Home — Services

Managed threat intelligence

A feed with your logo on it is not intelligence.

Intelligence requirements agreed with you, collection tuned to those requirements, and every finding assessed by an analyst before it reaches your inbox. You get fewer things to read and more things worth acting on.

PIR-led collection Human-validated, never auto-forwarded Confidence and source graded Board-ready reporting

The problem

Most teams don't have an intelligence gap. They have a filtering gap.

Very few organisations are short of threat data. They are subscribed to feeds, receiving sector alerts, and pulling in open source — and the volume means the material that genuinely applies to them arrives alongside a great deal that does not.

The result is predictable. Alerts get skimmed, then filtered to a folder, then ignored. When something relevant does land, it looks exactly like the eighty items that preceded it. Nobody can tell the difference at a glance, so nothing changes as a result of any of it.

The fix is not more sources. It is deciding in advance what you actually need to know, collecting against that, and having a person assess relevance before anything reaches you.

How it works

Requirements first, collection second.

01

Priority intelligence requirements

We work with you to define what you need to know and why — the decisions the intelligence is meant to inform, who makes them, and what would change as a result. Requirements are documented and reviewed, not inferred from a sector label.

02

Collection tuned to those requirements

Collection is built around your requirements, your sector, your technology estate, your third parties and your jurisdiction. Sources are assessed for reliability rather than counted.

03

Analyst validation

Every finding is assessed by an analyst before it reaches you. Nothing is auto-forwarded. If something does not meet a requirement or does not stand up on examination, it does not get sent — and that discipline is the point of the service.

04

Reporting at two levels

Working-level reporting for the people who act on it, and periodic assessment written for the people who fund decisions. Both carry explicit confidence levels, and both distinguish assessment from fact and from assumption.

05

Review and retune

Requirements are revisited on an agreed cycle. Business changes, estates change, and adversary interest changes — a requirement set that never moves is a requirement set nobody is using.

What you receive

What lands, and how often.

Priority alerting
Analyst-validated notification where something meets a defined requirement and warrants action
Periodic assessment
Written intelligence assessment on an agreed cadence, graded for confidence
Sector and peer reporting
Adversary activity against organisations of your profile, jurisdiction and regulatory footprint
Third party and supply chain
Monitoring extended to the providers your critical functions depend on
Board reporting
Periodic summary written for a non-technical audience, framed around business impact and decisions
Analyst access
Direct access to the analyst covering your account — not a ticket queue
Requirements review
Scheduled review of your PIRs and the collection built against them

Where this fits with a regulated test

If you are running or preparing for a TLPT, the intelligence requirements defined here carry directly into the engagement, and the picture stays current between tests rather than being rebuilt from scratch every cycle. See targeted threat intelligence.

Questions

Common questions.

How is this different from a threat intelligence platform?

A platform gives you somewhere to put data. This gives you an analyst who decides what is worth your attention and writes down why. The two are complementary, but buying a platform without analyst capacity is how most organisations end up with a filtering problem in the first place.

We already have a feed subscription. Does this replace it?

Not necessarily. Feeds are a collection source. This service defines what you need, uses appropriate sources including any you already hold, and assesses what comes out. In some cases the review shows an existing subscription is not earning its cost.

Will you send us indicators to load into our tooling?

Where indicators are relevant and reliable, yes. But indicators age quickly and rarely change a decision on their own — the value sits in the assessment of who is interested in you and what they are likely to do next.

How much of our time does this take?

The requirements phase needs real input from you, because the service is only as good as the requirements it runs against. After that the commitment is a periodic review and whatever time you spend acting on what arrives.

Can you act as our threat intelligence function?

For smaller teams, effectively yes — the service can operate as an embedded intelligence capability rather than a subscription, including representing the intelligence function in internal governance.

Also relevant

Where this leads.

Contact

Start with a conversation.

Thirty minutes, no pitch deck. Tell us what you're currently receiving and we'll tell you honestly whether we'd improve on it.