Every adversarial threat assessment I have trusted began with the same two questions. What exactly are we protecting, and who would want to harm it?
Bruce Braes put it simply in a 2025 interview with Security Systems News: “You need to think like the adversary, because they’re not following the rulebook.”
A generic threat picture tells you what is out there. It cannot tell you who wants to disrupt this organisation, this site, this project or this event, whether they intend to, and whether they could.
The question I have been working on is whether the structured legwork behind that judgement can be done far faster, while leaving the judgement itself with the analyst. This article walks through one assessment from start to finish, including how the analyst and the system work through the findings together.
The worked example: a Christmas market in Leeds
I needed a subject I could publish without exposing anyone’s real threat profile. So I invented one: the Leeds Millennium Winter Market 2026, run by a fictitious operator, Northlight Events Ltd, in Millennium Square from 13 November to 23 December.
The market has around 90 timber chalets, a 600-seat beer hall and a stage, with up to 5,000 people on site at peak. The market and its operator are invented. The location, the sources and the crime data are all real.
The assessment starts with the analyst defining the subject, and this is the first place the human sets the guardrails. I chose the threat vectors in scope (physical, cyber and human). I left out technical threats, because counter-eavesdropping is not a concern for a Christmas market. I rated its visibility as Medium against the system’s own definitions, as a regional event with local media coverage.
I also added proprietary context, the kind of insight public sources cannot provide: pickpocketing on busy weekend evenings last season, alcohol-related disorder near the beer hall after 20:00, a critical social media post by a local activist group, and stewards’ concerns about crowding at the main entrances.

Defining the subject. The analyst sets the scope, the visibility and the proprietary context before any research begins.
You can’t protect what you don’t understand
Before it looks at a single threat, the system builds the context: the venue, the operator, the surrounding area and the regulatory environment the event operates under. It did this in under five minutes. Done properly by hand, I would expect that to take an experienced analyst at least a couple of hours.
Most of it was right. It placed the square correctly in Leeds’s civic quarter, alongside the Civic Hall, Town Hall and City Museum, picked up its standing capacity of around 6,000, and worked through licensing and payment card obligations.
What it had not done was look at the most obvious precedent. So I asked it to research attacks on Christmas markets across Europe over the last decade. It came back with the cases any practitioner would expect, Berlin in 2016, Strasbourg in 2018 and Magdeburg in December 2024, where six people were killed and more than 300 injured. I checked each one against its source before accepting it.
That exchange set the pattern for the rest of the assessment. Time spent verifying the context is never wasted, because every threat that follows is built on it. Anything left unchecked there carries into the threat analysis, the narrative and, eventually, the risk picture.
Only when I was satisfied did I confirm and lock the context.
The threat picture in under five minutes
With the context locked, Talon identified 13 threats in under five minutes. My own estimate for doing the same work by hand is two to three hours.
For each threat it names the likely actor, assesses their intent and capability, rates its confidence and cites every source it relied on. Its suggested threat level sits beside the analyst’s own, so you can see at a glance where you have agreed and where you have overruled it.
The research draws on a controlled set of sources rather than the open internet: an aggregation of more than 750 news and intelligence sources in multiple languages, government advisories such as MI5 and Counter Terrorism Policing, sector sources such as UK Finance and the NCSC, and official police data. The source set can be tailored to what an analyst’s own work relies on.

The threat table. Hovering over a source shows exactly what was retrieved: here, UK Police Data for a 5 km radius around the site, September 2025 to August 2026.
The biggest improvement since my first test run is the police data. Talon now draws recorded crime for the area straight from data.police.uk. Within 5 km of the square, that came to 61,010 recorded offences over 12 months, including 805 thefts from the person.
A 5 km radius takes in most of central Leeds, so that is a baseline for the city centre rather than a picture of the square itself. The system said so itself, noting that the concentration on busy weekend evenings during the market season would be considerably higher.
Every point on the map traces back to an official record. Open one and you see the offence, the month, the outcome and a link to the source.

