DARINORCold Lab

Assessments / Threat-Informed Defense Maturity Assessment

Threat-Informed Defense Maturity Assessment

12 questions across Cyber Threat Intelligence, Defensive Measures, and Test & Evaluation — weighted 35 / 40 / 25, the same shape MITRE's own INFORM framework uses. Answer one at a time — step back whenever you want to change an earlier answer. Nothing is uploaded.

Cyber Threat Intelligence · 35%1 / 12

You maintain a current, named list of ATT&CK techniques prioritized for your actual threat model — not a generic industry top-techniques list.

// About this tool

Threat-Informed Defense Maturity Assessment

Threat-Informed Defense (TID) is the practice of building detections and mitigations from real adversary tradecraft — MITRE ATT&CK techniques — instead of generic best practice or compliance checklists. MITRE's own Center for Threat-Informed Defense (CTID) formalizes this into three dimensions: Cyber Threat Intelligence, Defensive Measures, and Test & Evaluation, published as a full maturity model called INFORM (the successor to their earlier M3TID model).

This tool borrows INFORM's three-dimension structure and its weighting shape — Defensive Measures weighted highest (40%), then Cyber Threat Intelligence (35%), then Test & Evaluation (25%) — because that's the order CTID's own research says matters. Twelve questions, four per dimension, answered Yes / Partial / No, roll up into a weighted 0-100 score and a maturity tier.

This is an informal practitioner self-check inspired by publicly described CTID material — it is not MITRE's INFORM assessment, not affiliated with MITRE or CTID, and not a substitute for running the real assessment at ctid.mitre.org/inform. Everything runs in your browser; nothing is uploaded or stored.

// When to use it

  • Sanity-check a TID initiative before you pitch it

    Run the assessment before writing a threat-informed defense roadmap, so the pitch targets your program's actual weakest dimension instead of a guess.

  • Find out if you're chasing coverage instead of resilience

    A high Defensive Measures score built on brittle, easily-evaded detections still fails Test & Evaluation. The per-dimension breakdown shows exactly where that gap is.

  • Justify investment in purple-teaming or CTI headcount

    A low Test & Evaluation or Cyber Threat Intelligence score, next to a strong Defensive Measures score, is a concrete case for where the next hire or budget line should go.

// Questions

Is this MITRE's official INFORM assessment?

No. It's an informal self-check inspired by publicly described CTID material, built for a quick gut-check — not a substitute for MITRE's own INFORM assessment at ctid.mitre.org/inform, and not affiliated with MITRE or the Center for Threat-Informed Defense.

Why are the three dimensions weighted 35/40/25 instead of evenly?

That weighting mirrors the shape MITRE's own INFORM framework uses: Defensive Measures counts for the most because taking defensive action is the point, Cyber Threat Intelligence next because it drives what gets defended, and Test & Evaluation last — not because it matters least, but because it validates the other two rather than standing alone.

Why only 12 questions when INFORM has 22 components?

This is a condensed practitioner gut-check, not a replacement for INFORM's full assessment. Four questions per dimension is enough to tell you which of the three is weakest — if the result says you're weak in, say, Test & Evaluation, that's your cue to go run the real INFORM assessment for the detailed breakdown, not to treat this score as the final word.

What if I don't have a dedicated purple team?

Score Test & Evaluation honestly rather than generously. Occasional manual testing against a known technique — even without a formal purple-team function — is a fair 'Partial.' The point of a low score there isn't to shame you, it's to show that Test & Evaluation is where your program's investment should go next.

This site uses minimal cookies and local storage to keep features like the chat widget and games working. We do not use third-party tracking cookies. Privacy Policy