Most of these terms are used loosely in the security trade, and the looseness is where the money goes. A GSOC is not a cyber SOC. Risk intelligence is not forecasting. Protective intelligence is not guarding. Each entry below says what the term means here, keeps the distinction the field notes make, and links to the note that argues it at length.
Nothing here is a dictionary entry. Where a definition names a boundary — what a term is not, or what we decline to claim — that boundary is the useful half, and it is the half most glossaries leave out.
The measured picture of what is normal for a place, a route or a footprint. Without one there is no anomaly to see and nothing to grade a change against.
The same behaviour means opposite things in different settings — a heated argument is unremarkable at a football match and alarming in a quiet library, and the only thing that changed is the baseline. So the work is not constant alarm, which is exhausting and useless, but the patient maintenance of normal so that a genuine deviation announces itself. An analyst's edge is rarely sharper eyes; it is a better-maintained sense of normal. A baseline also decays: a route run every month or a site assessed last year stops being true as checkpoints move and districts change hands, which is the whole argument for keeping one current.
Covered in depth in “How do you actually build situational awareness?” →Also: estimative language · confidence language
A fixed, published vocabulary for how likely a judgement is — likely, unlikely, roughly even — used instead of hedging or a percentage nobody earned.
A judgement commits to what is probable in calibrated language rather than asserting false precision: a “seventy percent” with no reasoning behind it is theatre, while a clear “more likely than not, and here is why” is something you can act on. The line held is not a banned word but a defined vocabulary. Sherman Kent wrote “serious possibility” into a 1951 national estimate and then found his own colleagues had read it as anything from about 20 to about 80 percent; his fix was to publish a table of what each term meant, not to forbid the phrase. What is rejected outright is a percentage attached to a single future event — arithmetic performed over judgements, which looks measured without being measured.
Covered in depth in “What is a possible course of action (PCOA)?” →A bridge, tunnel, gate or square that closes every option at once — the single point of failure a route, a site or a family's routine quietly depends on.
Choke points are what make an alternate real or fake: two routes that both cross the same river at the same bridge are one route with extra mileage, so the shared-choke fraction is measured per pair rather than assumed. In a route package they are treated as geometric candidates flagged for confirmation, never asserted as threats — the map proposes them, the ground confirms them. The same idea scales down to a household, where the one crossing or gate that closes every option at once is worth knowing before the day it matters.
Covered in depth in “How to assess a route through a high-risk city” →Also: battle tracking
A single view of your people, the known threats and the terrain that matters, kept current so that a group reasons and decides from the same reality.
In an operations centre this is called battle tracking: a map updated continuously with positions, incidents and fresh reporting, so everyone in the room works from one version of events rather than several private ones held in different heads. Most coordination failures are not failures of information — the facts were known to someone — but failures of a shared picture, two people acting confidently on two different mental maps. It is a discipline rather than a tool: battle tracking was done on acetate over a wall map long before software, and a beautiful map nobody keeps current is worse than a rough one updated every hour.
Covered in depth in “Why do maps matter? The common operating picture” →Also: global security operations centre
A global — or physical — security operations centre: the function that keeps an organisation's picture of physical risk current and turns it into action.
A GSOC holds a live picture of what can be harmed, monitors events and indicators against it, coordinates the response when something happens, and does the analysis that decides what matters in the first place. It is not a cyber SOC. The two share a spine — establish a baseline, monitor, detect change, respond — but a cyber SOC reasons about traffic, logs and intrusions inside a network, while a GSOC reasons about places, movements, unrest, weather and threat actors in the physical world. It is also not a room: the staffed desk and the video wall are the visible part, and most of the value is the discipline. The test is not how much it sends you, but how rarely it makes you do the analysis it exists to do.
Covered in depth in “What is a GSOC (global security operations centre)?” →Also: alternate route
A second route that survives the exact event which would close the primary. If both cross the same bridge, you do not have two routes — you have one drawn twice.
