Case Studies / Premium intelligence, operationalised
From vendor report to organisational answer: getting the full value out of premium intelligence.
A UK-headquartered financial services group · Threat intelligence team
Use case
Turning premium vendor intelligence from CrowdStrike and Google Threat Intelligence into organisation-specific assessment and action.
Goal
Answer "what does this mean for us, and what should we do?" for every relevant vendor report, without an analyst rewriting the vendor's work.
Challenge
Excellent vendor reporting arrived actor-first and generic by design; making it organisationally relevant took hours of manual correlation per report, so most reports were skimmed and filed.
Solution
Liberty91 reads each vendor report, contextualises it against related reporting and its accumulated knowledge of the actor, vulnerability and malware, assesses it against the organisation's profile, and produces outputs for people, machines and agents.
The challenge.
This team subscribes to first-rate intelligence: CrowdStrike and Google Threat Intelligence reporting is thorough, well sourced and fast. The gap was never the input. The gap was the distance between "Pulsar Kitten exploits CVE-2026-1234 with new modular malware MINIBIKE" and the two questions their organisation actually pays the team to answer: how is this relevant to us, and what should we do about it? Closing that distance by hand meant, for every report, pulling related reporting on the same activity, recalling what was already known about the actor, the vulnerability and the malware family, checking the CVE against the asset inventory, checking the targeting against their sector and suppliers, and then writing the assessment. Done properly it took hours per report. Done quickly it collapsed into restating the vendor's write-up with a paragraph of caveats on top. Most reports got the second treatment, or none.
What changed.
Now the vendor report is the starting point of an analytical chain rather than a document in a queue. When a report arrives through the CrowdStrike or Google Threat Intelligence integration, Liberty91 reads it and contextualises it against all other relevant reporting on the same activity and everything its knowledge agents already hold on that actor, that vulnerability and that malware family. The report joins a maintained picture instead of being assessed in isolation. That picture is then assessed against the organisation itself: the assets and technology it runs, the controls in place, its supply chain, its sector, its region. The output is the answer the team was assembling by hand: this is how the activity is relevant to us, this is the exposure, and this is what to do. People get contextualised reports written for their organisation. Machines get detection rules and STIX bundles ready for the stack. And the organisation's own AI agents get the same intelligence over MCP, structured for direct injection into business processes. The analysts still make the calls; what disappeared is the correlation and assembly between the vendor's report and their judgement, which is where the hours were going.
The result.
Every relevant premium report now gets a full organisational assessment, not just the high-profile ones. The subscriptions the organisation already pays for feed people, the security stack and its own agents from a single analytical pass, and the vendor intelligence investment compounds instead of accumulating in a read-later folder.
3 hours to 10 min
Time from a vendor report landing to a contextualised "here is what it means for us" assessment.
100%
Of relevant vendor reports receiving a full organisational assessment, up from roughly one in five.
3 consumers
Every assessment delivered simultaneously to people, to the security stack, and to the organisation's own AI agents over MCP.
“The vendors tell us what happened, and they do it brilliantly. Liberty91 tells us what it means for us, which is the report our leadership actually reads.”
Senior Threat Intelligence Analyst, a UK-headquartered financial services group
Evidence gathered through a customer interview, 2026. The customer has asked not to be named; role and organisation verified by Liberty91.
Make your premium intelligence yours.
More case studies.
The analyst team
How a UAE energy major's threat intelligence team went from manual collection and days of delay to briefing leadership before anyone else raises it.
The MSSP
How a regional MSSP turned threat intelligence into a priced, sellable service line for 30 customers, delivered under its own brand.
Risk and controls
How a UK insurer connected live threat activity to its assets, suppliers and controls, and fed the gaps straight into its security investment plan.
The CISO
How a large UK bank replaced an expensive CTI programme that had no capacity left for analysis with intelligence its stakeholders act on, from day one.