Tidal Cyber Separates ATT&CK Intelligence to Focus on Execution
Event summary
- Tidal Cyber separated MITRE ATT&CK intelligence from its proprietary threat intelligence (CTI) on May 13, 2026.
- The update aligns with MITRE ATT&CK Version 19, which restructures adversary behavior categorization.
- New architecture distinguishes MITRE ATT&CK as a technique structure and Tidal Cyber CTI as procedure-level intelligence.
- Platform now connects threat intelligence, procedures, vulnerabilities, assets, and defenses into a unified model.
The big picture
Tidal Cyber's update reflects the growing complexity of cyber threats and the need for more actionable intelligence. As MITRE ATT&CK evolves, security teams face challenges in translating technique-level mapping into practical defenses. This shift towards procedure-level intelligence aligns with broader industry trends towards operationalizing threat intelligence for more effective cybersecurity outcomes.
What we're watching
- Adoption Pace
- How quickly organizations will integrate procedure-level intelligence into their defensive strategies.
- Competitive Response
- Whether competitors will follow Tidal Cyber's approach to separating ATT&CK intelligence from proprietary CTI.
- Operational Impact
- The effectiveness of Tidal Cyber's new architecture in reducing attacker success and residual risk.
Related topics