The test is stated as a task: name the thing most likely to shut your primary, and confirm the alternate does not depend on it. An alternate that shares the primary's river crossing, tunnel or square is not an alternate, so the shared-choke fraction is measured per pair and the failure is stated rather than hidden. The same principle governs possible courses of action — raise options as different from each other as possible, because the more genuinely distinct they are, the more room there is to find a good one.
Covered in depth in “How to assess a route through a high-risk city” →Something observable that would tell you a scenario is developing — checkable in the world before the trigger fires, not a restatement of the worry.
Indicators are the counterweight to estimative language: they are what makes a judgement checkable by someone who is not the analyst, so a reader can check the world rather than the wording. Every scenario carries at least two, and a scenario whose indicators are not genuinely observable before the trigger fires is dropped rather than polished. The weekly Brief publishes indicators and an attention direction for each topic; a route package carries them for each leg, including the off-map ones a failing segment has to be described by.
Covered in depth in “What is a possible course of action (PCOA)?” →Assessing a movement as a whole: the regional read first, then each fixed point as a place in its own right, then the roads between them.
A journey is not a single risk. It is a chain of sites joined by movement, and the arrival point, where you stay and the destination each carry risk independent of the road — get the sites wrong and the best road in the city cannot save the trip. Journey management reads the region's baseline before anyone draws a line, grades a primary route with a genuinely independent alternate, and states plainly what has been confirmed and what has not. The crisis geography belongs to the same layer: safe havens, emergency spurs, and medical facilities graded by what they can actually treat.
Covered in depth in “How to assess a route through a high-risk city” →The person or body that actually said something, named separately from the publication that merely carried it. Confusing the two makes one voice look like many.
A wire service repeating a local official is a publication; the official is the originator. Splitting them is the first move in source grading and the reason “sourced” means more than “has links”. It is also what makes a corroboration count honest, because ten outlets repeating one anonymous post is one source amplified ten times rather than ten independent ones. Protective intelligence insists on the same separation before any alarm is raised: a worrying claim that traces back to a single anonymous post is not the same claim as one from three people who could not have coordinated.
Covered in depth in “How to read a risk report: what 'sourced' means” →Also: open-source intelligence
Intelligence built from sources anyone can reach — registries, court filings, corporate records, imagery, news — traced back to the originator, not the aggregator.
Most of what an analyst reads is already public, which is why who processes it changes nothing and the protection effort belongs on client-private material instead. The tradecraft is in provenance and grading rather than in access: an open-source claim is only as good as the originator behind it and the corroboration around it. It is also bounded, and the bounds are worth stating — an adversary would assemble a family's footprint from exactly the same public sources, and no open source we use carries a reliable trauma grade for a hospital, so we never write one.
The routine a person, family or organisation actually keeps — where it is predictable, where it can be observed, and which choke point closes every option at once.
Pattern of life is the exposure your own habits create: the school run at the same hour, the single gate everyone uses, the standing appointment anyone watching can time. It is a protective-intelligence input rather than a surveillance product — the point is to see what an adversary would assemble from open sources about the people you are responsible for, and then change what is cheap to change. A shift in someone's pattern of life is also a precursor, and like every precursor it is only visible against a baseline.
Also: course of action · PCOA
An option prepared in advance for a condition that may occur: a trigger written as a fact pattern, and ranked responses that each point at something real on the ground.
A PCOA is not a prediction that the thing will happen and it carries no probability. The trigger has to be something a person can observe under pressure and agree on — “traffic flow stops completely for more than five minutes with no visible cause” is a stopwatch; “elevated risk of disruption” is not a trigger at all. The options are assembled from objects that were measured — a graded alternate, a pre-staged spur, a facility whose drive time was checked — never generated as prose, and where no second option exists none is invented: the entry says abort and hold. “Most likely” and “most dangerous” are priority categories, not estimates.
Covered in depth in “What is a possible course of action (PCOA)?” →Identifying and understanding a threat before it reaches the person or asset it targets, while there is still time and the options are still cheap.
