Threat-INFORM to Optimize Security Operations

By Jon Baker (AttackIQ). Co-founder of MITRE’s Center for Threat-Informed Defense. July 20, 2026

The operating model most security programs were built for no longer exists. The evolution of threat actors and frontier AI has collapsed the time between vulnerability discovery and exploitation. Defenders can no longer rely on that window to identify, prioritize, and patch vulnerabilities. A different approach is required. Defenders must look holistically at adversary opportunity within their organization and systematically manage it.

That approach requires a foundation grounded in deep technical understanding of what adversaries actually do — the specific TTPs they use and how they operate within our environments to reach their goals. It requires a way to systematically manage adversary opportunity based on that knowledge. And it requires the organizational discipline to break down the silos that keep security, IT, and the business from managing adversary opportunity together.

I made the case for a new model focused on managing adversary opportunity at the annual FIRST Conference in Denver. This blog distills that argument for practitioners who couldn't attend, and a reference for those who did.

The Window to React Has Closed

Adversaries are faster and more sophisticated than most SOC's were built to manage.

CrowdStrike’s 2026 Global Threat Report puts the average eCrime breakout time at 29 minutes, the fastest observed at 27 seconds, and the year-over-year trend at 65 percent faster. The Cloud Security Alliance’s April 2026 paper The Collapsing Exploit Window reports that mean time from disclosure to exploitation fell from roughly 32 days in 2022 to about 5 days, with nearly one in three exploits now appearing on or before the disclosure date. Patch cycles built for a slower threat environment cannot keep up, no matter how well-staffed the team.

The operational question for a SOC has shifted. It is no longer how fast we can patch, or how many critical CVEs we have. It is what the adversary does after a vulnerability is exploited, and whether our defenses limit their opportunity across the full attack chain. That is a different question. It requires a different operating model.

Threat-Informed Defense Is the Foundation

MITRE’s Center for Threat-Informed Defense defines threat-informed defense as the systematic application of a deep understanding of adversary tradecraft and technology to improve defenses. In practice, that decomposes into three things a security program does:

Threat-informed defense is a discipline that continually evolves in response to changing adversary behaviors, the threat landscape, and the evolution of our IT and business infrastructure.

MITRE INFORM Makes Threat-Informed Defense Measurable

MITRE INFORM is a maturity model designed to help organizations systematically advance their threat-informed defense practices. It is structured across three dimensions: cyber threat intelligence, defensive measures, and test and evaluation. Across those dimensions sit 22 components covering depth and timeliness of CTI, attack surface scoping, detection rule metadata, propagation between CTI and detections, threat hunting, deception, and more — each scored across five maturity levels from Initial to Optimized.

MITRE INFORM: Dimensions & components

What INFORM measures is the depth, timeliness, and relevance of an organization’s threat intelligence, and how well it is integrated across people, processes, and technology. It is not compliance scoring. It is a structured way to ask whether a program is grounding decisions and processes in knowledge of the real-world adversary behaviors relevant to them.

The operational output is two things. The first is a maturity score per component and per dimension. The second is the Impact/Complexity Matrix, which sorts a program’s gaps by how much they would improve threat-informed defense maturity and how complex they are to close. That matrix is the basis for building a threat-informed defense maturity roadmap. Re-assessing on a cadence makes maturity a measurable trend rather than a one-time score.

Threat-Informed Defense Enables Understanding Adversary Opportunity

Threat-informed maturity != Opportunity reduction

INFORM will guide your organization to a security program that’s aligned with the adversary behaviors most relevant to you. It does not answer the question a CISO actually hears in the board room: are our critical assets protected, and are we getting better at defending the organization? The reason is simple. INFORM measures whether the program has the practices in place to be threat-informed. It does not measure what adversary opportunity exists in the environment today, or whether that opportunity is shrinking. Security programs built on a mature threat-informed defense integrate that knowledge into how they understand and manage adversary opportunity.

Threat Debt Provides a New Lens on Cyber Defense

Threat debt

Threat debt is the true adversary opportunity in an environment. It is the errors and gaps in that environment, including vulnerabilities, misconfigurations, control weaknesses, identity exposure, segmentation gaps, and detection blind spots, combined into the viable attack paths an adversary could use to reach business-critical assets. It is contextualized by the adversaries that actually target the organization, the assets that cannot be lost, and the defenses that have been proven through validation. It is not a count of findings. It is the adversary opportunity those findings create in context.

The framing is borrowed from technical debt deliberately. Threat debt names a condition that accrues continuously, compounds when ignored, and can only be reduced through specific engineering work. The management discipline is similar to technical debt: measure it, prioritize it, pay it down where the interest is highest. Unlike technical debt, threat debt is rarely chosen. It accumulates from drift, configuration changes, identity sprawl, and adversary evolution.

Threat debt is paid down by breaking the attack paths that matter most, not by patching faster. A typical environment might contain thousands of findings. Viewed through the lens of viable attack paths to critical assets, those findings collapse into perhaps fifty paths. Breaking one critical path dispatches the underlying findings that path depends on and eliminates downstream paths it enables. That is how a program with finite resources reduces real adversary opportunity at scale.

Threat debt is a single measurement shared across Security, IT, and the business. It gives leaders across the organization a common scoreboard to prioritize against and turns adversary opportunity into a conversation they can have together. Each leader or team can directly see where the overall organization stands and how their teams are contributing.

CTEM Is the Operating Discipline

Continuous Threat Exposure Management

Continuous Threat Exposure Management, or CTEM, is the operating discipline you use to reduce threat debt. Gartner introduced the term in 2022 to describe a continuous process for scoping, discovering, prioritizing, validating, and mobilizing against exposure. CTEM aims to turn measurement into action that systematically reduces adversary opportunity.

Done well, CTEM is threat-informed, anchored in the adversary behaviors that actually matter rather than generic exposure lists. It is oriented around attack paths, treating exposure as routes to critical assets rather than counts of findings. And it is grounded in evidence, validating defensive effectiveness against real adversary techniques rather than assumed coverage.

One Operating Model, Not Five Frameworks

Foundation, measurement, action -- how the pieces fit together

Threat-informed defense, MITRE INFORM, threat debt, and CTEM are layers of a single operating model.

Together, these four layers give defenders a single model for understanding and managing adversary opportunity. It is what prepares them for the new reality, and what brings the whole organization to bear on the problem.

Where to Start

Take an INFORM assessment. The tool is open and freely available. It will give your program a baseline, a clear view of where your threat-informed defense foundation stands, and a roadmap to mature it. Re-measure on a cadence and build your maturity roadmap.

Learn more about threat debt. For a deeper discussion of threat debt as a concept and how organizations are starting to measure it, see my recent blog.

Start a CTEM program. I have extended INFORM to include a CTEM maturity assessment, built to help organizations get a CTEM program off the ground and aligned with the rest of their threat-informed defense work.

The work is not finished, and you have a voice in how it evolves. Your feedback will shape how INFORM matures, how the discipline around threat debt develops, and how the broader operating model takes hold across the industry. What does not need to wait is the move from measuring activity to measuring adversary opportunity. That shift is the one that matters.



Catch the talk at FIRSTCON26