Cosive
Why work with us

Security operations expertise you can trust

Deep SecOps experience across international CERTs and managed security providers — our team has worked in and with security operations centres around the world
SIM3 assessors with experience assessing security teams globally — we use the Security Incident Management Maturity Model to provide objective, structured assessments
ATT&CK and VERIS framework specialists — we help teams classify threats, map detections, and build structured security incident vocabularies
A team of senior security practitioners — you work directly with experienced consultants who’ve spent their careers building and running security operations
Team presenting at a security conference
Cosive are frequent presenters at FIRST, AUSCERT and NZITF.
Person pointing at a map while planning a route

Benchmark your security operations and build on what works

We help you assess your current security operations maturity and build a practical improvement plan tailored to your organisation. We use frameworks like SIM3 to give you an objective, repeatable baseline so you can measure where you are and track real progress over time. Hiring senior cybersecurity staff is expensive and slow — our consultants have up to 25 years of experience and can embed in your team to deliver difficult projects and develop your people’s capabilities.

Discuss improving your team
01

SIM3 gap assessment

A structured gap assessment using the SIM3 framework, based on our extensive experience assessing security teams globally. We typically use SIM3 because it gives you a repeatable way to measure maturity across organisation, human, tools, and processes.

02

Improvement roadmap

We develop a multi-year improvement roadmap to fix your security team — a practical path to an efficient, effective capability that accounts for your budget, team size, and organisational context.

03

Staff augmentation

Experienced staff with 10–26 years of cybersecurity experience, embedded in your team to help you do the projects you just don’t have time to do — and level up your people’s skills along the way.

04

Industry benchmarking

Benchmark yourself against others in your industry so you understand where to improve. We help you compare your security operations to peers in your sector and set realistic, organisation-specific targets.

Build incident response processes that work under pressure

We have extensive experience helping organisations create and improve their incident response processes. Whether you’re building from scratch or refining what you have, we focus on making IR processes that work reliably when it matters most.

We act as a resource multiplier for your team — helping you do more with less by tuning alerts, automating repetitive tasks, and aligning your detection rules with your actual threat landscape.

01

IR process design

Create and improve incident response processes so they work reliably and effectively. We design processes that match your team’s size and operating environment.

02

Triage & investigation

Work out the best way to triage and investigate new potential security incidents. We help you build consistent, repeatable approaches to handling alerts.

03

Alert tuning & automation

Reduce alert fatigue so that your staff get an opportunity to work on other things. We tune detection rules and automate repetitive tasks — a resource multiplier for lean teams.

04

Table-top exercises (TTX)

Scenario-based exercises to make sure that people know what to do when an incident occurs. We design and facilitate exercises tailored to your threat landscape.

Close-up of red and green indicator lights
Discuss IR improvement
Chris Horsley speaking at FIRST Conference
Cosive co-founder Chris Horsley presenting at the annual FIRST Conference in Copenhagen.

Join FIRST, the world’s largest incident response community

FIRST (Forum of Incident Response and Security Teams) connects your team to a global network of security professionals. We can guide you through the application process and help you get the most out of your membership.

  • Learn from the world’s best incident response teams
  • Access helpful content about how to set up a SecOps team
  • Access Cyber Threat Intelligence to protect your organisation
  • Cheap tickets to the FIRST Annual Conference, one of the best defender-oriented conferences in the world
Talk to us about joining FIRST

Map threats with ATT&CK and VERIS to see how they reach you

ATT&CK mapping gives your team a structured way to describe adversary behaviour, classify incidents, and pinpoint where your defences are strongest and weakest. We help you operationalise ATT&CK and VERIS so they become practical tools your analysts actually use, not shelf documents.

Once threats are mapped to techniques and tactics, you can overlay your logging and detection coverage to find the gaps — and focus effort where it matters most.

Classify security incidents using ATT&CK or VERIS frameworks — give your team a structured vocabulary for categorising threats and mapping them to known adversary behaviours
Define logging standards — make sure your analysts have the information they need when investigating incidents, without drowning in noise
Develop attack flow diagrams — understand the choke points that let you catch your most likely threats, and where the best detection opportunities exist
Discuss framework adoption
MITRE ATT&CK Navigator showing Enterprise matrix with highlighted threat technique mappings across tactics

Common questions about improving your security operations

What is SecOps?

Security Operations (SecOps) is the practice of combining security and IT operations to protect an organisation’s systems, data, and people. It covers everything from monitoring and detection to incident response and recovery. A strong SecOps function helps you identify threats early, respond effectively, and continuously improve your defences.

What does a SecOps team do?

A SecOps team monitors, detects, investigates, and responds to cybersecurity threats across your organisation. Day-to-day activities typically include triaging security alerts, investigating potential incidents, maintaining detection rules, coordinating incident response, and working to continuously improve the organisation’s security posture.

The scope varies by organisation — some SecOps teams also manage vulnerability assessments, threat intelligence, and security tool administration.

What is the ATT&CK Framework?

MITRE ATT&CK is a knowledge base of adversary tactics, techniques, and procedures (TTPs) observed in real-world attacks. It provides a common language for describing what threat actors do and how they do it. Security teams use ATT&CK to map their detections, assess coverage gaps, track adversary behaviour during incidents, and communicate threats consistently across the organisation.

We help teams adopt ATT&CK practically — mapping your existing detections, identifying gaps, and integrating ATT&CK into your incident response and SecOps workflows.

What is the VERIS Framework?

VERIS (Vocabulary for Event Recording and Incident Sharing) is a framework for describing security incidents in a structured and repeatable manner. It was developed by the team behind the Verizon Data Breach Investigations Report (DBIR) and provides a common taxonomy for recording who did what to which assets, and what the impact was.

VERIS helps organisations build a consistent incident database that supports trend analysis, benchmarking, and evidence-based decision-making about security investments.

What is the SIM3 capability maturity model?

SIM3 (Security Incident Management Maturity Model) is a framework for assessing the maturity of security incident management teams across four dimensions: organisation, human, tools, and processes. It was developed by the Open CSIRT Foundation and is widely used to evaluate and certify CSIRTs and SOCs internationally.

SIM3 provides a structured way to identify strengths and weaknesses, benchmark against peers, and build a prioritised improvement plan. We use SIM3 in our gap assessments because it gives teams a clear, objective baseline to work from.

What is the SOC-CMM capability maturity model?

SOC-CMM (Security Operations Centre Capability Maturity Model) is a framework specifically designed for assessing and improving your SOC’s maturity. It evaluates capabilities across domains including business alignment, people, process, technology, and services.

SOC-CMM is a good fit for teams that are primarily SOC-focused rather than broader CSIRT or incident response teams. We help organisations choose between SIM3 and SOC-CMM based on their team structure and goals.

What is a TTX?

A TTX (Table-Top Exercise) is a discussion-based exercise where team members walk through their roles and responses during a simulated security incident. Unlike a full drill, a TTX doesn’t involve live systems — it’s a structured conversation that helps teams identify gaps in their processes, communication, and decision-making before a real incident forces them to find out the hard way.

We design and facilitate TTXs tailored to your organisation’s threat landscape, ensuring the scenarios are relevant and the outcomes are actionable.

Security analyst working at a computer

Start improving your security operations

Tell us about your SecOps goals and we’ll get back to you with practical next steps.