Cosive
What our customers say about us
“Cosive brought a high level of expertise and depth of knowledge to our engagement, and from the outset they were collaborative in developing the engagement methodology and deliverables.”
— Sasenka Abeysooriya, Program Director
Cosive
Why work with us

CTI expertise you can trust

Deep expertise in CTI tools and standards — we work across STIX/TAXII, MISP, and structured intelligence standards every day
Extensive experience in CTI triaging and workflow development — helping teams build repeatable processes for handling, prioritising, and acting on intelligence
We help you set your intel gathering requirements — defining what intelligence you actually need, from which sources, and in what formats
Threat modelling and analysis — identifying the adversaries, techniques, and attack paths most relevant to your organisation
Helped Australia build its national cyber threat intel sharing platform — we designed and operated the infrastructure behind national-scale intelligence sharing
Contributors to CTI-CMM — the capability maturity model that helps organisations assess and improve their CTI programmes
Experts in the ATT&CK Framework — mapping adversary behaviour, identifying detection gaps, and integrating ATT&CK into your workflows
Terry MacDonald presenting at NZITF
Cosive co-founder Terry MacDonald presenting at the NZITF Conference.

Building a CTI function from scratch

You know your organisation needs a threat intelligence capability, but you’re not sure where to start. We help CISOs and security leaders figure out what they actually need — then build it with them, step by step.

Plan your CTI programme — we run a gap analysis against your current security posture and build a practical roadmap that accounts for your budget, team size, and risk profile.
Decide what you need — requirements gathering based on your organisation’s risk profile, regulatory obligations, and the threats most relevant to your sector.
Find the right tools — threat intelligence platform selection, feed management strategy, and integration planning so your tooling supports your analysts rather than creating more work.
Design your team structure — reporting lines, analyst roles, skill requirements, and hiring priorities so you build the right team from the start.
Develop effective processes — collection, analysis, and dissemination workflows that turn raw threat data into intelligence your security team can act on.
Select the best threat intel feeds — commercial, open-source, and community feeds matched to your threat landscape. We help you avoid paying for feeds that don’t add value.

Ready to build your CTI function?

Tell us where you are today and what you're trying to achieve. We'll help you figure out a practical path forward.

Discuss your CTI goals

Take a good team and make them great

Your team is doing useful work, but you know there’s more they could be doing. Maybe your processes have grown organically and need structure. Maybe your tooling is holding you back. Maybe you need an outside perspective to identify the gaps.

We help CTI teams improve through structured assessment, practical recommendations, and hands-on support.

Talk to us about your team
Team collaborating on threat intelligence strategy
01

CTI-CMM benchmarking

Measure your maturity against industry peers and identify specific areas for improvement.

02

Gap analysis

Review your collection, analysis, dissemination, and feedback processes to find what’s working and what isn’t.

03

Process improvement

Develop or refine your intelligence requirements, reporting cadences, and stakeholder communication.

04

Tooling optimisation

Get more value from your existing platform, or evaluate whether a different approach would serve you better.

05

SOAR & AI orchestration

Adopt orchestration tools that reduce manual effort in processing and triaging threat intelligence — so your analysts spend their time on analysis, not data wrangling.

06

Platform evaluation

We help you evaluate, deploy, and optimise the platform that fits your organisation — whether that's a fully managed service, an open-source solution, or an enterprise commercial product.

Build new capabilities into your CTI programme

We help your team develop new disciplines and embed them into your existing workflow. These aren't one-off workshops — we work alongside your analysts to build skills that stick.

Discuss capability building
Pit crew changing tires on a yellow race car
01

ATT&CK Framework consulting

Build MITRE ATT&CK into your incident response tracking and CTI programme. We help you map your detections, assess coverage gaps, and use ATT&CK as a common language across your security team.

02

Priority Intelligence Requirements

Define what intelligence your organisation actually needs. We help you identify the right sources, evaluate commercial and open-source feeds, and build collection plans that align with your risk profile.

03

Threat modelling

Identify the threat actors most likely to target your organisation and research their tactics, techniques, and procedures. We help you build threat profiles that inform your detection and response priorities.