Physical protection manages the moment of contact — the barrier, the close protection officer, the response. Protective intelligence manages everything upstream of it, which is cheaper, quieter and far more in your control. It is not guarding and it is not blanket surveillance of everyone around a principal: it watches a narrow set of the right things, for a defined reason, and earns its keep by informing decisions rather than by collecting for its own sake. Its two failure modes are missing a real signal and raising one that is not there — a warning that proves wrong spends trust you will need the next time.
Covered in depth in “What is protective intelligence?” →A deliberate pass that argues against a conclusion before it ships — hunting the convenient assumption, the single-language source base, the missing counter-evidence.
A report worth trusting tells you that the challenge happened and what it found, even when the conclusion survived it. Where the work is automated the red team is a separate pass prompted to refute: a plausible-sounding but ungrounded scenario is dropped rather than polished, and a scenario the red team never ruled on is dropped too, because nothing survives by default. The rejections are published with their reasons — a method you can only see when it succeeds is a method you cannot audit.
Covered in depth in “How to read a risk report: what 'sourced' means” →Producing a defensible decision when the facts are incomplete and moving — sourced, weighed against the alternatives, and honest about its own limits.
Risk intelligence is not forecasting, and it is not the compliance exercise that risk management has often become. Risk management catalogues and controls the risks you already know about; it looks inward and is mostly static. Risk intelligence looks outward and stays in motion, reading the environment for what is emerging and revising as conditions change — one tells you which fire extinguishers you own, the other tells you where the smoke is coming from. Its value is not a record of calling events, because no honest practitioner has one; it is reducing the range of surprise. Two tests: can you trace the judgement back to independent sources, and does it tell you what would change its mind?
Covered in depth in “What is risk intelligence?” →A place a movement can divert to under duress — taken as the union of police, military and diplomatic posts as they exist in the sources, not a category we invent.
Safe havens are one half of a route package's crisis geography. The other half is medical, tiered by what a facility can actually treat, with anything unrecognised falling to the bottom tier rather than being flattered upward. Every segment of a journey must have medical and a safe haven reachable inside ten minutes' drive — or five kilometres where only a straight-line distance is available, with the basis recorded so the weaker measure cannot be quietly swapped in for the stronger. Segments that fail are rescued by a pre-staged emergency spur or carried as an off-map indicator, and the counts are published.
Covered in depth in “What is a possible course of action (PCOA)?” →A trained loop rather than a personality trait: perceive what is around you, comprehend what it means, and anticipate what comes next.
The three levels come from Mica Endsley's work on how operators stay oriented in demanding environments, and most failures are not failures of looking — people register the cue and do not read it, or read it and do not carry it forward. Perception without comprehension is just noticing; comprehension without anticipation is just commentary. It depends entirely on a baseline, and its most common failure is the narrowing that stress causes, which feels like focus and is actually a blind spot you cannot see. Run against an organisation's footprint rather than one person on a street, with the deviations graded, the same loop is an exposure assessment.
Covered in depth in “How do you actually build situational awareness?” →Also: source reliability · source evaluation
Grading a source before you trust it: the reliability of the source and the credibility of the claim scored as separate axes, then a decision on what to do with it.
Grading starts by splitting the originator from the publication, then scores the two axes separately on the analyst's A–F / 1–6 matrix — a source that is usually reliable can still carry a claim nothing corroborates, and collapsing the two hides exactly that case. The output is a decision rather than a label: use it, corroborate it, hold it, or discard it. It is applied to the assessments a client is handed by other people as readily as to our own, and it is what stands between a convincing claim and a costly one.
Covered in depth in “How to read a risk report: what 'sourced' means” →Independent originators, who did not get it from each other, arriving at the same fact. Volume is not corroboration — ten outlets repeating one post are one source.
A report that has done this shows you the count of independent originators behind each judgement and flags the contradictions instead of hiding them, rather than asserting that its sources agree. Triangulation is what raises confidence; amplification only raises volume, and the two are easy to confuse when a claim appears to be everywhere at once. It is the second half of the same discipline as originator-versus-publication, and it is one of the two questions worth putting to any judgement you are handed.
Covered in depth in “How to read a risk report: what 'sourced' means” →The longer arguments behind these definitions are in the field notes; the tools that apply them are in resources.