When Threat Intelligence Outgrows the Spreadsheet: Moving to MISP
For a lot of teams, tracking indicators and notes in a spreadsheet, then feeding them manually into detection and prevention systems, works well for months or even years. As your program grows, you'll eventually want to do things that get harder in a flat table. None of that is impossible in a spreadsheet. It just gets slower and more fragile as volume and complexity grow. For most teams reaching that point, we recommend MISP as the next step. It gives you more structure, correlation, automation and sharing capability without requiring you to build an overly complex CTI environment from day one.
Stay in the loop
Get occasional updates from Cosive about cyber threat intelligence, fraud data sharing, and security operations.
Episode #009 - Threat Sharing Communities with Prescott Pym
Cosive Principal Consultant and CTI expert Prescott Pym discusses the how and why of threat sharing communities, including CTIS, the Australian Signals Directorate's national threat sharing program. You'll learn how to get involved in your first threat sharing community, and why you might consider joining a national threat sharing program like CTIS.
SOC Maturity Assessment in Australia: Our Approach
Day-to-day firefighting in SOCs (Security Operations Centres) can make it hard to see the bigger picture. A steady drum-beat of alerts and incidents can blur your focus. That’s why it’s so important to step back, breathe, and look at the current state of your SOC with a fresh set of eyes.Whether it's via an internal SOC maturity assessment with a popular model like SIM3, or an external consultant with deep SOC expertise, a new perspective can help uncover blind spots you might have missed in the rush to keep on top of the day-to-day demands of security operations.
Meet Prescott Pym, Principal Security Consultant at Cosive
In this interview, we sit down with Prescott Pym, a cybersecurity expert with over 25 years of experience in both government and enterprise sectors. Based in Canberra, Prescott has built a career around InfoSec, drawn to the dynamic challenges of the field since his early exposure to technology in the 80s. Now, as a consultant at Cosive, he helps organizations strengthen their security operations and CTI programs. Beyond his professional life, Prescott is deeply committed to his community and family, balancing a demanding career with personal growth. In this conversation, he reflects on his journey, shares insights into the cybersecurity industry, and offers advice for those looking to break into the field.
Using the CTI-CMM Model to Evaluate Threat Intel Program Maturity
It’s okay to admit that you don’t know exactly what CTI means. Of course, you know it stands for Cyber Threat Intelligence, and you might have a general sense it has something to do with staying on top of threats. How, though, do you actually build a successful CTI program in an organisation? What activities should it perform? What should it produce? For who?
Using MISP Bookmarks with Workflows for Team Coordination
Have you tried the Bookmarks feature in MISP yet? It’s much more powerful than you might think. Bookmarks are incredibly useful because within a team, we need to know what to take action on from all the new MISP events that come in over the last 24 hours. MISP bookmarks give us a way to save searches that help us isolate the signal from the noise. Paired with the Workflow features, they give us some powerful options to get our team on the same page.
Episode #008: Getting Started with Cyber Threat Intelligence (CTI) with Chris Horsley
Can one analyst with zero budget start a Cyber Threat Intelligence (CTI) program?Yes! In fact, you may already have started a small threat intelligence program without even realising it.In this interview with Cosive CTO and renowned CTI expert Chris Horsley we delve into the following questions on how analysts and teams can start a threat intelligence practice with limited resources.




