TID-CMM Threat-Informed Detection Capability Maturity Model

Would you actually see the adversaries most likely to attack you?

Most organisations cannot answer that. They can tell you how many rules they run and how many alerts they closed — neither measures capability. TID-CMM measures whether your detection is driven by adversary behaviour, whether the telemetry exists to see it, and whether any of it has been proven to work.

Half a day for a first answer. Ten screens in your browser, no account, nothing installed. Go deeper when the number has to leave the room — three depths, and what each one is worth.

Model 1.5.0 · 8 domains · 58 sub-capabilities · 348 level descriptors · aligned to MITRE ATT&CK Enterprise v19.2 (697 techniques) · crosswalked to NIST CSF 2.0 and SOC-CMM · open licence, nothing to buy, nothing to install.

The problem

A rule that has never fired on a true positive, running on a log source that stopped reporting six weeks ago, mapped to a technique your adversaries do not use, counts exactly the same as a detection proven to catch a real intrusion in minutes. Every standard metric treats them identically.

Coverage claimed without visibility

A rule exists, is enabled, and is mapped to a technique. It cannot fire, because the data source is deployed on 60% of the estate or stopped parsing after an agent upgrade. Nothing tests it. Nothing monitors it.

Detection built without a threat model

Enable a content subscription and matrix coverage rises impressively. But the adversary who matters does not need a technique the content covers — they need the path through your estate that nobody modelled.

Capability asserted without evidence

“Would we detect credential dumping?” “There is a rule for it, so yes.” That answer reaches a risk register, a board pack and a budget decision. It is tested for the first time by an adversary.

Detection is bounded by visibility, and that is now measurable

MITRE ATT&CK v18 (October 2025) replaced its legacy data-source model with detection strategies and analytics that reference concrete log sources and channels, and v19.2 extends them. That turns a caveat into a computation.

423 techniques — 89% of all Windows techniques in ATT&CK Enterprise v19.2 — have detection analytics that reference Sysmon. For 20 of them it is the only source referenced. If you do not run it, or an EDR supplying equivalent process, command line and module telemetry, that is not a gap in your rule set. It is a gap in physics.

TID-CMM computes this for the techniques you scoped as relevant, bands each one as assured, partial, weak or blind against how much of your estate each source actually covers, and ranks what to enable by how many in-scope techniques it unblocks — naming capabilities and free routes, never products. How telemetry assurance works.

You do not have to know who targets you before you start

Choosing adversaries from 232 documented ATT&CK groups and campaigns is where assessments stall, and a technique set chosen by tooling rather than by threat is the failure this whole model exists to expose. So the tool does not start you with a blank search box.

Declare your sector and the regions you operate in, and it ranks the adversaries ATT&CK documents against organisations like yours — with the reason for each, so you can argue with it. Energy in Ukraine and Russia surfaces a different set from financial services in Europe, because it should.

It suggests. It never selects. Accept the list unchanged and constraint C5 caps TI.2 at level 2, because the question who are you defending against, and how do you know? was answered by the tool rather than by you. Add one it missed, remove one that does not apply, and the ceiling lifts. A model that supplies its own input and then scores you on it is grading its own homework.

44 of the 232 carry no reliable targeting information and are excluded rather than guessed at. How the profile is derived, and what it cannot tell you.

The eight domains

IDDomainWeightSub-caps The question it answers
TIThreat Intelligence & Adversary Prioritisation12.0%6Who are we defending against, and how do we know?
TMThreat Modeling & Attack Path Analysis12.0%7What do their behaviours look like against our architecture?
DCTelemetry & Detection Coverage14.0%6Can we see the activity at all?
DEDetection Engineering16.0%10Do we build, test and maintain detection like engineers?
AVAdversarial Validation & Emulation14.0%8Have we proven any of it works?
AAAnalytics, Automation & Hunting12.0%8Does detection output become a decision at operational tempo?
IRIncident Response & Recovery10.0%6Can we act on what we detect?
GVGovernance, Metrics & Continuous Improvement10.0%7Is this directed, measured and sustainable?

How deep do you want to go?

Every depth uses the same model, the same 58 sub-capabilities and the same tool. What changes is how much evidence you gather, and therefore how far the score can go and how far you can carry it.

Rapid self-assessment

Half a day · 2–3 people · caps at 3.00 · Directional only

The tool, answered from what the team already knows. No artefacts gathered, no interviews.

You get: A baseline, the constraints binding you, your blind techniques and a ranked roadmap.

Use it when: You need to know roughly where you stand and where to look first.

Do not report the number outside the team. Without named evidence C3 holds every sub-capability at 3, so the score is a floor, not a finding.

Structured self-assessment

2–3 days · 6–10 people · caps at 5.00 · Defensible internally

The same tool, but each score above 3 is recorded against a named artefact, and the people who own each domain answer for it.

You get: Everything above, plus a score you can put in a budget case.

Use it when: Annual planning, budget cases, board reporting with assumptions stated.

Still self-declared. Nobody has checked that the artefacts say what the scorer believes they say.

Evidence-based assessment

1–2 weeks · Reviewer plus the team · caps at 5.00 · Defensible externally

Artefacts are reviewed against each claimed level by somebody who did not score it, and validation results are checked for recency.

You get: A result that survives challenge from an auditor, a regulator or an incoming CISO.

Use it when: Assurance obligations, post-incident review, due diligence.

The most expensive and the only one whose number should leave the building unqualified.

The ceiling on a rapid assessment is not a penalty — it is C3 doing its job. A score of 4 or 5 requires a named artefact, and an assessment that gathered none is held at 3 by arithmetic that has been in the model since its first release. You are not being marked down for going fast. You are being told, accurately, that a number produced in half a day without evidence is a place to start looking and not a finding to report.

The full assessment guide covers who to involve, how to scope it and the mistakes that make a maturity assessment worthless.

Part of UTIOM

TID-CMM is the detection module of UTIOM, the Unified Threat-Informed Operations Model. UTIOM's premise is that everything a security operations function does is incident response, and detection is its first phase — get detection right and you are ready for the rest of the loop.

TIR-CMM, the response counterpart, is now published and completes the pair: containment authority, response tempo against adversary breakout time, and whether any of it has been rehearsed. TID-CMM asks whether you would see it; TIR-CMM asks whether you could stop it.

Why TID-CMM still has an incident response domain. The IR domain here measures the detection side of the interface — whether an alert reaches a responder reliably at 03:00, and whether every incident feeds back into detection. It is not a response capability assessment, and it does not attempt to be one: it carries the smallest weight in the model at 10%. If you need to know whether you could actually contain an intrusion inside the breakout window, that is TIR-CMM, and it runs standalone in about twenty minutes. More on how the two fit together.

What you get

The assessment tool

Ten guided screens following the model's own logic: what you run, what you protect, who targets you, what they would use, how they would reach it, what you can see, how you work, where you stand, what to fix — and what to do about it on Monday.

It derives your in-scope ATT&CK set from that — typically 150 to 250 techniques rather than 697 — then tells you which of them you are structurally unable to detect, and exactly what to enable.

Runs entirely in your browser. No server, no analytics, no network requests.

Start the assessment

Everything else