Intelligence pipeline

Reporting that becomes action.

Threat Intelligence Mapper takes raw reporting and returns something a defender can act on. Mapped techniques, sector relevance, and a short answer to whether this changes anything for the organisation reading it.

The gap it closes

Knowing that a campaign exists is not the same as knowing whether it matters to you.

Security teams receive far more intelligence than they can act on. The bottleneck is almost never collection. It is the translation from what somebody observed somewhere into what this organisation should check this week.

From narrative to technique

Prose descriptions of attacker behaviour become mapped techniques, which makes two reports about the same activity comparable for the first time.

From global to sector

Relevance depends heavily on who you are. The same campaign can be urgent for one sector and irrelevant to the one next door.

From technique to control

The useful output is a check. If this behaviour reached our environment, which control would have stopped it, and are we confident that control is working.

How it connects

Intelligence is most useful when compliance can hear it.

A mapped technique is only half an answer. The other half is which control was supposed to cover it and whether that control has been confirmed recently, which is where the platform work joins up.

This is the thread that runs from here into ControlGraph, and it is why threat informed prioritisation sits on the CyberNexus direction of travel rather than in a separate tool.

A threat report that ends without a check to run has told you about the weather. It has not helped you decide whether to leave the house.

What it covers

From a pile of reporting to one check.

Four steps, each of which throws away the part you did not need, so that what reaches a defender is small enough to act on.

01

Ingest whatever arrives

Vendor reporting, advisories, sector notices and research, in whatever shape they turn up in.

02

Map behaviour to technique

Prose descriptions become recognised technique references, which is the first point at which two reports about the same activity become comparable.

03

Score against your sector

Relevance depends heavily on who you are. The same campaign can be urgent for one sector and irrelevant next door.

04

End with an action

Which control was supposed to cover this, and whether anybody has confirmed it lately. A summary that ends in a check rather than a worry.

Questions we get asked

Before you get in touch

The questions that come up most often, answered the way we would answer them on a call.

Does it replace our threat intelligence feeds?

No, it sits after them. Feeds are the input. The value is in the translation from what somebody observed somewhere to what this organisation should check this week.

What does the output actually look like?

A short piece of reporting that ends in a check. Which technique, whether it is relevant to your sector, which control was meant to cover it, and whether that control has been confirmed recently.

Do you use a standard technique reference?

Yes. Mapping behaviour to a recognised reference is what makes two reports about the same activity comparable, which is the first thing that has to be true before anything else is useful.

How does this connect to the rest of the portfolio?

A mapped technique is half an answer. The other half is whether the control that was supposed to stop it is currently working, which is the join ControlGraph and CyberNexus are built to hold.

Drowning in reporting you cannot act on?

That is usually a translation problem rather than a sourcing problem, and it is a solvable one.