Known-Threat Assurance and Unknown-Threat Readiness
TID-CMM scores how well you are prepared for the adversaries you have already named. That is most of the model, and it should be. This page is about the rest: whether the organisation can recognise, investigate and learn from behaviour that falls outside its current assumptions — and why that is a readiness question, never a coverage number.
Everything in an assessment flows from a threat model: the actors you prioritised, the attack paths you drew to your crown jewels, and the ATT&CK behaviours those two things imply. The scope is deliberately an intersection, and the Validated Coverage Score is deliberately computed against that intersection and nothing wider. This is what makes the number honest. It is also what makes it incomplete, and the model should say so rather than let the reader infer that a high score means “we would see anything”.
Two questions, not one score
Known-Threat Assurance asks whether the organisation is prepared for the actors, attack paths and ATT&CK behaviours already prioritised in its threat model. It can be enumerated: the in-scope technique set is a list, every technique on it has a telemetry status, a detection status and a validation status, and the answer is a percentage with a stated denominator. Eight domains, the five constraints and the coverage score all serve this question.
Unknown & Emerging Threat Readiness asks whether the organisation can recognise, investigate and learn from important behaviour that falls outside its current assumptions: a technique nobody prioritised, a procedure ATT&CK has not catalogued yet, an actor not in the profile, a legitimate tool used in a way nobody modelled. It cannot be enumerated, because the thing being asked about is by definition not on the list. There is no denominator. Any figure that claims to be one is a coverage score of the known set wearing a different label.
The model never says “unknown threat coverage”, and neither should an assessor. Unknown threats cannot be counted, so they cannot be covered in the sense the coverage score uses. What can be assessed is readiness: whether the telemetry, the analytics, the people and the feedback loops exist that would turn an unfamiliar behaviour into an investigation, and an investigation into a change to the threat model. Readiness is scored through the sub-capabilities below. It is a view over the model, not a ninth domain.
Two ways in, one machinery
Evidence enters the model in two ways. A known threat arrives as threat evidence, is scoped into techniques and paths, and is answered by detection and validation. An unknown or emerging signal arrives as an anomaly, a hunt finding or a deception interaction, is investigated, and becomes new threat evidence. Correlation, the timeline and the feedback into the threat model serve both; they are not a third kind of threat.
- Known threat
- threat evidence
- scoped techniques
- detection and validation
- Unknown or emerging signal
- anomaly, hunt or deception
- investigation
- new threat evidence
- Both
- correlation
- timeline
- model feedback
The comparison
| Known-Threat Assurance | Unknown-Threat Readiness | |
|---|---|---|
| The question | Would we see the adversaries we have prioritised, doing the things they are documented doing, on the paths we drew? | Would we notice, investigate and learn from important behaviour we did not prioritise or could not have named? |
| Scope | The in-scope technique set: an intersection of platforms, prioritised actors and modelled attack paths. Enumerable. | Important behaviour outside current assumptions, or not yet represented by the scoped technique set. It cannot be enumerated completely in advance. |
| What is measured | Per technique: telemetry reach, detection logic, validation within the recency window. Rolled up into the Validated Coverage Score and the domain scores. | Per capability: whether behavioural and deviation detection exists, whether telemetry spans domains, whether hunting is hypothesis-led and continuous, whether anomalies become investigations and investigations become model changes. |
| Unit of evidence | A named artefact per technique: the rule, the emulation result, the telemetry inventory row. | A named artefact per capability: the baseline definition, the hunt library, the deception register, the analytic register with drift records, the case that changed the threat profile. |
| The output | A percentage with a stated in-scope count, a ranked list of gaps, a roadmap. | A statement of readiness against the sub-capabilities below, and a tracked record: how many unfamiliar behaviours were investigated, what each investigation concluded, how many became detections or model changes, and how long the feedback took. Counts, not a rate — there is no denominator. |
| Where it lives in the model | TI, TM, DC, DE and AV, constrained by C1–C5; the Validated Coverage Score. | TI.2, TM.6, DC.2, DC.5, DC.6, DE.6, DE.10, AA.2, AA.4, AA.5, AA.6 and AA.7, read together. |
| What good looks like | A high coverage score over an honestly scoped set, with validation results inside their window. | Unfamiliar behaviour is investigated by a repeatable workflow, its outcomes are tracked, and it reliably changes the threat profile, the models and the detection backlog, with a short and measured time from finding to feedback. |
| How it fails | Claiming coverage without visibility; scoring detection that was never validated; a convenient scope. | Treating an anomaly score as a detection; a vendor model nobody understands; hunts that only re-cover known ground; findings that never reach the threat model. |
Where readiness already lives in the model
No sub-capability is added for unknown threats, and none should be: readiness is what the existing capabilities look like at their upper levels, where the loop from observation to model change closes. The twelve below carry it. Each links to its full descriptors in the register.
