Skip to content

Threat intelligence

Turn a threat source into an assessable scenario.

KaitoSec brings recognised catalogues to the security and risk workflow, where entries connect to affected assets, existing controls and exercise context.

Where friction starts today

Threat catalogues that sit in a tab and never reach a risk

Everyone knows about MITRE ATT&CK, CWE, and the OWASP Top 10. The catalogues are open, thorough, and almost never touched after the kickoff workshop. They live in a browser tab while the risk register fills up with vague entries like 'malware' and 'human error', because copying a real attack pattern into a structured scenario by hand is tedious and nobody has the afternoon.

Threat data is only worth keeping current if it drives something. An ATT&CK technique should turn into a risk scenario with the assets it targets and the controls that blunt it. A Grundschutz Gefährdung should map to its safeguard without a manual lookup. When the catalogue feeds your risks, your continuity exercises, and your control selection directly, the intelligence does work instead of gathering dust.

One data model

What you enter here, the other modules already know

Modules are views on the same record, not separate databases. A change made here is the change every other module reads, with no export step and no second entry.

A change in this module is written to the shared data model, which the other modules read immediately.

This module

Threat Intelligence

Shared data model

One asset, one risk, one control, one piece of evidence

  • Risk ManagementCurrent at once
  • Business ContinuityCurrent at once
  • Asset ManagementCurrent at once

Entry to evidence

Every change carries its own proof

An auditor rarely asks what the register says today. They ask who changed it, when, and on what basis. That trail is written while the work happens, so nothing has to be reconstructed at the end of the year.

One change writes its previous value, its owner and its date, and surfaces in the management report, the audit evidence and the customer questionnaire.

One change

A risk is re-assessed

Written with it

  • Previous value and version
  • Person responsible
  • Date and reason

Where it surfaces

  • Management report
  • Audit evidence
  • Customer questionnaire

What changes for your team

01

Use recognised sources at the point of work

Search CAPEC attack patterns, CWE weaknesses, MITRE ATT&CK techniques, OWASP Top 10 and BSI threats together and retain a reference to the source.

02

Show relevance to assets, controls and continuity

Each threat entry connects to the assets it targets, the controls that mitigate it and the continuity scenarios it triggers. Threat intelligence becomes part of the same operating model used by your ISMS, BCMS and AIMS.

03

Assess instead of copying and pasting

Use a catalogue entry as the starting point for a structured risk scenario. The risk owner adds affected assets, likelihood, impact and suitable treatment in the organisation's own context.

The workflow

01

Unified threat catalogue browser

Search and filter across every built-in catalogue from one interface. Browse MITRE ATT&CK by tactic, find CWE weaknesses by software category, look up CAPEC patterns by asset type and push any entry into your risk register or BC exercise in one click.

02

Scenarios for ISMS and BCMS

Bring a threat entry into a risk or exercise scenario, then add the relevant assets and controls in your own context. Security and continuity work from the same referenced source.

03

BSI Grundschutz threat mapping

Review BSI Grundschutz threats together with their related modules and safeguards. Links to other standards remain visible and can be professionally confirmed for your own scope.

FAQ

How often are the threat catalogues updated?

KaitoSec adopts published versions of upstream sources as part of product updates and shows the source and version. An assessment therefore remains traceable to the catalogue state it used.

Can we add custom threat entries?

Yes. Workspace-specific threats can be created and linked to catalogue entries for reference. Custom threats appear alongside the built-in catalogues and can be used in risk scenarios, gap analyses and BC exercise design.

How does MITRE ATT&CK integration support compliance work?

ATT&CK techniques are mapped to ISO 27001 controls and NIS2 security measures. When an ATT&CK-based scenario is added, KaitoSec suggests the controls most likely to mitigate the technique and flags continuity dependencies that may need rehearsal.

Is OWASP Top 10 included for development teams?

Yes. OWASP Top 10 is included as a built-in catalogue and can be linked to software assets and development processes. It is particularly useful for SOC 2 and ISO 27001 work and for AI system due diligence under ISO 42001.