CTI Programme Maturity Assessment

SkillAI & models

Use when assessing the maturity of a CTI programme, the user asks "how mature is our CTI?" / "what should we improve next?", or wants a benchmark against the five-level model across six dimensions.

Available today. Use it from your connected AI after setup.

Connect ahel once, and every AI you use reads what you have installed.

Then ask your AI: use the CTI Programme Maturity Assessment skill

What this skill tells your AI

The instructions your AI receives, as published by liberty91ltd/cti-skills in skills/maturity-assessment/SKILL.md and read by ahel’s review.

Maturity Levels

LevelNameDescription
1Ad-hocNo formal CTI function. Reactive, incident-driven. Intelligence is incidental.
2EmergingBasic CTI capability. Some collection, limited analysis. Primarily tactical (IOC feeds).
3DefinedFormal CTI function with documented processes. Strategic, operational, and tactical output. PIRs defined.
4ManagedMature CTI programme. Stakeholder-driven, measured effectiveness, feedback loops. Proactive intelligence.
5OptimizedIntelligence-driven organisation. CTI informs all security decisions. Continuous improvement, advanced analytics, community contribution.

Assessment Dimensions

1. Collection

LevelIndicators
1No systematic collection. Ad-hoc Google searches when incidents occur.
21-2 threat feeds (usually free). No collection plan.
3Multiple sources across OSINT, commercial feeds, ISACs. Collection plan exists. Source assessment applied.
4Comprehensive collection mapped to PIRs. Source quality tracked. Dark web monitoring. Automated collection pipelines.
5Full-spectrum collection. HUMINT relationships (ISACs, vendors, government). Predictive collection based on emerging threat indicators.

2. Analysis

LevelIndicators
1No analysis. Raw data forwarded to SOC.
2Basic enrichment (VirusTotal lookups). IOC correlation. No structured techniques.
3Structured analysis applied. Threat assessments produced. ATT&CK mapping. Confidence levels used.
4Full SAT toolkit (ACH, red team, horizon scanning). Knowledge cells maintained. Alternative hypotheses routinely considered.
5Advanced analytics. Machine learning augments human analysis. Predictive threat modelling. Community-leading analysis.

3. Production

LevelIndicators
1No intelligence products. Maybe an IOC spreadsheet.
2Ad-hoc alerts and IOC lists. No standard templates. Inconsistent quality.
3Standardised products (flash reports, assessments). TLP applied. Likelihood language used. Quality review process.
4Full product suite tailored to stakeholder needs. Detection rules (SIGMA/YARA/KQL). STIX bundles for sharing.
5Dynamic intelligence products. Real-time dashboards. Automated tactical output. Strategic foresight publications.

4. Dissemination

LevelIndicators
1Intelligence stays within the CTI team.
2IOCs pushed to SIEM/EDR. Some ad-hoc briefings.
3Products reach defined stakeholders. TLP-governed sharing. Regular briefing cadence.
4Tailored delivery per stakeholder. Integration with SOAR/TIP. Feedback collected. ISAC participation.
5Intelligence embedded in all security workflows. Automated dissemination. External sharing (STIX/TAXII). Industry thought leadership.

5. Management

LevelIndicators
1No CTI manager. Analyst works in isolation.
2Informal CTI role. No PIRs. No stakeholder engagement.
3Formal CTI function. PIRs defined and reviewed. Stakeholder register maintained. SOPs documented.
4Programme measured on outcomes. KPIs tracked. Budget justified. Regular programme reviews.
5CTI programme informs security strategy. Board-level reporting. CTI drives investment decisions.

6. Tooling

LevelIndicators
1Email and spreadsheets only.
2Free tools (VirusTotal, MISP community). Manual processes.
3TIP deployed. OSINT tools in use. Some automation.
4Integrated toolchain. API-driven enrichment. SOAR integration. Custom tooling where needed.
5AI-augmented analysis. Full automation of tactical workflows. Custom detection engineering pipeline.

Self-Assessment Questionnaire

For each dimension, select the level that BEST describes current capability:

## CTI Maturity Self-Assessment

**Date**: YYYY-MM-DD
**Assessed by**: [Name/Role]

| Dimension | Current Level | Target Level | Gap |
|-----------|:---:|:---:|:---:|
| Collection | _ | _ | _ |
| Analysis | _ | _ | _ |
| Production | _ | _ | _ |
| Dissemination | _ | _ | _ |
| Management | _ | _ | _ |
| Tooling | _ | _ | _ |
| **Overall** | **_** | **_** | **_** |

### Key Findings
[What are the biggest gaps?]

### Recommended Actions
1. [Highest-impact improvement]
2. [Second priority]
3. [Third priority]

### Timeline
[Realistic timeline for reaching target maturity]

Improvement Priorities

When improving maturity, prioritise in this order:

  1. Management (PIRs, stakeholders) — without direction, other improvements are wasted
  2. Collection — can't analyse what you don't have
  3. Analysis — transform data into intelligence
  4. Production — package intelligence effectively
  5. Dissemination — get intelligence to decision-makers
  6. Tooling — automate and scale (last, not first)

This order reflects a common mistake: organisations buy tools (Level 6) before establishing processes (Levels 1-5). Tools amplify process — if the process is broken, tools amplify the problem.

Signals

GitHub stars
22
Forks
9
Last commit
Aug 2026
Advanced
Catalog kind
skill
Gateway key
maturity-assessment
Source
github.com/liberty91ltd/cti-skills