Assess
Review processes, tooling, telemetry, governance, evidence, and operating model.
Strategic Services
Threat Foundry strategic services help security leaders understand current maturity, prioritize investment, and build practical roadmaps across threat hunting, SOC operations, detection engineering, AI security, compliance, and OT/ICS resilience.
Engagement Approach
Each assessment is built to answer three questions: where are we now, what matters most, and what should we do next. The output is practical enough for technical teams and clear enough for executives, audit committees, and program sponsors.
Review processes, tooling, telemetry, governance, evidence, and operating model.
Benchmark maturity and map current state against the chosen framework or domain.
Separate quick wins, risk drivers, control gaps, and roadmap investments.
Deliver executive reporting, technical recommendations, and follow-on planning.
Assessment Catalog
Choose a focused assessment or combine related services into a broader cyber program review.
Evaluate the ability to proactively identify, investigate, and mitigate threats before they become incidents. Reviews hunting processes, data sources, workflows, ATT&CK coverage, hypothesis development, execution, and outcome measurement.
Assess people, process, technology, incident response, detection coverage, intelligence integration, automation, metrics, and governance against operating best practices.
Measure how effectively the organization develops, validates, deploys, and maintains security detections across SIEM, EDR, Sigma, YARA, ATT&CK mapping, testing, false positives, and detection-as-code practices.
Evaluate readiness to securely adopt, govern, and operationalize AI, including governance, data security, model risk, third-party AI, secure development, compliance, and monitoring controls.
Measure cybersecurity capabilities against NIST CSF 2.0 across governance, risk management, asset visibility, protection, detection, incident response, and recovery planning.
Evaluate implementation and effectiveness of the CIS Critical Security Controls to identify practical, prioritized investments that reduce risk.
Determine readiness for CMMC requirements by reviewing practices, evidence, documentation, policies, and operations needed to protect CUI and support certification objectives.
Assess compliance with NIST SP 800-171 requirements for protecting CUI, including security controls, documentation, and operational processes.
Evaluate OT and ICS security posture using IEC 62443 and industry practices across architecture, asset visibility, segmentation, remote access, vulnerability management, monitoring, and response.
Measure capabilities against CISA CPGs, focusing on a prioritized foundation of controls that reduce risk and improve cyber resilience.
Program Bundles
Strategic Briefing
Bring the current challenge: detection gaps, SOC maturity, compliance readiness, AI governance, or OT risk. We will help map the right assessment path.