skip to content

What does bottom line up front mean in a threat intelligence report, and what belongs in it?

level: middleimportance: should knowfreq 56%

answer

  1. assume they read only paragraph one
  2. judgement before method
  3. the so-what is about us, not the world
  4. name the action, the owner, the date

basics

~20 s

Bottom line up front means the opening lines carry the judgement and the recommended action, not how the research was done. A reader who stops after the first paragraph still leaves with the conclusion and the decision they have to take.

solid answer

~50 s

Write for a reader who may only read the first paragraph, because that is who you have. The opening carries four things: **what changed**, **what it means for us specifically**, **what we recommend**, and **who owns that recommendation and by when**. Everything after it is evidence for the reader who wants to check you. So an opening reads like: an extortion crew active against retailers has stopped encrypting and now exfiltrates and threatens to publish; our merchandising file share holds the data that model monetises and has no volume monitoring; we recommend the divisional VP fund data loss monitoring on that share this quarter. The failure mode is the academic shape — background, sources, methodology, findings, and the conclusion on page four. That structure is written for the author's process rather than the reader's decision, and the person you needed stopped reading at `Background`.

code

text · 14 lines
text
THREAT NOTE 26-114 - Retail sector extortion activity

1. Background
Between March and July the intelligence team reviewed reporting
on extortion activity affecting the retail sector, including a
peer retailer's public disclosure, a sector letter issued by the
regulator, and two of our own closed cases from last year.

2. Methodology
Each case was reviewed against our internal case notes and
cross-checked for overlap ...

3. Findings
... (the judgement and the recommendation appear on page 4)

go deeper

for a junior

Know what bottom line up front means and be able to say what the first paragraph contains: the judgement, why it matters to us, the recommended action and its owner. Be ready to spot a report that opens with methodology.

for a middle

Explain the mechanics — inverted-pyramid ordering, the so-what clause, and why an ask needs a named owner and a date. Show you can rewrite a buried opening into two or three sentences that carry the decision.

for a senior

Demonstrate judgement about what to cut. Interviewers look for the ability to size a product to the forum, to state a conclusion you can be held to, and to write a recommendation concrete enough that someone can say no to it.

for a principal

Own the writing standard across the team: a house structure, a rule that every product names an owner and a date, and a willingness to reject a draft whose ask cannot be refused. That standard is what keeps the function's output decision-shaped.

## Why the order is the whole technique An intelligence product is not a record of your work. It is an instrument for moving a decision, and it is read by someone whose attention you get for perhaps ninety seconds before they triage it against everything else in their morning. **Bottom line up front** — a discipline borrowed from military staff writing — means the first lines carry the conclusion and the ask, and the supporting material comes after in decreasing order of importance. A reader who stops anywhere still has everything above where they stopped, and everything above is the most important part. ## What the opening must contain Four elements, in roughly this order: 1. **The judgement.** One sentence saying what you now believe to be true, in the active voice, about a named actor or activity. Not "this report examines" — that says nothing. 2. **The so-what for us.** The judgement is about the world; this clause is about our estate. If the crew monetises stolen commercial data and our merchandising file share is exactly that, say so. Without this clause the reader silently supplies "so this is somebody else's problem", and they are usually right to. 3. **The recommendation.** A specific action, not an aspiration. 4. **The owner and the horizon.** Who can actually do it, and by when it matters. A recommendation with no owner is an observation. The rest of the document — the evidence, the cases, the technique detail, the annexes — exists so that a reader who wants to challenge you can. Most will not, and that is fine. ## The so-what clause is the one people drop A report that says a crew is targeting the retail sector is describing the news. A report that says the crew's model depends on bulk access to commercial data, that our merchandising share carries that data, that eleven hundred accounts can read it and nothing watches how much any of them takes, is describing us. The second one gets funded. The evidence for both is identical; the difference is a sentence of analysis the author had to be willing to commit to. ## Recommendations that are not recommendations `Continue to monitor` is the most common non-recommendation in intelligence writing. It names no decision, no owner and no change, so nothing happens and nobody can tell that nothing happened. If monitoring genuinely is the answer, make it real: say what would change the judgement, who is watching for it, and when you will revisit. Similar empty forms: `raise awareness`, `consider reviewing`, `ensure controls are adequate`. Each of them survives the meeting precisely because nobody can refuse them. **A recommendation an owner can refuse is a good recommendation.** Refusal means the ask was concrete enough to have a cost, and a documented refusal with the risk stated is a real outcome. An ask so soft it cannot be refused produces nothing you can point at later. ## Length is set by the forum, not by the evidence If your slot is fifteen minutes at a quarterly risk committee, the note is a page. That is not a compromise on rigour; it is the constraint the product exists inside. The evidence goes into annexes for the person who asks. Writing six pages because you have six pages of research is writing for yourself. ## What good looks like in the room A well-formed opening lets a reader who never gets past it repeat your conclusion accurately to someone else and know what they are being asked to do. That is the test. If the first paragraph could be deleted without changing what the reader can do, you have written a preface rather than a bottom line. ## Common structural traps - **Burying the judgement inside the evidence** so it reads as an inference the reader should draw themselves. They will not draw it, and if they do they will draw a different one. - **Leading with sourcing.** How you know matters and belongs in the body; it is not the point of the document. - **Hedging by deferral** — pushing an uncomfortable conclusion to the end so it feels less exposed. If you are not confident, say what you believe and how strongly in the same breath, up front. - **Ending on the recommendation** as a rhetorical climax. That is essay structure. Your reader is not reading an essay.

  • Your recommendation reads "continue to monitor" — is that a recommendation?
    No. It names no decision, no owner and no change, so it cannot be refused and cannot be tracked. If monitoring really is the answer, write what specifically would change the judgement, who is looking for it, and the date you will revisit — that version has an owner and can be checked.
  • How do you handle a reader who wants the full evidence?
    Keep the front page as the decision instrument and put the evidence in annexes or a linked companion product. The reader who challenges you is rare and welcome; designing the whole document around them costs you the readers who only ever see the first paragraph.

saying these in an interview costs you the question

  • Opens with background, sources and methodology
  • Places the recommendation last as a conclusion
  • Writes continue to monitor as the recommended action
  • Describes the threat generically with no clause about our estate
  • Sizes the document by the volume of research rather than the forum

context