Cyber Threat Intelligence Maturity
Your cyber threat intelligence capability, measured theme by theme and turned into a roadmap.
10 themes, a 5-level scale. And the action that moves each level to the next.
The framework’s 10 themes, already written from L1 to L5. One company, one business unit, or 300 at once.
Cyber Threat Intelligence Maturity
10 themes, 5-level scale.
Nordhavn Industries
53 / 100
They measure their maturity with Datamensio
An example
This could be your situation.
Take one company as an example: three sites, three spreadsheets, no shared answer.
Nobody can consolidate.
Nordhavn Industries, 2,400 people in Hamburg, Lyon and Porto. A client asks where the group stands. Each site answers in its own spreadsheet, with its own scales.
Three weeks, a single base.
One Cyber Threat Intelligence maturity framework (references CTI-CMM, MITRE ATT&CK, intelligence cycle) assessment launched across all three sites at once, from the managers’ interview notes. The framework was already written, its 10 themes and levels L1 to L5 too.
Two costs avoided before being committed.
A score of 53 out of 100, with the gap concentrated on three themes. The AI companion spotted that two actions duplicated those of another audit. The committee report took one sentence to request.
What it saved them
- 3sites measured on the same base, instead of three questionnaires to reconcile
- 2duplicate actions caught before the spend
- 1committee report, with no manual rework
These figures are an example. They could be yours.
The standard imposes processes. Datamensio says where you stand.
01
The framework is already written
Themes, questions and levels L1 to L5, all written. You do not start from an empty spreadsheet.
02
The score lands the same day
Online, by self-assessment link or in interview. Theme by theme, comparable over time.
03
The gap becomes a costed plan
Every step up carries its action. The AI prioritises on expected effect, not on the order of the standard.
04
Progress can be demonstrated
Campaign after campaign, against your target and against your own past. That is what your board asks for.
The maturity scale
One level, the next, and the action that links the two.
It is this mechanism (a level, a level above, and the action that connects the two) that turns a finding into a trajectory.
Are priority intelligence requirements formalised with stakeholders and reviewed regularly?
- N1
No formalised requirements. Monitoring follows the news and the analysts’ own interests.
- N2
A list of topics exists, drawn up by the security team alone. It is not shared with the business and has not been reviewed since it was created.
- N3
Requirements are formalised with the main stakeholders, prioritised and reviewed on a fixed schedule. Each output is tied to an identified requirement.
- N4
Requirements cover the strategic, operational and technical levels, are validated by recipients and steered through coverage and timeliness indicators.
- N5
Requirements evolve continuously with incidents, risk scenarios and changes in activity, with a documented history of revisions and their effects on outputs.
Action to move from L2 to L3
Run a workshop with the SOC, vulnerability management, risk and a business representative to prioritise intelligence requirements, record them in a single document and put their review on the agenda of the quarterly security committee.
« With Datamensio, we meet our objectives far more efficiently. The ERDF inspection services and our supervising ministry particularly appreciated an approach that gives them reliable data. »

Director, CCI 94CCI Île-de-France
« We believe this is the most suitable solution to scale our transformation project and measure impact according to our needs. »

Maja SucekChief Operating Officer, Interreg Danube
Rarely on its own
Frameworks combine. Put several together to cover your business, or have the AI write yours.
Take your first measurement
What this framework covers
Cyber threat intelligence, or CTI, is a capability, not a compliance requirement. It rests on a well known cycle: stakeholders express their intelligence requirements, then comes collection, processing, analysis, dissemination and feedback. It works across three horizons: strategic for leadership, operational for campaigns and actors, technical for indicators and tactics. The frameworks that structure the discipline, from the intelligence cycle to the MITRE ATT&CK mapping, shape practice without setting a level to reach. It is up to the organisation to define its own target.
In practice, this freedom makes the capability hard to steer. The questions teams face are concrete. Who set the priority intelligence requirements, and when were they last reviewed? Are the outputs read and used by the SOC, vulnerability management and leadership, or do they simply circulate among analysts? Are purchased or open indicator feeds assessed for their real contribution, or accumulated simply because they are available? Without a measurable answer, CTI investment is hard to justify at budget arbitration.
The European context has moved the subject forward. NIS 2 and DORA require documented knowledge of relevant threats and, for the financial sector, threat led testing under TIBER-EU. Intelligence has become an expected input to risk management and crisis preparedness. A common confusion persists: a subscription to an indicator feed is not an intelligence capability. The feed is a source. Intelligence is the contextualised analysis work that produces a decision.
The maturity assessment does not answer the question of compliance. It does not say whether the practice is compliant or not, since no body certifies a CTI capability. It places each theme on a progressive scale inspired by the CMMI method, from no practice in place to optimised practice, and points to the action that moves you to the next level. You get a current state, a target, and the costed gap between the two, usable at both security committee and investment committee level.
The framework is ready to use in Datamensio and remains yours. AI adjusts the themes, questions and level wording to your organisation, or builds a variant from your own documents: CTI charter, SOC procedures, threat monitoring reports. The underlying models can be selected, including from European providers.
Reference standard: Cyber Threat Intelligence maturity framework (references CTI-CMM, MITRE ATT&CK, intelligence cycle)
The themes assessed
Capability governance
Team mandate and reporting line, roles and responsibilities, dedicated budget, links with the SOC, risk and leadership, sharing policy.
Priority intelligence requirements
Stakeholder identification, requirement definition, prioritisation, review frequency, traceability between stated requirement and delivered output.
Sources and collection
Mapping of open, commercial, community and internal sources, coverage of scope, reliability assessment, access management and legality of collection.
Processing and data management
Threat intelligence platform, format normalisation, deduplication, indicator lifecycle and expiry, automated enrichment.
Analysis and tactics mapping
Analysis methods, reasoned attribution, use of MITRE ATT&CK, tracking of relevant actors and campaigns, distinction between hypothesis and established fact, confidence scoring.
Dissemination and outputs
Strategic, operational and technical formats, publication cadence, tailoring to the recipient, urgent alerts, measurement of readership and use.
Operational integration
Feed into detection rules, alert triage and investigations, contribution to vulnerability management and threat hunting, use during exercises and crises.
External surface and brand monitoring
Internet exposure, data and credential leaks, domain and brand impersonation, monitoring of the supply chain.
Sharing and cooperation
Participation in sector communities and CERTs, exchanges with authorities, classification and dissemination rules, reciprocity of contributions.
Measurement and continuous improvement
Relevance and timeliness indicators, feedback from recipients, post incident reviews, method updates, comparison over time and across entities.
A short version of the framework is available for the online self-assessment.
Frequently asked questions
Can cyber threat intelligence be certified?
No. It is a capability, with no dedicated certification body. The assessment measures the maturity level of your practices and produces a progression trajectory. It can, however, feed into preparation for an ISO 27001 audit or the demonstration of NIS 2 and DORA requirements.
What is the difference between this assessment and an audit?
An audit checks that requirements are present and concludes with a gap or a compliance finding. The assessment places each theme on a progressive scale and points to the action that moves you to the next level. The result is a roadmap, not an opinion.
How long does the assessment take?
The short version takes 20 to 30 minutes for a manager familiar with the setup. The full version, run collaboratively, typically spans one to two weeks, most of the time going into gathering input from the SOC, CTI and the business.
Can the framework be adapted to our organisation?
Yes. Themes, questions and level wording can all be changed, and AI can build a variant from your existing procedures and outputs. An entity with no dedicated team and a group with a CTI unit are not assessing the same things.
Do we need a dedicated CTI team to take part?
No. The assessment also works when monitoring is done part time or outsourced to a provider. The questions then focus on how you set your requirements, use the deliverables and measure their contribution.
How do we compare several entities within the group?
The same framework is rolled out to each business unit, and results are then compared by theme, across entities and against previous assessments. AI groups the gaps into a cross entity roadmap that avoids duplicating the same actions across several plans.
Where is the data hosted?
In France, with OVH, backed up with Scaleway. No transfer outside the European Union. The AI models used can be selected, including from European providers.