Twelve months of police-recorded crime around Millennium Square, with a single record open: a violent crime in April 2026 near Jacob Street, about 350 m from the square. Investigation complete, no suspect identified.
Two other details stood out. One threat, crowd crush at the entrances, was tagged as having no hostile actor at all. That is a safety risk rather than an adversarial one, and I am genuinely interested in whether others would keep it in a threat assessment.
The system was also candid about its limits. It rated its overall confidence as Medium-High, explained why its cyber findings were only Medium, and listed the sources it could not reach, from conflict event data with nothing inside the radius to event licence conditions that are not published.
The analyst and the machine, working together
This is the part of the exercise I most wanted to show. Every output is a draft until the analyst has verified it, and the system is built to be questioned.
Take Martyn’s Law. The draft narrative concluded that enhanced tier obligations applied to the event, and set out the duties in detail. A finding like that goes in front of a client, so it is exactly the kind of statement an analyst should verify before accepting.

The draft finding, before verification.
There were two things to test. The Terrorism (Protection of Premises) Act 2025 is not yet in force, and an open-access market with no entry checks or ticketing is a complex case under the Act’s tests for a qualifying event.
So I put the question to the system in the reviewer chat. It worked through the Act, came back with a sharper answer and updated the executive summary and the affected threat paragraphs. Its revised position was that the Act is not yet in force, that the market’s status as a qualifying event is uncertain, and that the operator should still align with enhanced tier good practice. Along the way it also removed a passing reference to firearms that no source supported.


Left: the analyst’s question and the start of the system’s reasoning. Right: what changed and why, set out for the assessor section by section.
I took the same approach elsewhere. Where a finding leaned on a source the system had not retrieved, or a precedent that did not quite fit, I asked it to show its evidence. It either supported the point or withdrew it.
This is the interaction I set out to build. The analyst can always override the machine, but in practice a short exchange of question and answer usually settles it. Together they reach a more accurate assessment far faster than either could alone.
It also showed where verification pays off most. A judgement set in the context stage carries into everything built on it, so that is where a careful analyst spends their time.
The system did the structured legwork in minutes. The analyst verified it, sharpened it and signed it off.
A threat assessment is one side of the risk triangle
Talon is the AI threat assessment skill within HawkSight Nexus, our next generation security risk management platform. It was never meant to stand alone, because a threat on its own tells you little about risk.
Risk only emerges when you bring together what you are protecting, what threatens it and how exposed it is. In Nexus, Talon is one stage in that sequence:
- Asset identification. The people, sites, information and operations that the organisation depends on, and how critical each one is.
- Threat identification. The work shown in this article, carried out by Talon: who might act against the subject, and with what intent and capability.
- Threat to asset mapping. Pairing each threat with the specific assets it could affect, because a vehicle attack and a compromised payment terminal do not threaten the same things.
- Vulnerability assessment. How exposed each asset is to each threat it faces, given the controls already in place.
Together, those give you a risk profile you can defend in front of leadership. At every stage, the analyst reviews, edits and accepts what the system proposes before anything moves on.
Why I built it, and where it is today
I have spent a good deal of time talking about the challenges in our profession. Over the past year I have tried to spend more of it building tools that help security professionals overcome them.
What you see here is the first iteration of Talon, due for release in the new year. Since my first test run, we have added official UK police data and a crime layer on the map, and every update an analyst makes is being carried through to the narrative and the map as well as the threat table.
Like the rest of the HawkSight platform, Talon will keep improving after release, driven by extensive testing and by feedback from both our testers and our clients.
So here is my invitation. If adversarial threat assessment is your profession, I would genuinely value your challenge. Tell me where the analysis is wrong, which threats you would add or remove, and where you would draw the line between collection and judgement.
If you would like to see Talon working on a subject of your own, get in touch at info@hawksightsrm.com and I will happily walk you through it.
The Leeds Millennium Winter Market 2026 and Northlight Events Ltd are fictitious, created for this case study. Crime data is from data.police.uk, September 2025 to August 2026.

