September 9, 2026

Threat-INFORM to Optimize Security Operations

In brief

Jon Baker argues that conventional security programs can no longer depend primarily on vulnerability prioritization and patching because attackers are exploiting weaknesses increasingly quickly, sometimes before or immediately after public disclosure. Security operations should instead focus on “adversary opportunity”: the practical routes attackers could use to reach critical assets after an initial compromise. The foundation for this approach is threat-informed defense, which identifies the tactics, techniques and procedures relevant to an organization, aligns controls with those behaviors and continuously tests whether defenses work. MITRE INFORM supports this process by assessing maturity across cyber threat intelligence, defensive measures, and testing and evaluation, using 22 components and five maturity levels to expose gaps and guide investment.

The article introduces “threat debt” as a contextual measure combining vulnerabilities, misconfigurations, weak controls, identity exposure, segmentation failures and detection blind spots into viable attack paths. Rather than treating thousands of findings separately, organizations should identify and break the relatively small number of paths that create the greatest risk to business-critical systems. Continuous Threat Exposure Management provides the operating discipline for reducing this debt through repeated scoping, discovery, prioritization, validation and remediation. Together, threat-informed defense, MITRE INFORM, threat debt and CTEM form a unified model: understand relevant adversaries, measure program maturity, quantify real attacker opportunity and systematically reduce it across security, IT and business teams.

Source: FIRST

Explore More Insightful Articles: