Advanced level
SORT ThreatLens: threat intelligence about your technology, not the world’s
Threat intelligence contextualised to the client’s technology stack and prioritised by criticality, fed into the ISMS risk cycle.
What problem it solves
Vulnerability bulletins are unmanageable and almost nothing in them applies. The predictable result is that nobody reads them, and the one vulnerability that did matter goes unnoticed among hundreds that did not. ThreatLens inverts the order: it starts from the organisation’s technology inventory and only reports what touches that inventory, with the analysis of why it matters and what to do.
Who it is for
- Organisations with no dedicated threat monitoring team, that need the signal without the noise.
- ISMSs that must demonstrate the threat intelligence control introduced in the 2022 version of ISO/IEC 27001.
- Boards that need an executive reading of the risk landscape, not a technical dump.
Capabilities
01
Contextualisation
The analysis starts from the client’s technology inventory: operating systems, platforms, exposed services and suppliers. What does not apply is not reported.
02
Prioritisation by criticality
Each finding is weighted by severity, observed exploitability and the real exposure of the asset, so the action list stays short and ordered.
03
Out-of-cycle alerts
When a critical vulnerability or an active campaign affects the client, the communication does not wait for the monthly report.
04
Executive report
A monthly report with a reading of the landscape, sector trends and the status of actions, ready for the management review.
What the rollout includes
- Assessment of the technology inventory and exposed assets.
- Definition of the thresholds that trigger an out-of-cycle alert.
- Periodic report with prioritised findings and recommended actions.
- Monthly executive report fed into the ISMS risk cycle.
Frequently asked questions
How is it different from a vulnerability feed?
A feed publishes everything and leaves the filtering to the client. ThreatLens does the filtering: it cross-references the flow against the organisation’s specific inventory and delivers only what affects it, with an explanation of why it matters and what action follows. In practice the difference is between hundreds of entries a month and a handful of actionable ones.
Does it cover the ISO/IEC 27001:2022 threat intelligence control?
Yes. The 2022 version introduced threat intelligence as a new Annex A control, and requires that the information collected be analysed and used. ThreatLens produces exactly that evidence: collection, contextualised analysis and documented use within the risk cycle.
Does it require installing anything in our infrastructure?
No. The service works from the declared inventory and external sources; it deploys no agents and does not access the client’s internal systems. When you also want to see real exposure from the outside, the right service is SORT ASM.