| Sub-capability | What it contributes to readiness | Where readiness becomes visible |
|---|---|---|
TI.2 Threat profile and adversary prioritisation | The profile is the boundary of the known. Readiness is whether that boundary moves when reality disagrees with it. | Level 4: re-scored against internal telemetry, with recorded downstream tasking. Level 5: includes emerging and unattributed behaviour clusters. |
TM.6 Model maintenance and change triggers | A significant incident is a defined trigger for model review. An unfamiliar behaviour that reaches the model only through memory is a model that decays. | Level 3: incidents and new actors force review, completion tracked. Level 4: drift between model and reality is sampled and reported. |
DC.2 Telemetry quality, completeness and timeliness | Deviation detection is only as good as the baseline, and the baseline is only as good as the data. Known-gap periods must be recorded, because an anomaly during a gap is an artefact. | Level 3: quality measured per source with alerting on deviation. Level 4: known-gap periods recorded and coverage claims adjusted for them. |
DC.5 Coverage breadth across attack surfaces | An adversary you did not model will use the surface you did not instrument. Cross-domain telemetry is the precondition for cross-domain correlation. | Level 3: per-surface scoping with recorded accepted risk. Level 4: per-surface reporting so endpoint strength cannot mask a blind identity or cloud plane. |
DC.6 Visibility gap management | Blind spots are where the unknown lives. A register with owners, priorities and dates is the difference between a tolerated gap and a managed one. | Level 3: gaps registered with affected techniques and crown jewels. Level 4: closure rate reported, uncloseable gaps compensated or explicitly accepted. |
DE.6 Detection health and silent-failure monitoring | A detection that stopped working is a self-inflicted unknown. Silent failure is discovered during an incident, or never. | Level 3: health monitored on data availability, schema drift and volume change. Level 5: canary events prove the path end to end. |
DE.10 Detection modality breadth | A single modality is a single evasion problem. Behaviour that slips past event analytics can still be caught in memory, on the wire, in identity behaviour or on a decoy. | Level 3: modalities chosen per behaviour. Level 5: modalities corroborate each other, raising confidence and the cost of evasion. |
AA.2 Correlation and attack-chain assembly | Weak signals are what an unmodelled intrusion produces. Readiness is whether they are assembled into an entity, a chain and a timeline rather than triaged one at a time. | Level 4: risk-based aggregation of weak signals into scored entities. Level 5: graph correlation reconstructs the path against real topology. See correlation and timeline reconstruction. |
AA.4 Advanced analytics governance | Behavioural and statistical analytics are the instruments that see deviation. Ungoverned, they see noise, and drift silently into seeing nothing. | Level 3: purpose, targeted behaviour, features and owner documented. Level 4: precision, recall and drift evaluated with a re-baselining cadence. |
AA.5 Threat hunting programme | Hunting is the deliberate search for what the detections did not catch. Hypothesis-led hunting probes the edges of the threat model; continuous hunting keeps probing as the estate changes. | Level 3: hypothesis, scope, method, result and a required output per hunt. Level 4: negative results retained. Level 5: continuous, partly automated, a primary source of the backlog. |
AA.6 Case management and knowledge capture | An investigation of unfamiliar behaviour is only readiness if what it learned survives the analyst. Cases are the record that feeds the profile and the backlog. | Level 3: mandatory structure including the detection that fired or should have. Level 4: cross-case analysis drives the backlog. |
AA.7 Deception and adversary engagement | A tripwire fires on the interaction, not on the technique. Deception can expose activity without prior knowledge of the exact procedure, which is why it belongs here — although its placement still depends on understanding the estate and the likely adversary paths. | Level 3: placed at attack-tree choke points and along modelled paths. Level 4: coverage of choke points measured, triggers exercised. |
What readiness is made of
Behavioural and deviation-based detection
Signature and rule content encodes what is already known. Behavioural detection encodes what is normal for an entity — a user, a service account, a host, a workload — and reports departures from it. The departure is the signal, and the signal is agnostic to technique. That is its strength and its limitation in one sentence: it will fire on a procedure nobody has catalogued, and it will fire on the finance team closing the quarter. A baseline needs a defined population, a defined window, a documented feature set and a recorded false-positive rate, or it is a random number generator with a dashboard.
