When Threat Intelligence Outgrows the Spreadsheet: Moving to MISP
For a lot of teams, tracking indicators and notes in a spreadsheet, then feeding them manually into detection and prevention systems, works well for months or even years. As your program grows, you'll eventually want to do things that get harder in a flat table. None of that is impossible in a spreadsheet. It just gets slower and more fragile as volume and complexity grow. For most teams reaching that point, we recommend MISP as the next step. It gives you more structure, correlation, automation and sharing capability without requiring you to build an overly complex CTI environment from day one.
Stay in the loop
Get occasional updates from Cosive about cyber threat intelligence, fraud data sharing, and security operations.
How the ASD June 2026 ISM Uplifts CTI Programs
While the Australian cyber security sector has recently been captivated by broader structural framework conversations around evolving the Essential Eight, a major operational shift slipped into the June 2026 Information Security Manual (ISM) update. The Australian Signals Directorate (ASD) introduced a critical new monitoring requirement: Control ISM-2116. "Cyber threat intelligence services are used to support the detection of cyber security events and the identification of cyber security incidents." If you need to comply with the ISM and you're not actively using cyber threat intelligence as part of your detective controls, the system could now be considered non-compliant.
MISP Beta UI/UX Mode (v2.5.32): A Walkthrough from Contributor Chris Horsley
We’ve been doing some work at Cosive to modernise the MISP user interface and bring more responsive web design into the experience. The result is a new beta UI that you can enable today if you’re running a recent version of MISP (v2.5.32 or later).This update is driven by a simple goal: make MISP easier to use, especially for analysts working on smaller screens or remotely.
MISP 2025 Retrospective: Monthly Highlights & Workflow Improvements
The incredibly active MISP developer community put out a dozen-plus releases in 2025 – and the results speak for themselves in new features and quality-of-life improvements for threat intel teams. In this article we recap some of the highlights from 2025, and extend a big thank you to the MISP core team and community for their hard work keeping this critical open-source tool moving forward.
Meet Joe Cozzupoli, Field CISO and Principal Security Advisor at Cosive
Joe Cozzupoli is a cybersecurity leader with a passion for people, problem-solving, and community. As Field CISO at Cosive, Joe bridges the gap between technology and business, helping organisations navigate complex security challenges while building lasting relationships based on trust.
What I Learned About Logging and Detection Strategies From Moving House
Moving house isn’t usually the metaphor you’d reach for when talking about security logging and detection — but in my recent move, I couldn’t help but draw the parallels. Packaging, tracking, and discovering the really important items in your environment, all mirrored the challenges we wrestle with through logging strategies and detection engineering.
Why CISOs Should Care About Cyber Threat Intelligence with Joe Cozzupoli
Everyone wants the CISO to care about their corner of the security landscape, so why is Threat Intelligence any different? Cosive Field CISO Joe Cozzupoli argues that CTI can help CISOs prioritise investments of time and budget, and avoid rabbit-holes that waste time defending against irrelevant threats.
Becoming a FIRST.org Member with Terry MacDonald
Security teams often aspire to become FIRST members, but it can be a long and winding road to get there. In this interview, Terry MacDonald breaks down each stage of the journey and charts a path forward. He says that contrary to what many people think, you don't need to be a rockstar organisation to join FIRST.
Australia’s New Gateway Security Guidance: What Leaders & SOC Teams Should Know
On 24 July 2025, the Australian Department of Home Affairs released a major update to its Protective Security Policy Framework (PSPF) as part of the Commonwealth Uplift Reforms, overhauling how government agencies secure their internet gateways. As someone immersed in the challenges of government gateway security at Verizon for over 14 years, I believe the recent advice marks a dramatic shift in approach.
Creating CTI Like a Journalist
I'm going to argue that as CTI analysts, we often get lost in the middle of these technical woods and forget about the ultimate purpose of threat intel: our outputs. These are commonly called threat intelligence products; the reports, alerts, or briefings we send to help others make decisions and take action. So how do we stay focused on the real purpose of CTI: producing useful, actionable outputs? Consider the lessons from an occupation we’ve had lifelong exposure to: journalism.
CTI-CMM: Improving Cyber Threat Intel Maturity with Colin Connor, Terry MacDonald & Prescott Pym
In this episode of the Cosive podcast, Terry MacDonald and Prescott Pym are joined by CTI-CMM framework co-lead Colin Connor to dive into what the CTI-CMM framework is, why it exists, and how to use it.





