UTIOM stands for the Unified Threat-Informed Operations Model. It is a lifecycle framework for cybersecurity and security operations centers (SOCs). It connects business strategy, threat-informed detection engineering, and incident response into a single, measurable system focused on real-world adversary behavior.
UTIOM is an operating framework that helps organisations unify siloed security functions into a single threat-informed operation. It connects management, engineering and operations through one lifecycle, provides the methodology to run it, and can be measured — so maturity is demonstrated rather than asserted.
How UTIOM is structured
One canonical view: three operating pillars, seven lifecycle phases, three cross-cutting enablers, the STRATA enabling lens and the three v1.4 assessment tiers.
Click to enlarge
Five structures, five jobs
Each structure answers a different question. Confusing them is the most common way a framework becomes unusable.
3 Pillars
Operating structure. Leadership & Governance, Engineering & Enablement, Operations & Analysis. Who owns what, and which discipline each borrows from — management science, systems engineering, decision science. Leadership & Governance is the management and control plane. It establishes vision, strategy, crown jewel priorities, decision authority, investment and governance, and receives operational evidence through the feedback loop to adapt the system.
Talent, Validation and Threat Hunting. These are not lifecycle phases. They operate across multiple phases and pillars, although each has a primary operational home so it can be assessed.
3 Assessment tiers
System-integrity view of assessment results. Strategic & Governance Foundation, Engineering & Operational Capability, Assurance & Evolution. A tier cannot be governed above the tier it rests on, so a strong area cannot conceal a hollow foundation. The tiers do not replace the three pillars, seven lifecycle phases or three cross-cutting enablers — they add a view over the same results.
STRATA
Organisational enabling and design lens. Strategy, Talent, Resilience, Automation, Telemetry, Adaptability. Explains why a capability is strong or weak. It does not replace the pillars, lifecycle or enablers, is not a maturity score, and never changes a UTIOM result.
Diagnostic Capability Index is not Governed Maturity. The index is continuous and drives trends, the radar and prioritisation. Governed Maturity is the official ordinal level, derived from the tiers and floored by the binding constraint. Two results, two questions, never compared.
Core pillars of UTIOM
UTIOM organises security operations into three pillars. Each owns part of the lifecycle, and the framework exists to keep them aligned rather than siloed.
Leadership & Governance — focuses on business vision, the security operations strategy, and prioritizing critical assets (crown jewels).
Engineering & Enablement — builds threat visibility and creates detection mechanisms tuned to actual attacker tactics.
Seven phases, run as a continuous loop rather than a linear project. Each stage produces the input for the next.
1. Vision — the purpose of the security operation, tied to business outcomes rather than security activity.
2. Strategy — the security operations strategy and the threat profile: probable adversaries, motivations and relevant TTPs.
3. Crown Jewels — what must not fail, with threat models and the attack paths through which impact can occur.
4. Threat Visibility — telemetry engineering: the evidence each attack path requires, sourced or engineered, then assured.
5. Threat Detection — threat-informed detection engineering, validated against the behaviour it claims to see.
6. Response — structured incident response and analysis, with containment authority defined before the incident.
7. Continuous Improvement — lifecycle-wide feedback that updates every phase above it.
What “strategy” means in UTIOM
Strategy in UTIOM means the security operations strategy, not the business strategy. The distinction matters, because conflating them is one of the reasons security programmes drift.
Business strategy is an input
It tells you what the organisation is trying to achieve, which markets it operates in, which services it cannot afford to lose, and what regulatory obligations it carries. UTIOM consumes that. It does not produce it.
The security operations strategy is the answer to it
Which adversaries realistically target an organisation of this shape. Which assets carry the business consequence. What capability gets built, in what order, with what owner and what date. How success will be measured. That is what UTIOM's Strategy phase produces.
They must align, not merely coexist
A security operations strategy that cannot be traced back to a business objective is an engineering plan wearing a strategic title. One that works against business objectives — blocking delivery, adding friction without proportional risk reduction — will be routed around, and eventually defunded. Alignment means the security operations strategy actively supports what the business is trying to do, and can demonstrate that it does.
Strategy sits second in the lifecycle: Vision defines purpose, Strategy turns it into direction, priorities and design choices, and those choices guide every phase that follows. Strategy is a lifecycle phase, not a fourth cross-cutting enabler.
How UTIOM compares to traditional SOC models
Traditional SOC models separate the functions
Monitoring, threat intelligence, detection engineering, threat hunting and incident response are typically run as separate functions, with separate teams, separate tooling and separate goals. Work is handed between them, and the handovers are where context is lost.
UTIOM treats them as one discipline
Threat intelligence is incident response before impact. Threat hunting is incident response without an alert. Detection engineering is incident response encoded into logic. Monitoring is continuous incident response at low intensity. They are expressions of the same discipline at different distances from impact, so UTIOM unifies them into one lifecycle instead of coordinating between silos.
Prioritisation is anchored to business consequence
Traditional models measure coverage: how many log sources, how many detection rules, what percentage of a technique matrix. UTIOM anchors prioritisation to crown jewels, so visibility, detection and response are strongest where compromise would cause the most business damage.
Every design decision requires a matching validation
UTIOM pairs each design activity with the activity that proves it. Purple team exercises prove the attack paths were real. Detection QA proves the telemetry delivers. Response outcomes prove the threat profile picked the right adversaries. Without the validation side, the design side is unverified assumption.
The UTIOM incident response lifecycle
UTIOM maps directly onto NIST SP 800-61, extending it into a threat-informed operating model rather than replacing it.
Detection and analysis — threat detection engineering, rule development, tuning and analysis workflows.
Containment, eradication and recovery — engineered playbooks, containment automation and recovery coordination.
Post-incident activity — continuous improvement, with lessons learned feeding back into strategy and engineering.
It can be measured
A framework that mandates measurement and provides no instrument to measure with is incomplete on its own terms. UTIOM ships with four, all free and running entirely in the browser.
Maturity assessment
50 staged criteria across six levels. Gated, so advanced practice built on an incomplete foundation does not count toward your level.
Capability assessment
105 indicators across ten lifecycle domains, returning a position per pillar and a ranked view of where effort buys the most risk reduction.
Metrics calculator
70 metrics with explicit formulas, split into leading and lagging indicators, with time-based metrics scored against adversary breakout time.
Improvement roadmap
Combines the three into one sequenced plan: what is already working, what to fix in the next ninety days, and what depends on that landing first.
Two capability maturity models measure individual pillars in greater depth. TID-CMM asks whether you would see the adversary; TIR-CMM asks whether you could stop it inside the breakout window. Both consume what UTIOM produces.
CISOs and security leaders defining operating models and governance. SOC architects and detection engineers building capability under real constraints. Incident responders who need consistent, threat-aligned execution. Organisations moving from alert-driven security to outcome-driven operations.