Cosive
What our customers say about us
“Cosive brought a high level of expertise and depth of knowledge to our engagement, and from the outset they were collaborative in developing the engagement methodology and deliverables.”
— Sasenka Abeysooriya, Program Director
Cosive
Why work with us

Threat intelligence expertise you can trust

Threat modelling and analysis — identifying the adversaries, techniques, and attack paths most relevant to your organisation
Extensive experience in CTI triaging and workflow development — helping teams build repeatable processes for handling, prioritising, and acting on intelligence
Built & operated sharing communities for national CERTs and government agencies
Deep expertise in threat intelligence frameworks — MITRE ATT&CK, CTI-CMM, STIX/TAXII
Terry MacDonald presenting at NZITF
Cosive co-founder Terry MacDonald presenting at the NZITF Conference.

Results from our threat intelligence engagements

50+
Threat intelligence platform deployments worldwide
12
Countries with active deployments
1M+
Indicators processed daily
99.9%
CloudMISP platform uptime
24/7
Monitoring and support

How organisations are sharing threat intelligence

Real results from real engagements across threat intelligence sharing, national programmes, and threat intelligence platform migrations.

Australian government building
Government

Australian Cyber Threat Intelligence Sharing (CTIS)

How Cosive designed and built the infrastructure for Australia's national cyber threat intelligence sharing program, connecting government agencies and critical infrastructure operators.

European infrastructure
Critical Infrastructure

European ISAC Threat Intelligence Sharing Platform

Deploying a managed threat intelligence sharing platform for a European sector ISAC, enabling cross-border threat intelligence exchange between member organisations.

Government security operations
Government

Government Agency TIP Migration

Migrating a government security agency from a legacy TIP to CloudMISP, improving feed management, correlation, and sharing workflows.

View all case studies

How we help you consume threat intelligence

If you're standing up a threat intelligence capability for the first time — or formalising one that's been ad hoc — you're probably feeling the pressure from multiple directions:

  • Regulations like NIS2, DORA, and Australia's SOCI Act are raising the bar on how you identify, assess, and respond to threats
  • Boards and executives want regular threat briefings
  • Your team is already stretched

You don't need to solve all of this at once. We help you start consuming threat intelligence in a structured way — connecting your feeds, analysts, and security tools through a platform that:

  • Ingests indicators from commercial feeds, open-source intelligence, and sharing communities
  • Distributes enriched IOCs to your SIEMs, firewalls, and infrastructure automatically

Don't have a threat intelligence platform yet? CloudMISP is our fully managed platform purpose-built for consuming and sharing threat intelligence.

CloudMISP overview diagram showing CloudMISP at the centre connected to analysts, Okta, MISP community, SIEMs, threat intel feeds, and infrastructure

How we help you share threat intelligence

Effective sharing starts with separating what you triage from what you publish. We configure a pipeline where:

  • Your Triage instance ingests feeds and your analysts curate intelligence
  • Your Sharing instance publishes vetted indicators to partner organisations
  • You control exactly what leaves your environment

Partners connect the way that suits them:

  • Push-only delivery for organisations that just need your indicators
  • Push/pull for bidirectional sharing with peers
  • Direct login for close collaborators

This flexibility lets you share with ISACs, sector peers, and government partners on their terms. CloudMISP includes built-in sharing workflows, granular access controls, and multi-community support out of the box. Learn more about CloudMISP.

Pipeline diagram showing threat intel feeds ingested into Triage CloudMISP, published to Sharing CloudMISP, and distributed to partner organisations

CloudMISP: more than MISP in the cloud

CloudMISP is rearchitected and containerised with watchdog services and monitoring, deployed in a dedicated VPC. It's not just MISP on an EC2 box. Deployed in any AWS region globally for data sovereignty. Available on AWS EU Sovereign Cloud.

Core

For teams already experienced with MISP
  • 1 production MISP instance
  • Managed hosting in your preferred AWS region
  • Dedicated VPC deployment
  • Automatic updates and security patches
  • Monitoring and alerting
  • Production support
  • Unlimited users*
  • 100GB storage*

Insight

Core + Consulting + Training + Built-in threat feed
  • Feedly for Threat Intelligence license
  • 10 days of Cosive Professional Services each year
  • 1 production MISP instance
  • Managed hosting in your preferred AWS region
  • Dedicated VPC deployment
  • Automatic updates and security patches
  • Monitoring and alerting
  • Production support
  • Unlimited users*
  • 100GB storage*
  • MISP Kickstarter training for up to 5 users in the first year
  • Advanced integrations with your security stack
  • Priority support and dedicated account management
  • Custom feed configuration and optimisation

* Fair use policy applies.

Optional add-ons
Sharing
An additional MISP instance for use as a dedicated sharing hub.
STIX TAXII API
Consume and share STIX/TAXII threat intelligence with your existing security tools.
Learn more about CloudMISP

Questions we hear from threat intelligence leaders

What threat intelligence platforms do you support?

CloudMISP is our managed MISP SaaS — rearchitected, containerised, and deployed in a dedicated VPC in your preferred AWS region. We also support Filligran OpenCTI and EclecticIQ Intelligence Center.

We integrate with existing MISP deployments and other vendor TIPs via STIX/TAXII and REST APIs. If your organisation already runs a platform, we work with it rather than replacing it.

Can you help us comply with NIS2?

Yes. NIS2 requires essential and important entities to share cyber threat intelligence. We deploy managed sharing platforms and connect you to relevant sectoral ISACs and national CERTs, covering Article 29 information sharing requirements.

Our platforms include the access controls, audit logging, and data governance needed to demonstrate compliance.

Can you help us comply with DORA?

Yes. DORA Articles 45 and 49 encourage voluntary threat intelligence sharing between financial entities, provided appropriate confidentiality protections are in place. We deploy platforms with access controls, audit logging, and data governance, then connect you to the relevant sharing communities.

The same platform handles both threat intelligence and fraud data sharing, so you can address both obligations with a single infrastructure.

Can you help us comply with the SOCI Act?

Yes. Australia’s Security of Critical Infrastructure Act requires reporting of cyber incidents to ASD. We help you connect to ASD ACSC’s threat sharing feeds and establish reporting workflows via MISP, so your organisation can meet its obligations efficiently.

Can you help us comply with the UK CSR?

Yes. The UK Cyber Security and Resilience Bill strengthens obligations for critical infrastructure operators. We help you connect to UK NCSC feeds and establish sharing arrangements with sector-specific communities, ensuring your organisation meets the new requirements.

Can you help us connect to the NZ NCSC feeds?

Yes. We help organisations connect to the NZ National Cyber Security Centre’s threat intelligence feeds via MISP, configure automated ingestion, and develop workflows to action the intelligence within your existing security tools.

Can you help us connect to the UK NCSC feeds?

Yes. We configure connections to the UK NCSC’s threat data feeds, including their MISP-based sharing platform. We handle authentication, feed configuration, and integration with your existing security tools.

Can you help me start a cyber threat intelligence sharing community?

Yes. We’ve designed and operated threat intelligence sharing communities for national CERTs and government agencies. We help with governance frameworks, platform deployment, onboarding processes, and ongoing community management.

Learn more about starting a sharing community.

Can you also help me share cyber threat intelligence?

Absolutely. Sharing is as important as consuming. We help you establish sharing workflows, configure TLP and sharing group controls, develop automation for publishing indicators, and connect to your relevant sharing communities — whether they’re sector ISACs, national CERTs, or peer organisations.

Brown and black sand during daytime
Cosive

How can we help?

Tell us about your threat intelligence requirements and we'll get back to you as soon as possible.