Liberty91

Case Studies / The analyst team

From three days to 40 minutes: how an energy major's threat intelligence team got ahead of the news.

A major energy enterprise in the UAE · Critical infrastructure · Threat intelligence team

Use case

Analyst acceleration across the intelligence cycle: collection, triage, analysis and production.

Goal

Stop being surprised by threat events others reported first, and get relevant, finished products out while they still matter.

Challenge

Manual collection and triage consumed most of the team's week, and coverage gaps meant leadership sometimes heard about relevant threats from outside the team.

Solution

Liberty91's agents collect and triage continuously against the organisation's profile, contextualise each threat against affected assets and controls, and draft finished products the analysts review and send.

The challenge.

The threat intelligence team at one of the region's largest energy companies had a problem every analyst team recognises. Collection was manual, and one person can only read so many sources. By the time an event had been found, read and assessed, days could pass. Worse than the delay was the exposure: occasionally a threat event the team had not yet caught reached their CISO through another channel, and the team was suddenly answering "why didn't we know about this?" instead of briefing on it. For a critical infrastructure operator, that is not an operational annoyance. It is the exact failure mode a CTI function exists to prevent.

What changed.

With Liberty91, the collection and triage the team used to do by hand now happens continuously. Hundreds of sources are read around the clock and filtered against the organisation's profile on the way in, so the analysts start their day with the events that matter already surfaced, not with a reading list. When a relevant threat event lands, the platform has already assessed it against their environment: which of their assets and technologies are affected, and how the threat measures up against the defences they already run. The question leadership actually asks, "what does this mean for us?", is answered in the draft before an analyst opens it. The same analysis feeds every output the team needs: written reports for people, and STIX bundles, Sigma rules and KQL queries the SOC can load directly. The analysts review, adjust where their judgement says so, and send.

The result.

The team briefs stakeholders on relevant threat events before anyone else in the business raises them, every product is contextualised to their own threat profile including affected assets and controls, and detection engineering gets machine-ready output from the same pass that produced the report.

3 days to 40 min

Average time from a breaking threat event to a finished, contextualised product.

400+

Sources monitored continuously against the organisation's profile, up from around 40 read manually.

0

Relevant threat events reaching leadership from outside the team in the first six months.

We used to find out from our CISO. Now our CISO finds out from us, with the assessment and the detection rules attached.

Threat Intelligence Lead, a major energy enterprise in the UAE

Evidence gathered through a customer interview, 2026. The customer has asked not to be named; role and organisation verified by Liberty91.

See what your organisation's threat picture looks like.