← UTIOM
UTIOMv1.4

What is UTIOM?

UTIOM stands for the Unified Threat-Informed Operations Model. It is a lifecycle framework for cybersecurity and security operations centers (SOCs). It connects business strategy, threat-informed detection engineering, and incident response into a single, measurable system focused on real-world adversary behavior.

UTIOM is an operating framework that helps organisations unify siloed security functions into a single threat-informed operation. It connects management, engineering and operations through one lifecycle, provides the methodology to run it, and can be measured — so maturity is demonstrated rather than asserted.

How UTIOM is structured

One canonical view: three operating pillars, seven lifecycle phases, three cross-cutting enablers, the STRATA enabling lens and the three v1.4 assessment tiers.

Click to enlarge UTIOM architecture overview Security operations managed as a living product, divided into three operating pillars. Leadership and Governance is the management and control plane holding the Vision, Strategy and Crown Jewels phases. Engineering and Enablement builds capability and holds Threat Visibility and Threat Detection. Operations and Analysis exercises capability and holds Response and Continuous Improvement. Talent, Validation and Threat Hunting are cross-cutting enablers rather than lifecycle phases. STRATA is an organisational enabling lens across all of it. Three assessment tiers provide a system-integrity view of results, where a tier cannot be governed above the tier it rests on. Security Operations, managed as a living product Leadership & Governance Management & control plane Engineering & Enablement Builds capability Operations & Analysis Exercises capability · Analysis & Response LIFECYCLE PHASES 1 Vision 2 Strategy 3 Crown Jewels 4 Threat Visibility 5 Threat Detection 6 Response 7 Continuous Improvement CROSS-CUTTING ENABLERS Talent Validation Threat Hunting Not lifecycle phases. They act across multiple phases and pillars, each with a primary assessment home. ENABLING LENS STRATA — organisational enabling lens Strategy · Talent · Resilience · Automation · Telemetry · Adaptability Explains why capability is strong or weak. Not a maturity score and not an additional assessment domain. ASSESSMENT VIEW Tier 1 — Strategic & Governance Foundation Vision & Governance · People & Operating Model Strategy & Threat Profile · Crown Jewels Tier 2 — Engineering & Operational Capability Threat Visibility · Threat Detection Threat Hunting · Response Tier 3 — Assurance & Evolution Validation & Adversary Emulation Continuous Improvement A tier cannot be governed above the tier it rests on. The tiers do not replace the three pillars, seven lifecycle phases or three cross-cutting enablers. 10 assessed domains · 105 capability indicators · 50 maturity criteria · 70 metrics

Five structures, five jobs

Each structure answers a different question. Confusing them is the most common way a framework becomes unusable.

3 Pillars
Operating structure. Leadership & Governance, Engineering & Enablement, Operations & Analysis. Who owns what, and which discipline each borrows from — management science, systems engineering, decision science.
Leadership & Governance is the management and control plane. It establishes vision, strategy, crown jewel priorities, decision authority, investment and governance, and receives operational evidence through the feedback loop to adapt the system.
7 Lifecycle phases
How operational value flows. Vision → Strategy → Crown Jewels → Threat Visibility → Threat Detection → Response → Continuous Improvement.
3 Cross-cutting enablers
Talent, Validation and Threat Hunting. These are not lifecycle phases. They operate across multiple phases and pillars, although each has a primary operational home so it can be assessed.
3 Assessment tiers
System-integrity view of assessment results. Strategic & Governance Foundation, Engineering & Operational Capability, Assurance & Evolution. A tier cannot be governed above the tier it rests on, so a strong area cannot conceal a hollow foundation. The tiers do not replace the three pillars, seven lifecycle phases or three cross-cutting enablers — they add a view over the same results.
STRATA
Organisational enabling and design lens. Strategy, Talent, Resilience, Automation, Telemetry, Adaptability. Explains why a capability is strong or weak. It does not replace the pillars, lifecycle or enablers, is not a maturity score, and never changes a UTIOM result.

Diagnostic Capability Index is not Governed Maturity. The index is continuous and drives trends, the radar and prioritisation. Governed Maturity is the official ordinal level, derived from the tiers and floored by the binding constraint. Two results, two questions, never compared.

