The response module of UTIOM · v0.2 draft

You would see it.
Could you stop it?

Detection maturity models ask whether you would observe the attack. TIR-CMM asks the question that decides the outcome: could you act on it — inside the adversary's breakout window, with someone permitted to pull the trigger, at the blast radius you intended — and can you prove it?

Start in 20 minutes. Twenty questions gets you a band, the three things holding you back and a quick-fix list. Go deeper when you are ready — every answer carries forward, and nothing is ever rescored.

Free. Open. Runs entirely in your browser — nothing is transmitted, stored remotely, or analysed.

The number nobody measures

Organisations have spent a decade getting better at detection. Almost none can say what happens in the ninety minutes after the alert fires — because the thing that decides the outcome is not the playbook, and not the tooling.

Typical breakout time
62 min
Foothold to first lateral movement. The clock your response is racing.
Time to decide
?
Alert validated → containment authorised. Almost universally buried inside MTTR, where it becomes invisible.
Playbooks written
many
Documented, reviewed, version-controlled.
Playbooks rehearsed
few
An unrehearsed playbook is an assumption wearing a document's clothing.

A validated detection that fires into an organisation which cannot contain is a very expensive alarm.

Three ways response fails

Each one is the structural parallel of a failure mode TID-CMM already exposes in detection.

Playbooks without authority

The procedure exists. It is well written. At 03:00 on a Sunday, the analyst who could execute it is not permitted to isolate a production domain controller, and the person who is permitted is unreachable for forty minutes.

The playbook was never the constraint.

Response without attack paths

A generic, NIST-shaped IR plan. It tells you how to run an incident, and nothing about which incidents you are structurally unable to stop — because it was never derived from your crown jewels or your modelled paths.

Generic planning violates the crown-jewel principle on contact.

Capability without rehearsal

Playbooks are written, automation is built, and neither is ever executed against a clock. Tabletops test the conversation, not the capability.

The failure surfaces exactly once, under maximum cost.

What the model does differently

Atomic unit

The Containment Lattice

Response does not vary per ATT&CK technique — you isolate a compromised laptop the same way whichever technique got in. It varies by where on the attack path you are and what kind of asset you are acting on.

Eight stages by eight asset classes, scoped down by your crown jewels to a working set of 24–38 cells. Each scored 0–3, and status 3 expires. The first stage is Prevent & Harden, and it carries the highest leverage in the model — prevention buys the one thing response cannot manufacture, which is time.

How the lattice works →

Headline metric

Containment Margin

Detection maturity is a coverage problem. Response maturity is a race. A model that scores response without reference to adversary tempo is measuring paperwork.

Breakout time minus detect, decide and contain. Negative margin means you lose, however good the radar looks — and MTTDecide is measured separately, because folding it into MTTR is what makes the most fixable failure in incident response invisible.

The scoring math →

Honesty mechanism

Seven constraints you cannot argue with

Applied mechanically at scoring. They only ever lower a score.

  • R1 — an unrehearsed playbook is an assumed capability
  • R2 — automation you are not permitted to fire is a demo
  • R3 — a score is capped at the strength of its evidence
  • R4 — you cannot respond to what you never saw
  • R5 — slower than the adversary is not level 3
  • R6 — no option on a crown jewel is not threat-informed
  • R7 — a result nobody challenged is not assurance

Position

Runs standalone. Completes TID-CMM if you have it.

You do not need a detection assessment to use this. The tool defaults to standalone: answer eight short questions on detection and threat modelling and you can assess response to L4. Supply nothing at all and the band caps at L3 — a self-assessment is enough to assess response, but claiming adaptive maturity on an unaudited detection figure is not credible.

TIR-CMM still contains no detection domain at all. It consumes detection maturity as an input constraint, which keeps the two models complementary and a combined assessment under two hours.

Import your TID-CMM export and it pre-fills crown jewels, attack paths, actors and the detection score — and the band ceiling lifts to L5. Both export upward into UTIOM's roadmap.

Output

It tells you what to do on Monday

Every one of the 58 sub-capabilities carries a concrete action, an effort tier and the role that must actually do it. The roadmap is ranked mechanically, then bucketed by what it takes: quick fixes (0–30 days, one person, no budget), ninety-day moves (1–3 months), and structural work (6–12 months, budget and procurement).

Twenty of the 58 are quick fixes — and authority and measurement work is almost all of it. The highest-leverage items in the model usually cost nothing but a decision.

Output

Three answers, in plain language

The same 58 sub-capabilities are re-cut against the questions leadership actually asks: respond — could we act in time; recover — could we get the business back, clean; resilience — could we keep running. Each reports what you claim and what you can prove.

Alongside them, a written current-state report and a ranked set of findings, each with a what to do — generated from your own numbers, not from a template.

Where TIR-CMM sits

UTIOM — the Unified Threat-Informed Operations Model — is the foundation. It is a complete lifecycle operating model for security operations, spanning three pillars and seven phases from vision through to continuous improvement, and it covers detection and response directly. If you run UTIOM, you already have the model you need to operate.

The modules do not fill gaps in UTIOM. They add measurement depth. UTIOM defines how security operations should work; a module tells you, with evidence, how well one part of it actually works in your organisation. You can run UTIOM without any of them. You reach for a module when intent is no longer enough and you need proof.

The foundation · all three pillars, all seven phases

UTIOM — the operating model

Leadership & governance · Engineering & enablement · Operations & analysis. Vision, strategy, crown jewels, threat visibility, threat detection, response and continuous improvement — connected as one lifecycle rather than separate functions. It carries its own maturity and capability assessments and the unified improvement roadmap.

utiom.de →

The measurement modules, each deepening one pillar UTIOM already defines

Depth within engineering & enablement

TID-CMM & RSMM

TID-CMM measures detection capability and maturity: telemetry coverage per modelled threat, detection traceability, and validation depth. It answers “would we actually see it?” and produces the uncomfortable gap between detection claimed and detection proven.

RSMM — the Realistic SIEM Maturity Model — covers the operating platform underneath: ingestion, normalisation, correlation and search.

tid-cmm.com →

Depth within operations & analysis

TIR-CMM

Measures whether you can act on what you detect: authority to contain, playbooks that have been executed under a clock, containment options with known blast radius, and whether you move faster than the adversary. It answers “could we actually stop it?”

It contains no detection domain at all — it consumes detection maturity as a constraint, which is what keeps it complementary to TID-CMM rather than overlapping it.

You are here

TIR-CMM can be run standalone, without TID-CMM and without adopting UTIOM. The modules are instruments; the model is the foundation they measure against.

Run it on your own organisation

Four steps and twenty minutes for a Pulse; eleven steps and an afternoon for a Baseline. Bring your TID-CMM export if you have one, your crown jewel list, and whatever timing data your case system holds. If you cannot separate decision latency from containment time, that is not a blocker — it is your first finding.

The model is licensed CC BY-ND 4.0 and the schemas CC BY 4.0. Free to use, including commercially. Not vendor-aligned. Nothing to buy, nothing to install. Licence.

This is a v0.2 draft published for challenge. Seven questions are still open — including whether R1's rehearsal ceiling is too aggressive, and whether the L4 cap on a self-assessed detection figure is calibrated right. An organisation that ran the model and found a constraint wrong is the most valuable feedback there is. See the open questions →