Home — Services

Targeted threat intelligence

The intelligence phase sets the standard the whole test inherits.

We deliver the TI phase of threat-led penetration tests under TIBER-EU and DORA and other frameworks. Scenarios grounded in real adversary behaviour, graded for confidence and source reliability, and handed to the red team in a form they can execute against.

TIBER-EU & TIBER-CZ DORA TLPT Independent of any red team

What it is

Where we sit in your test.

Under TIBER-EU, a test runs across three phases — preparation, testing and closure. In the preparation phase your authority appoints a test manager, you form a control team, and you procure two separate providers: a threat intelligence provider and a red team.

We are the threat intelligence provider. During the testing phase we produce the Targeted Threat Intelligence Report, which identifies the adversaries realistically capable of targeting your critical or important functions and develops the scenarios the red team will emulate. That report becomes the basis of their Red Team Test Plan.

Everything downstream depends on it. If the intelligence phase produces generic actors and plausible-sounding scenarios, the red team spends twelve weeks emulating a threat that was never real, and the closure phase produces findings your board cannot act on.

Why we don't do the red teaming

TIBER-EU/DORA and other frameworks require the threat intelligence provider and the red team to be separate organisations. We only sell intelligence, so there is no commercial reason for our scenarios to point towards work we would like to win. Where you have already appointed a red team, we work alongside them; where you haven't, we can point you at accredited providers without taking a fee for it.

Method

Five phases, evidenced throughout.

Each phase produces material that is carried into the report and defensible to your control team and your regulator.

01

Scoping and intelligence requirements

We confirm the engagement parameters that govern the whole deliverable — entity and sector, framework and overseeing authority, the critical or important functions in scope, critical ICT third-party providers, the research window, and the TLP marking. Intelligence requirements are agreed here, not assumed later.

02

Business and digital footprint

Your organisation assessed from an adversary's perspective: what you do, what makes you worth targeting, and what is externally observable. Attack surface, exposed services, third-party and supply chain relationships, personnel exposure and credential material already in circulation.

03

Threat landscape analysis

The actor set with genuine intent, capability and opportunity against an organisation of your profile — informed by sector reporting, your jurisdiction, and where relevant the generic threat landscape supplied by your authority. Assessed and graded, not listed.

04

Actor prioritisation and profiling

Prioritised against a documented severity scoring methodology, then profiled — objectives, known tradecraft, tooling, and the behaviour a red team would need to reproduce to emulate them credibly.

05

Scenario development and handoff

Scenarios built from the prioritised actors, each with an intelligence rationale, an end-to-end attack path and a MITRE ATT&CK TTP mapping pinned to a stated version. We confirm coverage across confidentiality, integrity and availability, document noise-sequencing, and populate the red team handoff requirements.

The deliverable

The Targeted Threat Intelligence Report.

A TLP-marked report structured for the entity, the red team and the overseeing authority to read from the same document. Full contents:

Typical duration
4–6 weeks from scoping to handoff
Default classification
TLP:RED, with TLP:AMBER+STRICT available where the engagement requires it
Source grading
Admiralty/NATO 6×6 — source reliability A–F, information credibility 1–6
Assessment language
Explicit confidence levels tied to the evidence base, with assessment, fact and assumption distinguished
ATT&CK mapping
Pinned to a stated Enterprise version and echoed on every mapping table
Format
Word document with TLP markings on every page, generated contents, distribution table and sign-off page

Standards

Never fabricate intelligence.

It is the rule the whole method is built around, and it is worth stating plainly because the incentive to break it is real.

A TTIR drives a live red team engagement and is read by your control team and your authority. Invented attributions, indicators, breach findings or citations do not stay on the page — they get emulated. A gap gets filled; a fabrication gets tested against your production estate.

Where a required input is missing, our drafts carry an explicit placeholder naming what is needed, rather than plausible filler that reads complete. Every assessment carries a confidence level. Every underpinning source carries a reliability and credibility grade, and the grading scheme in force is defined in the report rather than assumed.

A complete-looking report is not the objective. A defensible one is.

Questions

Common questions.

Which frameworks do you work under?

TIBER-EU and its national variants including TIBER-CZ, CBEST-style engagements, DORA TLPT, and STAR-FS-aligned testing. The core method is consistent; what changes is the overseeing authority, the terminology and the sign-off route.

Can you also run the red team?

No, and that is deliberate. The schemes require the two providers to be separate organisations. We deliver intelligence only.

We're not under a mandated test yet. Is this still useful?

Yes. Entities preparing for a first TLPT commonly run the intelligence phase early to understand what the test will surface, identify the critical functions that will come into scope, and give the control team time to prepare. It is considerably cheaper to find the problems before the formal engagement starts.

How does this differ from a threat landscape assessment?

A threat landscape assessment tells you who targets organisations like yours and what to do about it. A TTIR does that and then develops emulable scenarios with attack paths and ATT&CK mappings for a red team to execute. If you are not running a test, the assessment is usually the right purchase.

Who needs to be involved on our side?

Primarily your control team, plus whoever owns the critical functions in scope. The engagement is designed to keep knowledge tightly held — the blue team should not know the test is happening.

What happens after handoff?

The red team builds their test plan from our report and executes. We remain available to the control team through the testing phase for clarification, and can support the closure phase where the findings need to be traced back to the original intelligence.

Also relevant

Before and after the test.

Contact

Start with a conversation.

Thirty minutes, no pitch deck. Tell us where you are in the process and we'll tell you honestly whether we're the right people for it.