An anomaly is an investigation lead, not proof of malicious activity. It earns an investigation, an entity, a timeline and a verdict. It does not earn a detection credit, a coverage status, or a line in a board report until a human or a validated analytic has turned it into one.
Cross-domain telemetry
An intrusion that was not modelled will still touch identity, endpoint, network, cloud
control plane, SaaS and email — usually several, usually in sequence. Telemetry that
concentrates on one surface can only ever see one chapter of it. DC.5 scores
breadth deliberately, per surface, so that a strong endpoint programme cannot hide a blind
identity plane. Readiness needs the breadth and the normalisation
(DC.3) that lets a session on one surface be joined to a process on another.
Multi-modal detection
Event analytics, file and memory content matching, network protocol analysis, identity
and entitlement behaviour, integrity monitoring and deception are different instruments
with different blind spots. DE.10 scores whether modalities are chosen per
behaviour rather than inherited from whichever product was bought first. For behaviour that
evades one modality by design, a second modality that corroborates is the difference
between a hunch and a case.
Hypothesis-led and continuous hunting
Hunting is the organised search for what the detections missed. At AA.5
level 3 every hunt has a hypothesis drawn from the threat profile, the models, the attack
trees or a validation gap, a data scope, a method, a result and a required output. The
hypotheses that matter for readiness are the ones at the edge of the model: if an
actor we have not prioritised reached this crown jewel, what would the last three steps
look like in our data? Continuous hunting — recurring hunts promoted to
scheduled analytics, hunts validated against emulation ground truth — is what keeps
the edge moving as the estate changes. Negative results are kept, so the same ground is not
re-covered blindly.
Deception and tripwires
A canary credential, a decoy share, a honeytoken inside the data an adversary would
actually steal. When a deception asset is deliberately placed and governed so that
legitimate activity has no reason to touch it, an interaction is a high-confidence signal,
whatever technique reached it. It still requires context and verification, and an
interaction that turns out to be legitimate must be treated as a possible placement defect
rather than dismissed as noise. AA.7 scores placement at attack-tree choke
points, refresh so the decoys age like the estate around them, and exercised
trigger-to-alert paths. Deception can expose activity without prior knowledge of the exact
procedure, although its placement still depends on understanding the estate and the likely
adversary paths; the assessment tool credits it as an assurance floor for the techniques a
choke point carries, never as telemetry it does not have.
Analytics and model drift
Behavioural analytics decay. The population changes, the estate changes, the adversary
learns what the baseline tolerates. AA.4 asks for each analytic to have a
documented purpose, a targeted behaviour, named features, an owner, and — at level 4
— measured precision, recall and drift with a re-baselining cadence. An analytic that
cannot be explained well enough for an analyst to justify an action on it is not a
detection; it is a liability with a licence fee.
Unattributed behaviour clusters
Not every intrusion resolves to a named group, and the profile should not pretend
otherwise. TI.2 at level 5 includes emerging and unattributed behaviour
clusters: a set of behaviours observed together, in this estate or in sector reporting, that
no ATT&CK Group yet explains. A cluster is scoped, hunted and modelled on its own terms
until attribution catches up, or does not. Waiting for a name before acting is how an
unknown stays unknown for a second quarter.
Internal telemetry feeding the threat profile
The loop closes when what the organisation observed changes what it expects.
TI.2 at level 4 re-scores the profile against internal telemetry, not only
external reporting, and records the downstream tasking that follows. A behaviour caught by a
hunt, a decoy or a baseline that does not end up in the profile, the models
(TM.6), the detection backlog and the emulation plan was an incident, not a
lesson.
When something unfamiliar fires
Readiness is a workflow before it is a score. This is the one the model expects to find, in a playbook and in case records, when behaviour outside the threat model is found.
- Preserve the original telemetry and evidence. Retention windows, rollovers and pipeline drops do not wait for the investigation. Snapshot the raw records before anything else.
- Identify affected identities, hosts, workloads, sessions and processes. The entities are the spine of everything that follows.
- Correlate related weak signals across domains. The behaviour that fired is rarely the first; look for what preceded it on the same entities and on the surfaces they touched.
- Reconstruct the adversary timeline. Order what was observed, mark what was inferred, and mark the blind periods honestly. The correlation and timeline page sets out what that record must contain.
