Case Studies / The analyst team
From three days to 40 minutes: how an energy major's threat intelligence team got ahead of the news.
A major energy enterprise in the UAE · Critical infrastructure · Threat intelligence team
Use case
Analyst acceleration across the intelligence cycle: collection, triage, analysis and production.
Goal
Stop being surprised by threat events others reported first, and get relevant, finished products out while they still matter.
Challenge
Manual collection and triage consumed most of the team's week, and coverage gaps meant leadership sometimes heard about relevant threats from outside the team.
Solution
Liberty91's agents collect and triage continuously against the organisation's profile, contextualise each threat against affected assets and controls, and draft finished products the analysts review and send.
The challenge.
The threat intelligence team at one of the region's largest energy companies had a problem every analyst team recognises. Collection was manual, and one person can only read so many sources. By the time an event had been found, read and assessed, days could pass. Worse than the delay was the exposure: occasionally a threat event the team had not yet caught reached their CISO through another channel, and the team was suddenly answering "why didn't we know about this?" instead of briefing on it. For a critical infrastructure operator, that is not an operational annoyance. It is the exact failure mode a CTI function exists to prevent.
What changed.
With Liberty91, the collection and triage the team used to do by hand now happens continuously. Hundreds of sources are read around the clock and filtered against the organisation's profile on the way in, so the analysts start their day with the events that matter already surfaced, not with a reading list. When a relevant threat event lands, the platform has already assessed it against their environment: which of their assets and technologies are affected, and how the threat measures up against the defences they already run. The question leadership actually asks, "what does this mean for us?", is answered in the draft before an analyst opens it. The same analysis feeds every output the team needs: written reports for people, and STIX bundles, Sigma rules and KQL queries the SOC can load directly. The analysts review, adjust where their judgement says so, and send.
The result.
The team briefs stakeholders on relevant threat events before anyone else in the business raises them, every product is contextualised to their own threat profile including affected assets and controls, and detection engineering gets machine-ready output from the same pass that produced the report.
3 days to 40 min
Average time from a breaking threat event to a finished, contextualised product.
400+
Sources monitored continuously against the organisation's profile, up from around 40 read manually.
0
Relevant threat events reaching leadership from outside the team in the first six months.
“We used to find out from our CISO. Now our CISO finds out from us, with the assessment and the detection rules attached.”
Threat Intelligence Lead, a major energy enterprise in the UAE
Evidence gathered through a customer interview, 2026. The customer has asked not to be named; role and organisation verified by Liberty91.
See what your organisation's threat picture looks like.
More case studies.
The MSSP
How a regional MSSP turned threat intelligence into a priced, sellable service line for 30 customers, delivered under its own brand.
Risk and controls
How a UK insurer connected live threat activity to its assets, suppliers and controls, and fed the gaps straight into its security investment plan.
The CISO
How a large UK bank replaced an expensive CTI programme that had no capacity left for analysis with intelligence its stakeholders act on, from day one.
Premium intelligence, operationalised
How a UK financial services group turns CrowdStrike and Google Threat Intelligence reporting into organisation-specific assessment and action.