Assessment Methodology for Cyber Threat Intelligence Maturity

The Cyber Threat Intelligence Maturity Model is build up from 2 pillars, 5 domains, and 12 focus areas. We analyzed and decomposed each of the focus areas into 29 process groups and 83 concrete business processes and activities that organisations run to realize their cyber threat intelligence program. Not all of these business processes will be of equal importance, for example, a large multinational requires a different CTI generation and support structure than a small- or medium enterprise. Furthermore, an organisation just starting with CTI will pursue different activities than organisations with a mature program.

CTIM: A novel CTI maturity model.
Maturity Decomposition and Maturity Assignment

We hence rank each business process and rate it with a maturity level ranging from 0 to 5. In other words, determine whether this is an essential activity for the successful start of a CTI program, whether it will provide benefit only later on once the business processes around the generation, integration and support of threat intelligence have sufficiently matured, or it is an activity only relevant for highly advanced use cases.

CTIM: A novel CTI maturity model.

In the CTIM self-assessment, we ask you a set of 250 questions. These questions allow us to assess which activities you are currently pursuing, to which extent you are implementing these processes, and how these processes integrate throughout your organisation. From this, we compute your maturity at the level of focus areas and domains, as shown below, and thus provide you with very detailed insight on your current level of cyber threat intelligence in your organisation. Furthermore, we provide you with an assessment report, that includes recommendations and a roadmap to further develop the CTI program in your organisation.

Your Current CTI Maturity and Opportunities for Improvement

Cyber Threat Intelligence within organisations.

After the survey, you will receive a report characterizing your current CTI activities, and the maturity of the CTI program in your organization. This analysis includes a classification of the maturity of your entire CTI program, as well as an investigation by domain and focus area.

In addition to this, your report also contains a list of recommendations on how to bring your current CTI activities to the next level and increase the returns you can gain from your program. Ranked by importance and impact to advance your organization as a whole, we determine focus areas to concentrate on to achieve the next level of maturity. For each of the focus areas, we recommend measures and activities that you could deploy or focus your attention on as a next logical step, and supply specific examples. This provides you with input to your personal roadmap to develop and further improve your CTI program.

Your Cyber Threat Intelligence Maturity Level:
Determine your CTI maturity level and receive your personalized report here.