Targeted threat intelligence
We deliver the TI phase of threat-led penetration tests under TIBER-EU and DORA and other frameworks. Scenarios grounded in real adversary behaviour, graded for confidence and source reliability, and handed to the red team in a form they can execute against.
What it is
Under TIBER-EU, a test runs across three phases — preparation, testing and closure. In the preparation phase your authority appoints a test manager, you form a control team, and you procure two separate providers: a threat intelligence provider and a red team.
We are the threat intelligence provider. During the testing phase we produce the Targeted Threat Intelligence Report, which identifies the adversaries realistically capable of targeting your critical or important functions and develops the scenarios the red team will emulate. That report becomes the basis of their Red Team Test Plan.
Everything downstream depends on it. If the intelligence phase produces generic actors and plausible-sounding scenarios, the red team spends twelve weeks emulating a threat that was never real, and the closure phase produces findings your board cannot act on.
TIBER-EU/DORA and other frameworks require the threat intelligence provider and the red team to be separate organisations. We only sell intelligence, so there is no commercial reason for our scenarios to point towards work we would like to win. Where you have already appointed a red team, we work alongside them; where you haven't, we can point you at accredited providers without taking a fee for it.
Method
Each phase produces material that is carried into the report and defensible to your control team and your regulator.
We confirm the engagement parameters that govern the whole deliverable — entity and sector, framework and overseeing authority, the critical or important functions in scope, critical ICT third-party providers, the research window, and the TLP marking. Intelligence requirements are agreed here, not assumed later.
Your organisation assessed from an adversary's perspective: what you do, what makes you worth targeting, and what is externally observable. Attack surface, exposed services, third-party and supply chain relationships, personnel exposure and credential material already in circulation.
The actor set with genuine intent, capability and opportunity against an organisation of your profile — informed by sector reporting, your jurisdiction, and where relevant the generic threat landscape supplied by your authority. Assessed and graded, not listed.
Prioritised against a documented severity scoring methodology, then profiled — objectives, known tradecraft, tooling, and the behaviour a red team would need to reproduce to emulate them credibly.
Scenarios built from the prioritised actors, each with an intelligence rationale, an end-to-end attack path and a MITRE ATT&CK TTP mapping pinned to a stated version. We confirm coverage across confidentiality, integrity and availability, document noise-sequencing, and populate the red team handoff requirements.
The deliverable
A TLP-marked report structured for the entity, the red team and the overseeing authority to read from the same document. Full contents:
Standards
It is the rule the whole method is built around, and it is worth stating plainly because the incentive to break it is real.
A TTIR drives a live red team engagement and is read by your control team and your authority. Invented attributions, indicators, breach findings or citations do not stay on the page — they get emulated. A gap gets filled; a fabrication gets tested against your production estate.
Where a required input is missing, our drafts carry an explicit placeholder naming what is needed, rather than plausible filler that reads complete. Every assessment carries a confidence level. Every underpinning source carries a reliability and credibility grade, and the grading scheme in force is defined in the report rather than assumed.
A complete-looking report is not the objective. A defensible one is.
Questions
TIBER-EU and its national variants including TIBER-CZ, CBEST-style engagements, DORA TLPT, and STAR-FS-aligned testing. The core method is consistent; what changes is the overseeing authority, the terminology and the sign-off route.
No, and that is deliberate. The schemes require the two providers to be separate organisations. We deliver intelligence only.
Yes. Entities preparing for a first TLPT commonly run the intelligence phase early to understand what the test will surface, identify the critical functions that will come into scope, and give the control team time to prepare. It is considerably cheaper to find the problems before the formal engagement starts.
A threat landscape assessment tells you who targets organisations like yours and what to do about it. A TTIR does that and then develops emulable scenarios with attack paths and ATT&CK mappings for a red team to execute. If you are not running a test, the assessment is usually the right purchase.
Primarily your control team, plus whoever owns the critical functions in scope. The engagement is designed to keep knowledge tightly held — the blue team should not know the test is happening.
The red team builds their test plan from our report and executes. We remain available to the control team through the testing phase for clarification, and can support the closure phase where the findings need to be traced back to the original intelligence.
Also relevant
Contact
Thirty minutes, no pitch deck. Tell us where you are in the process and we'll tell you honestly whether we're the right people for it.