Core pillars of UTIOM

UTIOM organises security operations into three pillars. Each owns part of the lifecycle, and the framework exists to keep them aligned rather than siloed.

The UTIOM lifecycle

Seven phases, run as a continuous loop rather than a linear project. Each stage produces the input for the next.

What “strategy” means in UTIOM

Strategy in UTIOM means the security operations strategy, not the business strategy. The distinction matters, because conflating them is one of the reasons security programmes drift.

Business strategy is an input

It tells you what the organisation is trying to achieve, which markets it operates in, which services it cannot afford to lose, and what regulatory obligations it carries. UTIOM consumes that. It does not produce it.

The security operations strategy is the answer to it

Which adversaries realistically target an organisation of this shape. Which assets carry the business consequence. What capability gets built, in what order, with what owner and what date. How success will be measured. That is what UTIOM's Strategy phase produces.

They must align, not merely coexist

A security operations strategy that cannot be traced back to a business objective is an engineering plan wearing a strategic title. One that works against business objectives — blocking delivery, adding friction without proportional risk reduction — will be routed around, and eventually defunded. Alignment means the security operations strategy actively supports what the business is trying to do, and can demonstrate that it does.

UTIOM diagram showing Strategy as the primary directional enabler for downstream lifecycle phases, with the three pillars, cross-cutting enablers and STRATA.
Strategy sits second in the lifecycle: Vision defines purpose, Strategy turns it into direction, priorities and design choices, and those choices guide every phase that follows. Strategy is a lifecycle phase, not a fourth cross-cutting enabler.

How UTIOM compares to traditional SOC models

Traditional SOC models separate the functions

Monitoring, threat intelligence, detection engineering, threat hunting and incident response are typically run as separate functions, with separate teams, separate tooling and separate goals. Work is handed between them, and the handovers are where context is lost.

UTIOM treats them as one discipline

Threat intelligence is incident response before impact. Threat hunting is incident response without an alert. Detection engineering is incident response encoded into logic. Monitoring is continuous incident response at low intensity. They are expressions of the same discipline at different distances from impact, so UTIOM unifies them into one lifecycle instead of coordinating between silos.

Prioritisation is anchored to business consequence

Traditional models measure coverage: how many log sources, how many detection rules, what percentage of a technique matrix. UTIOM anchors prioritisation to crown jewels, so visibility, detection and response are strongest where compromise would cause the most business damage.

Every design decision requires a matching validation

UTIOM pairs each design activity with the activity that proves it. Purple team exercises prove the attack paths were real. Detection QA proves the telemetry delivers. Response outcomes prove the threat profile picked the right adversaries. Without the validation side, the design side is unverified assumption.

The UTIOM incident response lifecycle

UTIOM maps directly onto NIST SP 800-61, extending it into a threat-informed operating model rather than replacing it.

It can be measured

A framework that mandates measurement and provides no instrument to measure with is incomplete on its own terms. UTIOM ships with four, all free and running entirely in the browser.

Maturity assessment
50 staged criteria across six levels. Gated, so advanced practice built on an incomplete foundation does not count toward your level.
Capability assessment
105 indicators across ten lifecycle domains, returning a position per pillar and a ranked view of where effort buys the most risk reduction.
Metrics calculator
70 metrics with explicit formulas, split into leading and lagging indicators, with time-based metrics scored against adversary breakout time.
Improvement roadmap
Combines the three into one sequenced plan: what is already working, what to fix in the next ninety days, and what depends on that landing first.

Two capability maturity models measure individual pillars in greater depth. TID-CMM asks whether you would see the adversary; TIR-CMM asks whether you could stop it inside the breakout window. Both consume what UTIOM produces.

Who UTIOM is for

CISOs and security leaders defining operating models and governance. SOC architects and detection engineers building capability under real constraints. Incident responders who need consistent, threat-aligned execution. Organisations moving from alert-driven security to outcome-driven operations.

This page is a summary. The full treatment is in the book: The Unified Lifecycle →

Join the UTIOM community. Discuss, contribute evidence and share implementation experience. About the community →