DARINORCold Lab

Assessments / Threat-Informed Defense Maturity Assessment

Threat-Informed Defense Maturity Assessment

12 questions across Cyber Threat Intelligence, Defensive Measures, and Test & Evaluation — weighted 35 / 40 / 25, the same shape MITRE's own INFORM framework uses. Answer one at a time — step back whenever you want to change an earlier answer. Nothing is uploaded.

Cyber Threat Intelligence · 35%1 / 12

You maintain a current, named list of ATT&CK techniques prioritized for your actual threat model — not a generic industry top-techniques list.

// About this tool

Threat-Informed Defense Maturity Assessment

Threat-Informed Defense (TID) is the practice of building detections and mitigations from real adversary tradecraft — MITRE ATT&CK techniques — instead of generic best practice or compliance checklists. MITRE's own Center for Threat-Informed Defense (CTID) formalizes this into three dimensions: Cyber Threat Intelligence, Defensive Measures, and Test & Evaluation, published as a full maturity model called INFORM (the successor to their earlier M3TID model).

This tool borrows INFORM's three-dimension structure and its weighting shape — Defensive Measures weighted highest (40%), then Cyber Threat Intelligence (35%), then Test & Evaluation (25%) — because that's the order CTID's own research says matters. Twelve questions, four per dimension, answered Yes / Partial / No, roll up into a weighted 0-100 score and a maturity tier.

This is an informal practitioner self-check inspired by publicly described CTID material — it is not MITRE's INFORM assessment, not affiliated with MITRE or CTID, and not a substitute for running the real assessment at ctid.mitre.org/inform. Everything runs in your browser; nothing is uploaded or stored.

// When to use it

  • Sanity-check a TID initiative before you pitch it

    Run the assessment before writing a threat-informed defense roadmap, so the pitch targets your program's actual weakest dimension instead of a guess.

  • Find out if you're chasing coverage instead of resilience

    A high Defensive Measures score built on brittle, easily-evaded detections still fails Test & Evaluation. The per-dimension breakdown shows exactly where that gap is.

  • Justify investment in purple-teaming or CTI headcount

    A low Test & Evaluation or Cyber Threat Intelligence score, next to a strong Defensive Measures score, is a concrete case for where the next hire or budget line should go.

// Questions

Is this MITRE's official INFORM assessment?

No. It's an informal self-check inspired by publicly described CTID material, built for a quick gut-check — not a substitute for MITRE's own INFORM assessment at ctid.mitre.org/inform, and not affiliated with MITRE or the Center for Threat-Informed Defense.

Why are the three dimensions weighted 35/40/25 instead of evenly?

That weighting mirrors the shape MITRE's own INFORM framework uses: Defensive Measures counts for the most because taking defensive action is the point, Cyber Threat Intelligence next because it drives what gets defended, and Test & Evaluation last — not because it matters least, but because it validates the other two rather than standing alone.

Why only 12 questions when INFORM has 22 components?

This is a condensed practitioner gut-check, not a replacement for INFORM's full assessment. Four questions per dimension is enough to tell you which of the three is weakest — if the result says you're weak in, say, Test & Evaluation, that's your cue to go run the real INFORM assessment for the detailed breakdown, not to treat this score as the final word.

What if I don't have a dedicated purple team?

Score Test & Evaluation honestly rather than generously. Occasional manual testing against a known technique — even without a formal purple-team function — is a fair 'Partial.' The point of a low score there isn't to shame you, it's to show that Test & Evaluation is where your program's investment should go next.

// How to read your score

What “mature” actually means here

The four tiers this tool maps to aren't a leaderboard — they're a description of how the three dimensions connect. In practice, a program's tier is set by its weakest link, not its average.

Level 1 — Ad hoc

Defense exists, but nothing connects it to threat intelligence. Detections come from vendor defaults and compliance checklists; nobody can say which adversary techniques they were built for.

Level 2 — Developing

Some ATT&CK mapping is happening, but it lives in one team or one spreadsheet. Coverage gets measured by technique count, not by whether a detection would actually fire.

Level 3 — Managed

All three dimensions operate as a loop: intelligence priorities drive detections, and testing results feed back. Gaps at this level are usually resourcing, not design.

Level 4 — Optimized

The loop runs on a cadence, and detection quality is graded by evasion-resistance — what CTID's Summiting the Pyramid project is for — not just presence. Getting here mostly means deepening what Level 3 already does.

One honest caveat: this is a twelve-question gut-check. A real maturity reading — the kind you'd put in front of a budget owner — needs MITRE's full INFORM assessment, which scores 22 components instead of summarizing three dimensions. Use this to find your weakest dimension; use INFORM to make the business case.

For the reasoning behind the framework — why a detection built on a file hash costs the adversary nothing to evade, while one built on a technique costs them a change in how they operate — read Threat-Informed Defense Is Detection Engineering, Minus the Guessing. It covers the Pyramid of Pain logic this assessment assumes, where most TID programs fail, and what to build first.