Case Studies / The CISO
The CTI programme that finally paid for itself: relevant intelligence, delivered where it gets acted on.
A large UK bank · Office of the CISO
Use case
Relevant, contextualised, actionable intelligence delivered across the security function without the cost and on-ramp of a traditional CTI programme.
Goal
Get intelligence the organisation actually acts on, at a cost and effort the return can justify.
Challenge
An expensive, slow-to-build CTI programme was producing reformatted news, much of it not applicable to the organisation, and stakeholders had stopped reading it.
Solution
Liberty91 identifies the threat events relevant to the organisation on the way in, contextualises them against its profile, and delivers finished products to each consumer in the form they can act on.
The challenge.
This CISO had done what the industry playbook says: invested the time and money to stand up a threat intelligence programme. The return was not there. What reached his inbox, and everyone else's, was mostly a summary of the week's security news inside a corporate template, and the structure of the work explains why. When most of a team's capacity goes to collection, formatting and assembly, reformatting the news is what capacity is left for. Meanwhile the rest of the security function was reading the same headlines from their own sources, and too much of the reporting did not apply to the organisation at all: zero-days in technology they did not run, campaigns against sectors they were not in. An expensive programme, a long on-ramp, and a product the business had quietly stopped reading.
What changed.
Liberty91 changed all three stages at once: what comes in, what happens in the middle, and what goes out. At the front, relevance is decided on the way in. The platform holds the organisation's profile: its sector, its regions, the technology it runs, its suppliers, its stated intelligence requirements. Threat events are assessed against that profile as they break, so a zero-day in technology the organisation does not run never generates a report, and a campaign against their sector in their region does, immediately. In the middle, each relevant event is analysed and contextualised: what it means for this organisation specifically, read against everything the platform knows about the actor, the vulnerability and the environment it lands in. At the output end, intelligence reaches every consumer in the shape they act on. Stakeholders get contextualised reports and briefs, per report or by instant message, framed for their role. The tech stack gets STIX bundles and detection rules, as Sigma or KQL, loaded rather than read. And it arrived without the build: no new hires, no tooling project, no year of tuning. The first products landed as soon as the organisation's profile existed.
The result.
Reporting is relevant by construction, because threat events are filtered against the organisation's actual estate before anyone writes a word. Stakeholders receive intelligence in the form they act on, and the capability arrived at a fraction of the cost of the programme it replaced, with no on-ramp.
95%
Of delivered products rated relevant by their stakeholders, up from roughly half under the previous programme.
60 / month
Contextualised products delivered across the security function: briefs for people, Sigma, KQL and STIX for the stack.
Day one
First reports, indicator lists and detection rules arrived as soon as the organisation's profile existed, against a programme that took a year to stand up.
“We spent two years and serious money building a programme that summarised the news. This started answering 'what does it mean for us?' in the first week.”
CISO, a large UK bank
Evidence gathered through a customer interview, 2026. The customer has asked not to be named; role and organisation verified by Liberty91.
Real intelligence at machine speed, no team to build.
More case studies.
The analyst team
How a UAE energy major's threat intelligence team went from manual collection and days of delay to briefing leadership before anyone else raises it.
The MSSP
How a regional MSSP turned threat intelligence into a priced, sellable service line for 30 customers, delivered under its own brand.
Risk and controls
How a UK insurer connected live threat activity to its assets, suppliers and controls, and fed the gaps straight into its security investment plan.
Premium intelligence, operationalised
How a UK financial services group turns CrowdStrike and Google Threat Intelligence reporting into organisation-specific assessment and action.