Cyber Threat Intelligence as a Service (CTIaaS)
Cyber Threat Intelligence (CTI) is a proactive part of computer and network security and takes its approach from the traditional intelligence cycle. It focuses on collecting and analysing data to meet strategic, operational and tactical level requirements allowing Cyber Defenders to proactively predict, identify, prevent and respond to attacks.
Features
- Quarterly strategic CTI reporting
- Monthly operational CTI reporting
- Weekly tactical CTI research and sharing via MISP
- Continual vulnerability research
- Ad-hoc advisory tasking
- On demand information requests
- Collaborative development of priority requirements
- Portal access
Benefits
- Real time availability of latest threat intelligence
- Secure access to your own intelligence products
- Interact with the CTI team via secure requests
- Access to a repository of IOC data
- Access to knowledge base of articles, blogs etc
- Synchronised to your own MISP
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 7 3 3 8 7 3 4 8 4 0 0 7 2 5
Contact
CYSIAM LIMITED
Rupert Ryan
Telephone: 07376019394
Email: tenders@cysiam.com
About your service
- Service categories
-
Systems Infrastructure Software
Security
- Cloud native application protection platform
- Security analytics
- Governance, risk and compliance
Network security
- Trusted network access and protection
- Active application security
Data security
- Information protection
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- No constraints. We work with clients to manage changes throughout the life of the service. Service operates 24/7/365
- System requirements
- No mandatory system requirements
User support
- Email or online ticketing support
- Yes
- Support response times
- Acknowledgement of tickets varies with priority of event but usually within max 1hr
- User can manage status and priority of support tickets
- No
- Phone support
- No
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- All CTIaaS clients are allocated a Customer Success Manager who will be their PoC during the service term. Frequency and quality of engagement can be determined by the client.
- Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
Client onboarding consists of the following activities:
► Collaboratively generating Priority Intelligence Requirements (PIRs)
►Identifying critical assets and organisations of interest
►Create access to CYSIAM’s MISP instance
►Provide CYSIAM with an email address for report notifications
►CYSIAM will then create an account (using the email provided) on our portal.
►Login, set up MFA and confirm access to all areas.
►Once service has started, continue to hone PIRs, and submit feedback and RFIs - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- An exit plan is agreed with each client describing all aspects of service off boarding, including data extraction/migration if required.
- End-of-contract process
- The processes described in the agreed exit plan will be implemented.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- PDF documents, plans, designs and reports are shared with the client either via email, Slack, a shared data environment or any other platform the client requires.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- Yes
- What users can and can't do using the API
- XXX
- API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Dashboards and reporting can be customised to meet client requirements as well as other aspects of the service.
Scaling
- Independence of resources
- Operations management keep a close watch on internal measures of SOC utilisation. If the measures breach 75% of maximum capacity then mitigation measures are introduced which include, changed shift patterns, and other efficiency methods. Resilience is underpinned by more strategic decisions including procurement of new tooling and recruitment of SOC staff.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Metrics presented by the real-time dashboard can be tailored to client requirements. Typical metrics include number of current open alerts, resolved alerts, number of P1 alerts, Response time, mean time to resolution, major incident log etc
- Reporting types
- Real-time dashboards
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Encryption of all physical media
- Data sanitisation process
- No
- Equipment disposal approach
- A third-party destruction service
Data importing and exporting
- Data export approach
- This is rarely a requirement in an CTIaaS service but most data sets can be exported if needed.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- N/A
- Approach to resilience
- N/A
- Outage reporting
- N/A
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Multi-Factor Authentication (MFA)
- Access restrictions in management interfaces and support channels
- All remote verification is done using 2FA
- Access restriction testing frequency
- At least once a year
- Management access authentication
- Multi-Factor Authentication (MFA)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- We have a comprehensive information security policy supported by processes all of which are compliant to ISO27001. All staff are briefed on joining with an annual refresh.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Service components and approach are continually tracked by the service lead and overseen by the CTO.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We use Qualys tool for vulnerability scanning and our extensive open source intelligence knowledge to continuously assess and prepare for threats to the organisation and the cyber security industry at large.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We continually monitor our systems for signs of compromise and respond immediately to any concerns.
- Incident management type
- Supplier-defined controls
- Incident management approach
- We are a small enterprise. All events are evaluated and shared with all employees and systems updates accordingly. The process is managed by the CTO/CISO.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 5%
- Between £250,000 and £500,000
- 10%
- Between £500,001 and £1,000,000
- 15%
- Between £1,000,001 and £2,500,000
- 20%
- Between £2,500,001 and £5,000,000
- 25%
- Over £5,000,001
- 30%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- NQA
- ISO/IEC 27001 accreditation date
- Thursday 3 November 2022
- What the ISO/IEC 27001 doesn’t cover
- The whole business except the SOC is covered (SOC coverage is underway)
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Citation ISO Certification Limited
- ISO 9001 accreditation date
- Wednesday 3 April 2024
- What the ISO 9001 doesn’t cover
- Whole business is covered
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 419afc90-a5b0-4586-ba19-994a82cdcdd0
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- C4748965-2508-4394-b10a-8e837badcfa4
- Other security certifications
- Yes
- Any other security certifications
-
- IASME Cyber Assurance Level One
- CREST Accredited for Penetration Testing
- CREST Accredited for Vulnerability Assessment
- CREST Accredited for Cyber Incident Response
- CREST Accredited for Security Operations Centre (SOC)
- NCSC Accredited for Cyber Incident Response (CIR) Standard Level
- NCSC Accredited for Cyber Incident Exercising (CIE)
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
-