Part of: it-sa Expo&Congress 2026 — Intelligence-Driven Cyber Threat Modelling, From CTI to Real-World Defence

Session 02

Frameworks, taxonomies and the governed Cyber Threat Model — Webinar 2 (English)

WebinarEnglish

21 October 2026, 12:30–14:30 CEST

Online

Schedule

21 October 202612:30–14:30 CEST

Online

120 min·Track: Technical

Which concepts, taxonomies, methodologies and frameworks formalise a Cyber Threat Model — and what has to be true before a machine, or an AI agent, can act on the result?

Learning Content
  • Part 1 · Cyber-domain-specific frameworks, taxonomies and concepts (approx. 30 min)
    • 1.1) Detection Maturity Level (DML) model — levels 9 … 1, from goals to atomic indicators
    • 1.2) MITRE ATT&CK as a taxonomy; MITRE CAPEC, CWE and CVE as a classification model; CPE naming
    • 1.3) STRIDE; the Diamond Model of Intrusion Analysis; environmental effects; Intelligence Preparation of the Cyber Environment
    • 1.4) STIX 2.1 — Structured Threat Information Expression: the typed object graph
    • 1.5) CBEST and TIBER-EU — where the requirement comes from: deliverables read as data, every TTIR component as an entity, operational depth 0 – 6, the threat intelligence and modelling process
  • Part 2 · Problem statement and strategic response (approx. 25 min)
    • 2.1) Where large language models stop — the six gaps of generation: no persistent state, no addressable provenance, no per-claim confidence, no schema, no lifecycle, no validation
    • 2.2) AI agents, no-code agent builders and the agentic SOC — definitions and challenges
    • 2.3) SCIPAB — Situation, Complication, Implication along five threads: representation, AI-generated knowledge, operational reuse, ownership and interoperability, deployment and sovereignty
    • 2.4) The Semantic Threat Classification Model; semantics, taxonomies, ontologies — and how they interrelate
    • 2.5) SCIPAB — Position, Action, Benefit: a customer-owned Cyber Threat Model on established standards as the shared knowledge layer between CTI and security operations — trust by design, not by vendor assurance
  • Part 3 · From theory to a governed model — two real models as data (approx. 30 min)
    • 3.1) The adversary (CrowdStrike CSIT-22052, Emotet delivery — used with approval) and the critical function — two STIX 2.1 exports
    • 3.2) Representation — the formal apparatus in the data; two ladders populated: TIBER-EU depth 0 – 6 × DML 9 – 1, where the adversary meets the function
    • 3.3) AI-generated knowledge — one claim, fully governed: id, evidence, confidence, lifecycle, validation status; the validation gate: validate, supersede, reject, verify
    • 3.4) Operational reuse — one graph, four consumers: detection engineering, threat hunting, incident response, threat-led testing
    • 3.5) Ownership and interoperability — what in this export does your stack already read; deployment and sovereignty — where a restricted report may be processed
  • Part 4 · The governed model in the agentic SOC (approx. 20 min)
    • 4.1) Where the governed model sits — the shared knowledge layer of the agentic SOC
    • 4.2) How an agent works on it — the loop: read validated, write draft; the gate closed by a person
    • 4.3) Five agents, one graph — what each reads, does and writes back
    • 4.4) The five complications of the SCIPAB, solved one thread at a time; trust and determinism answered
    • 4.5) Value, measured on the two models — coverage, validation backlog, exposure
    • 4.6) Recap — what you can now do
  • Q&A (approx. 15 min)
  • What participants take home
    • Participants can place any claim on the two ladders and name its vocabulary, read a governed claim with its evidence, confidence and validation status, spot the six gaps of generation and the field that closes each — and describe how AI agents of any platform consume a governed model without owning it.
Target Audience
  • Security Consultants
  • Security Analysts
  • Security Investigators
  • Threat Hunters
  • Incident Responders
  • Detection Engineers
  • SOC Architects and SOC Managers preparing for AI agents

Register

Select sessions *

Webinars (Online)

Workshops (Onsite at it-sa Expo&Congress)

This site is protected by reCAPTCHA. Details on how your data is processed can be found in our Privacy Policy.