- Determine crown-jewel exposure and viable attack paths. Where the
entities sit relative to the assets that matter, and which modelled or computed paths run
through them (
TM.4). - Create temporary hunts, monitoring and detection hypotheses. Look for the same behaviour elsewhere in the estate, and watch the affected entities while the investigation runs.
- Validate the behaviour where safely possible. Reproduce it in a controlled way so that a detection can be built against ground truth rather than against one sighting.
- Hand prevention and containment to TIR-CMM. Whether the adversary can be stopped, by whom, with what authority and how fast, is the response model’s question. The boundary is drawn on purpose.
- Convert the finding into TI, TM, DE and AV work. A profile change, a model change, a detection in the backlog and an emulation case. Four tickets, or it did not happen.
- Update the threat model and detection assumptions. The behaviour is now known. The scope moves, the in-scope set changes, and the coverage score is recomputed against a slightly more honest denominator.
Evidence requirements
Readiness is scored through the twelve sub-capabilities, so the evidence is theirs, and C3 applies as it does everywhere: a 4 or a 5 needs a named artefact. The artefacts that speak to readiness specifically:
- The threat profile with its re-score records and the tasking that followed a change
driven by internal telemetry (
TI.2). - The change-trigger definitions and a review log showing an incident forcing a model
review (
TM.6). - Per-source quality measurement with known-gap periods recorded
(
DC.2); per-surface coverage reporting and accepted-risk records (DC.5); the visibility gap register (DC.6). - The detection health dashboard with dependency mapping (
DE.6) and the modality map per prioritised scenario (DE.10). - The analytic register with owners, features, ATT&CK mapping and drift evaluation
records (
AA.4). - The hunt library with hypotheses, methods, outcomes and retained negatives, and the
hunt-to-detection conversion metric (
AA.5). - The deception asset register mapped to choke points, with exercised
trigger-to-alert records (
AA.7). - Cases with the mandatory structure, and at least one that demonstrably changed the
profile or the backlog (
AA.6,AA.2).
Where it appears in the tool
The homepage puts the two questions side by side and sends both to the same assessment. On the results page, the Unknown-Threat Readiness view and section D of Assurance at a glance report the relevant sub-capabilities assessed and not assessed, the lowest counted levels, whether evidence text was supplied, and the top improvement actions — as counts and statements, never as a percentage.
Limitations
Readiness cannot be proven the way coverage can. A validated detection is evidence that the tested behaviour was observed under the validated conditions, on the tested surfaces and within the stated evidence window; a hunt library is evidence that someone is looking, not of what they would find. The model therefore scores the capabilities, not the outcome, and an honest report says so.
Behavioural detection has a cost that scales with the quality of the baseline and the
patience of the analysts. Where DC.2 is weak the baseline is wrong, and where
AA.4 is weak nobody knows how wrong. A readiness claim resting on an ungoverned
analytic is not a claim.
Deception only fires where it was placed. It is a high-confidence signal on the modelled paths and silent everywhere else; it extends readiness along the attack trees, not across the estate, and a decoy that legitimate activity keeps touching is a placement defect, not a detection.
And the model cannot see the adversary who leaves no trace in any instrumented surface.
That is a visibility gap (DC.6), it belongs on the register with an owner and
a date, and no readiness argument closes it.
Common anti-patterns
- Reporting an anomaly score as detection coverage. The vendor dashboard says 94% of entities are baselined. Nothing has been detected.
- “Unknown threat coverage: 71%.” A percentage of an uncountable set. It is the known set again, relabelled.
- The black box. A machine-learning feature enabled with default
settings, never evaluated, whose alerts are closed as noise because nobody can say what
they mean (
AA.4level 0 or 1). - Hunting the known. Hunts that re-run existing detections over longer windows. Useful for validation; not readiness.
- The unmonitored honeypot. Deployed once, never refreshed, never
exercised. It would not be noticed firing (
AA.7level 1). - The finding that stayed in the ticket. Investigated, closed, and absent from the profile, the models and the backlog. The behaviour is still unknown to the organisation; only one analyst knows it.
- Baselining over a gap. A normal built during a telemetry outage
that
DC.2never recorded, so the return to normal fires as an anomaly and the real deviation does not. - Treating readiness as a ninth domain. A separate score, separately gamed. It is a view over the twelve sub-capabilities above, and it moves only when they do.
The Validated Coverage Score · Correlation and timeline reconstruction · Prevention, protection and the TIR-CMM boundary · The 58 sub-capabilities