it operates, what stress it is under, and what a bad outcome would look like for its work.

  2. Critical processes and assets

    The organization identifies the activities that must keep working — publishing, case work, payments — and then the people, devices, accounts, and information each one depends on.

  3. Threat modeling

    Using that map, the assessment works through plausible threats: who might interfere with the work, what they would target, and how. Threats are scored by likelihood and impact.

  4. Findings and recommendations

    Answers become findings with severity ratings and clear rationale. Each finding links to practical recommendations sized to the organization's capacity.

  5. Roadmap

    Recommendations are sequenced into a 30/60/90-day roadmap so improvement starts immediately and progress is trackable.

A note on how assessments should feel

An assessment should leave an organization stronger, not alarmed. Questions are phrased without blame, findings are written plainly, and recommendations start with what the organization can actually do this month.

Curious how assessment data is handled? See the privacy principles.