Knowledge Base · Programme Building

The CTI maturity model

3 min read · Updated September 2026

A CTI maturity model describes the progression of an intelligence function across five levels, from ad hoc and reactive through to optimised and adaptive. Its purpose is not to push every organisation to level five but to establish where a function currently sits, where it should sit given the business it supports, and what the gap between those two costs.

Standing up an intelligence function is not a binary decision. It is a spectrum, and the right position on it depends on the size, complexity and risk appetite of the business being supported. Organisations get this wrong in both directions: some try to build a complete intelligence team from the outset without the inputs or use cases to justify it, while others leave a single analyst embedded in another function, unsupported and misaligned.

A maturity model exists to make that judgement explicit. Rather than comparing organisations with each other, it asks three questions about yours: is the capability aligned to business needs, is it resourced proportionately to the risk, and are its products actually influencing decisions.

Level 1: ad hoc and reactive

Intelligence is informal or non-existent. Information is gathered reactively during incidents, there are no standing requirements, reporting is inconsistent and produced manually under pressure, and there are no dedicated processes or tooling. This is survival mode, and it is common in early-stage and small organisations.

Level 2: defined but isolated

A function exists, but usually embedded inside another team such as operations, incident response or risk. Analysts lean heavily on vendor feeds or open-source material, there is no formal prioritisation of requirements, reporting is sporadic and audience-specific, and influence on wider decision-making is limited. The function exists; its impact does not.

Level 3: integrated and operational

Objectives are defined and aligned to business and risk teams. Priority intelligence requirements are established and reviewed periodically, reporting runs to a regular cadence, frameworks such as ATT&CK are embedded, and stakeholder engagement spans operations, incident response, cloud and risk. This is operational maturity: the function is a recognised contributor to risk reduction.

Level 4: intelligence-led

Intelligence drives proactive decision-making across both cyber and business units. It informs detection engineering, vulnerability prioritisation and crisis simulation, integrates with engineering and red team work, includes geopolitical and strategic inputs in threat modelling, and feeds enterprise risk frameworks and board reporting. The function is strategic: respected, resourced and embedded.

Level 5: optimised and adaptive

The capability evolves continuously with threat trends, business change and stakeholder feedback. It includes automation, enrichment pipelines, AI-assisted analysis and tailored stakeholder feeds. Intelligence informs product development, mergers, market entry and regulatory posture. Feedback loops are formalised, quality assurance is standard, and performance is measured against defined outcomes.

Using the model without misusing it

A maturity model is a framework for reflection rather than a checklist for perfection, and the most common mistake is treating the top level as the target for everyone. Every level brings value if it matches the need. A small fintech may thrive at level three. A multinational bank may struggle without level four.

Used well it prioritises investment and tooling decisions, sets realistic expectations with the CISO and wider stakeholders, demonstrates progress in language risk and business leaders understand, and avoids the build-everything trap where capability outpaces consumption. That last one is worth dwelling on: a function producing more intelligence than anybody reads has not matured, it has overbuilt.

Maturity is ultimately about fit, influence and purpose rather than headcount or tooling. A programme is mature when its outputs are trusted, its sources are respected, and its analysts are empowered to shape how the organisation defends itself.

How this maps to the platform

Most of what separates level two from level three is structural rather than technical: formal requirements, a reporting cadence, frameworks embedded, stakeholders engaged. Conundrum supplies that structure, which is why it tends to be most useful to functions sitting at the lower levels with the ambition and the mandate to move up.

What no platform supplies is the influence. Levels four and five are defined by whether intelligence changes decisions, and that is earned through relationships and reporting quality rather than bought.