Start a threat intel sharing community

Sharing threat intelligence is how organisations move from standing alone to collective defence. We help you design the governance, deploy the platform, onboard the members, and run the operations that turn a good idea into a thriving community.

Threat intelligence sharing sounds simple. The reality is anything but.

Everyone agrees that sharing threat intelligence is a good idea. Fewer organisations manage to actually do it. The challenge is not technology; it is trust, governance, legal risk, and the hard work of getting busy people to contribute consistently. A platform alone does not create a community. People do.

We have done this before. Let us help you do it right.

Get help from Cosive

We work side-by-side with you to design a well-run threat intelligence community

When your community is working well, it does not just produce more indicators. It gives every member organisation a clearer picture of who is targeting them, how attacks unfold, and what to prioritise. We know what that looks like in practice.

Meet every member where they are on the maturity journey

1
Reading and learning

Newer members consume intelligence through reports, email advisories, and curated briefings. They are building awareness and internal processes before they automate.

2
Structured consumption

Members at this level pull structured indicators from a portal or feed — IOC lists, CSV exports, or SFTP downloads — and use them in their own detection and response workflows.

3
Automated integration

More mature members connect directly to the community MISP instance via API or STIX/TAXII, ingesting intelligence into their own TIP, SIEM, or SOAR for automated detection and enrichment.

4
Producing and sharing back

The most mature members contribute their own intelligence to the community. They run bidirectional syncs, share sightings, and help curate and contextualise intelligence for others.

Where are you on this journey? We use the CTI-CMM Framework to measure maturity and identify your next steps. Learn more here.

Every community we build is designed to support members across the full maturity spectrum.

Start a successful community
CTIS Case study

Building a national-scale sharing community

Cosive co-designed and developed Australia’s national Cyber Threat Intelligence Sharing (CTIS) platform: a bi-directional sharing hub bringing together government agencies, critical infrastructure organisations and the private sector for real-time threat sharing.

CTIS leverages MISP and the STIX/TAXII standards so members can connect with the tools they already run, whether that's a threat intelligence platform, a SIEM, or a SOAR. No one has to adopt a brand new stack to take part, which is what makes joining realistic for a busy team.

Building the platform was never the hardest part. What made CTIS work was a focus on the human factors most communities underestimate: agreeing what gets shared and with whom, getting legal and compliance teams comfortable, and setting clear TLP and confidentiality rules. This framework created the necessary conditions for trust between organisations that wouldn't otherwise work together.

Learn more about CTIS
Who we work with

We work with every type of organisation that shares threat intelligence

National Cyber Security Centres
National cyber security agencies building or scaling programmes that distribute threat intelligence to government networks, critical infrastructure operators, and the private sector.
Sector ISACs & Trust Groups
Industry-led sharing communities that are formalising how their members exchange threat intelligence — moving beyond email alerts and ad hoc calls to structured, automated sharing with accountability.
Enterprise CTI Teams
Organisations with established threat intelligence capabilities that want to share what they learn with trusted peers and contribute to collective defence beyond their own perimeter.
Critical Infrastructure Sharing
Energy, transport, water, and telecommunications operators coordinating threat intelligence across their sector to defend against adversaries who target shared supply chains and interdependencies.
Regional Sharing Communities
Cross-sector and cross-border communities that bring together organisations within a geographic region to share intelligence on threat actors, campaigns, and tactics relevant to their part of the world.
what you get

How we help you build and run your community

platform

CloudMISP as your sharing platform

A fully managed MISP instance deployed in your preferred AWS region, with enterprise-grade reliability and support.

  • Sharing groups, access controls, and member isolation configured to your community’s trust model
  • Custom taxonomies, galaxies, and warning lists aligned to your sector’s threat profile
  • Automated backups, patching, monitoring, and ongoing platform management by our team
governance

Community design and analyst onboarding

Consulting to help you design the rules, processes, and culture that turn a platform into a functioning community.

  • Develop governance charters, data-handling policies, TLP rules, and membership agreements
  • Design triage and curation workflows so members receive intelligence they can trust and act on
  • Run analyst workshops that teach members what to share, how to structure it, and how to get value from community intelligence
Integrations

Integrations and sustained operations

Custom integrations that connect member security tools to the community, plus ongoing support to keep everything running.

  • Build and maintain MISP, STIX/TAXII, and REST API integrations across diverse member environments
  • Connect the community platform to members’ TIPs, SIEMs, and SOAR tools for automated ingestion
  • The same platform supports fraud data sharing alongside cyber threat intelligence
why work with us

Trusted by the organisations building national cyber defence programmes

Our consulting team includes the Co-Chair of FIRST’s IEP-SIG, bringing direct experience shaping the frameworks and best practices behind trusted threat intelligence sharing.
Co-designers of Australia’s national threat sharing programme, CTIS
Creators of CloudMISP, the leading managed threat intelligence platform
We understand the legal frameworks, funding models, analyst workflows, and social dynamics that determine whether a sharing community thrives or stalls
Cosive co-founder Terry MacDonald presenting at NZITF.
case studies

Sharing communities we have designed and operated

Real results from real engagements across threat intelligence sharing, national programmes, and community operations.

Government

National cyber threat sharing programme

Designed the governance framework, deployed the platform, and operated a national-scale sharing programme connecting government agencies with critical infrastructure operators across energy, transport, finance, and telecommunications.

Transport

UK rail sector threat sharing

Worked with a major UK rail operator to establish structured threat intelligence sharing with industry peers, creating new integrations that connected their internal security tools to a sector-wide community platform.

Financial Services

APAC banking consortium

Helped a consortium of banks across the Asia-Pacific region build a cross-border threat intelligence sharing community — from governance design and legal frameworks through to CloudMISP deployment and analyst onboarding for member organisations.

Frequently asked questions

Questions about building a threat intelligence sharing community

get in touch

Tell us about your goals for starting a new CTI sharing community and we'll get back to you as soon as possible.