Cyber Threat Intelligence

We help organisations consume, share, and act on cyber threat intelligence to stay ahead of adversaries.

Select your goal

APRA FCA

Banks & Financial Services

Banks, insurers, and financial institutions using CTI to detect fraud, track threat actors, and meet regulatory obligations from APRA, FCA, and ECB.

SOCI NIS2

Critical Infrastructure & OT

Energy, transport, water, and utilities operators building CTI capabilities to protect operational technology and essential services.

ISAC MSSP

Enterprise

Large organisations and managed security providers embedding threat intelligence into security operations to improve detection and response.

ASD CISA

Government

National cyber security agencies and defence organisations sharing threat intelligence across government networks and allied partners.

Why work with us

Cyber threat intelligence expertise you can trust

Extensive experience in CTI triaging and workflow development — helping teams build repeatable processes for handling, prioritising, and acting on intelligence
We help you set your intel gathering requirements — defining what intelligence you actually need, from which sources, and in what formats
Built and operated sharing communities for national CERTs and industry groups
Deep expertise in CTI standards and methodologies including MITRE ATT&CK and CTI-CMM
Chris Horsley presenting at AUSCERT
Cosive co-founder Chris Horsley presenting at AUSCERT.

Cyber threat intelligence services

CTI program strategy

Assess your current CTI maturity and design a roadmap to improve collection, analysis, and dissemination.

MISP deployment

Deploy and configure CloudMISP with feeds, taxonomies, and integrations tailored for your threat landscape.

Sharing community setup

Launch and operate a threat intelligence sharing community for your sector or region.

CTI team development

Train your analysts, build playbooks, and embed CTI into your security operations workflow.

ATT&CK mapping

Map your detections and threat reports to MITRE ATT&CK for consistent coverage analysis.

Tool integration

Connect MISP to your SIEM, SOAR, EDR, and other security tools for automated indicator enrichment.

Common questions about cyber threat intelligence

What is CTI?
Cyber Threat Intelligence is the collection, analysis, and dissemination of information about current and potential cyber threats. It helps organisations understand who is targeting them, how attacks are carried out, and what they can do to defend themselves. CTI turns raw threat data into actionable intelligence that security teams can use to prioritise defences and respond to incidents faster.
What is a TIP?
A Threat Intelligence Platform (TIP) is software that aggregates, correlates, and manages threat intelligence from multiple sources. It allows security teams to collect indicators of compromise (IOCs), enrich them with context, share them with trusted partners, and feed them into detection and response tools. MISP is the world's most widely used open-source TIP.
What is MISP?
MISP (Malware Information Sharing Platform) is the world's most widely used open-source platform for sharing, storing, and correlating threat intelligence. It enables organisations to share indicators of compromise, threat reports, and contextual information with trusted communities. Cosive is a core contributor to MISP and operates CloudMISP, a fully managed MISP hosting service.
Why should I share my cyber threat intelligence?
Sharing threat intelligence helps the broader security community detect and respond to threats faster. When organisations share indicators, TTPs, and threat reports, everyone benefits from earlier warning of attacks. Sharing also strengthens relationships with peers and regulators, and many frameworks now require or encourage intelligence sharing as part of operational resilience.
Can you help us find good threat intelligence?
Yes. We help organisations identify and evaluate commercial, open-source, and community threat intelligence feeds relevant to their threat landscape. We configure MISP to ingest, correlate, and deduplicate feeds so your analysts spend time on analysis, not data wrangling.
Can you benchmark us against others?
Yes. We conduct CTI maturity assessments using frameworks like CTI-CMM to benchmark your program against industry peers. This identifies gaps in your collection, analysis, dissemination, and feedback processes, and provides a prioritised roadmap for improvement.
Can you do CTI-CMM audits?
Yes. We are experienced in CTI-CMM (Cyber Threat Intelligence Capability Maturity Model) assessments. We evaluate your CTI program across all maturity dimensions, provide a detailed scorecard, and deliver actionable recommendations to advance your capabilities.
Low angle photography of metal structure

Start improving your threat intelligence

Tell us about your cyber threat intelligence goals and we'll get back to you.