Threat, Risk and Privacy Assessment
How the Assessment Organizes Risks
Understand which answers inform the analysis, how priorities are determined and where additional evidence is needed.
Start the AssessmentTailored Coding’s tool is a rules-based self-assessment. Your browser connects the answers to conditions defined in the algorithm and produces a report for each activity. It does not interview you through an AI model or send your answers to an AI service to generate recommendations.
Context Comes First
You can assess one to six activities. For each, you describe the work, the information involved, who receives it, the consequences of a problem and whether a relevant event is approaching. General context includes personal safety, a possible incident, authority to act and available resources.
Questions cover accounts, devices, communications, suppliers, continuity, personal data and other aspects of the activity. Your profession helps contextualize the guidance; on its own, it does not establish a threat or prove that a control works.
How Answers Are Interpreted
The algorithm first checks whether a scenario applies. It then distinguishes a control reported as absent or partial from one reported as present or tested. “Unknown”, declined answers and unanswered fields remain uncertainties; they are not converted into confirmed protection.
Some combinations need clarification. For example, excluding personal-data processing while selecting information about identifiable people produces an inconsistency to review. The report keeps that uncertainty visible.
How Priorities Are Determined
Priority combines the scenario’s applicability, the reported control, impact and the proximity of an event. A known gap with material consequences may require remediation; an unknown control may need verification before a decision. A reported existing control receives maintenance and review guidance, without certification by the tool.
Physical danger, possible coercion, an unsafe device and reported incidents receive specific treatment. These conditions can change the order of guidance and restrict export. Changes requiring an administrator or owner remain subject to that person’s authorization.
An Example Using Fictional Answers
Consider an activity involving online accounts, severe impact and an imminent event. If authentication is absent, the corresponding rule identifies a priority to address now. If authentication is unknown, the guidance becomes verification before the event. If the control is reported as tested, the recommendation is to maintain and review it.
This example illustrates the prioritization rule; it does not describe a real person, client or incident. Other answers can introduce safety restrictions or additional priorities. “Tested” remains information supplied by the user, not an inspection performed by Tailored Coding.
What You Can Check in the Report
Each finding identifies the activity, rationale, relevant answers, unknowns and a suggested action. The report also provides possible owners, effort, verification steps and references. Excluded scenarios, inconsistent answers and matters requiring specialists remain distinguishable.
The analysis does not calculate statistical attack probabilities or a security score. It does not run scans, penetration tests or real-time threat-intelligence collection. Technical audits, incident investigations, legal opinions, certifications and data-protection impact assessments require separate work.
What Stays in Your Browser
The questionnaire and report operate without analytics tools and do not automatically transmit answers to our team. You decide whether to export or send a report, subject to the safety conditions indicated by the tool. A separate contact form supports end-to-end encrypted submission.
This public methodology page uses the introduction’s statistical configuration, with analytics and advertising storage disabled. Saved files, browsing history and information retained by the device itself require care by its user.
When to Revisit the Assessment
Repeat the assessment when activities, data, suppliers, access or controls change. The report identifies the rules version and the guidance reference date so that you can identify the material used. Time-sensitive information needs confirmation before a decision.
The research considers NIST SP 800-30, NIST CSF 2.0, OWASP, NIST PRAM, LINDDUN, EFF, CPJ, CERT.br and Brazil’s ANPD. These inform the method; they do not constitute certification or endorsement by those institutions.
If the results identify issues requiring technical analysis, our team can discuss the context, available evidence and a scope of work with you.