Choose the right threat intelligence platform

We deploy and support three threat intelligence platforms. Each suits different team sizes, maturity levels, and integration needs. We help you pick the right one and get it working.

Cosive CloudMISP

If your team is spending time on platform maintenance instead of analysis, a managed service frees them up. CloudMISP is our rearchitected, containerised MISP SaaS — deployed in a dedicated VPC in your preferred AWS region so your analysts can focus on intelligence, not infrastructure.

We handle hosting, monitoring, updates, and security patches. You get a production-ready MISP instance with built-in sharing workflows, multi-community support, and the confidence that your platform is being looked after by the team that built it.

Learn more about CloudMISP
MISP Beta UI showing the redesigned Event Index with tags, clusters, and streamlined navigation
OpenCTI platform dashboard showing threat intelligence data

Filigran OpenCTI

For teams that need flexible knowledge graph modelling and strong STIX support, OpenCTI gives you control and extensibility. Its STIX-native data model means your intelligence relationships are first-class objects — not afterthoughts bolted onto a flat database.

We help you plan, deploy, and tune OpenCTI so it fits your team’s workflows — whether you self-host or use Filigran’s SaaS offering. From connector configuration to dashboard design, we make sure you get value from the platform quickly.

  • STIX-native data model with full relationship mapping
  • Connector ecosystem for feed ingestion and enrichment
  • Flexible dashboards and reporting
  • Self-hosted or SaaS deployment options
Discuss OpenCTI deployment

EclecticIQ Intelligence Center

For enterprise security teams that need deep integration with their existing stack and analyst-centric workflows, EclecticIQ Intelligence Center provides a structured environment for creating, managing, and disseminating intelligence.

We help you get the most from EclecticIQ — configuring analyst workbenches, building bi-directional integrations with your SIEM and SOAR, and setting up outgoing feeds so your intelligence reaches the teams and tools that need it.

  • Analyst workbench with structured analysis tools
  • Bi-directional SIEM and SOAR integrations
  • Outgoing feed management for sharing with partners
  • Enterprise support and SLA guarantees
Discuss EclecticIQ
EclecticIQ Intelligence Center platform interface

Questions about improving your CTI team

Can you help us develop a CTI roadmap?

Yes. We assess where your CTI capability is now, identify the gaps that matter most, and build a prioritised roadmap that accounts for your budget, team size, and organisational context. We don’t prescribe a one-size-fits-all maturity model — we work with you to define what “good” looks like for your organisation and then map out how to get there incrementally.

What is the ATT&CK Framework?

MITRE ATT&CK is a knowledge base of adversary tactics, techniques, and procedures (TTPs) observed in real-world attacks. It provides a common language for describing what threat actors do and how they do it. Security teams use ATT&CK to map their detections, assess coverage gaps, track adversary behaviour during incidents, and communicate threats consistently across the organisation.

We help teams adopt ATT&CK practically — mapping your existing detections, identifying gaps, and integrating ATT&CK into your incident response and CTI workflows.

What is CTI-CMM?

CTI-CMM (Cyber Threat Intelligence Capability Maturity Model) is a framework for assessing and improving your CTI programme’s maturity. It evaluates capabilities across dimensions like collection, analysis, dissemination, and feedback — giving you a structured way to measure where you are, benchmark against peers, and prioritise improvements.

We use CTI-CMM in our gap analysis engagements to provide an objective baseline and actionable recommendations.

Can you help us understand what to do next?

Absolutely. If you’re not sure whether you need a platform, a consultant, training, or something else entirely — that’s a good place to start a conversation. We help organisations at every stage of CTI maturity figure out their next practical step, whether that’s formalising what they already do, choosing a platform, or building out a team.

Get in touch and tell us where you are. We’ll give you honest advice about what would actually help.

Can you help us connect to specific threat intel feeds?

Yes. We help organisations connect to government feeds (NCSC, ASD ACSC, CISA), commercial feeds, open-source intelligence sources, and sector-specific sharing communities. We configure automated ingestion, handle authentication and format translation, and develop workflows so your analysts can act on the intelligence within your existing security tools.

Person writing on glass whiteboard with diagrams

Start improving your threat intelligence

Tell us about your CTI goals and we’ll get back to you with practical next steps.