From victim reports to national advisories
PISA, as a community CERT, runs intelligence the way national CERTs do — but with citizen-grade sources:
Collection: portal scam-gallery submissions (defanged, PII-redacted), volunteer field reports from awareness sessions, NCCIA/PKCERT/PTA public advisories, open-source reporting (Dawn/Tribune/Express cyber coverage), platform abuse reports, honeypot telemetry where lawful.
Processing: defang everything (hxxp, 03xx-xxx-xxxxxxx), dedupe by campaign fingerprints (same mule-account patterns, same lure templates), tag by audience (who's being hit: seniors? students? chambers?).
Analysis products:
- Scam alerts (24–48h): new active campaign → gallery + WhatsApp-shareable card + advisory
- Campaign reports (weekly): trends, targeting shifts, infrastructure overlap
- Quarterly landscape (strategic): sector risk, SDG-aligned impact metrics for PISA leadership & government partners
Dissemination discipline: advisories cite sources, mark confidence levels (assessed/likely/highly likely), never name unconvicted individuals, and coordinate with PKCERT on national-significance items.
Measuring impact: scam-gallery takedown requests filed, reduction in repeat submissions of known scams, awareness-quiz score deltas by city — intelligence that doesn't change behavior is trivia.
