The response module of UTIOM · v0.2 draft
You would see it.
Could you stop it?
Detection maturity models ask whether you would observe the attack. TIR-CMM asks the question that decides the outcome: could you act on it — inside the adversary's breakout window, with someone permitted to pull the trigger, at the blast radius you intended — and can you prove it?
Start in 20 minutes. Twenty questions gets you a band, the three things holding you back and a quick-fix list. Go deeper when you are ready — every answer carries forward, and nothing is ever rescored.
Free. Open. Runs entirely in your browser — nothing is transmitted, stored remotely, or analysed.
One model, three depths
The v0.1 model was too heavy to start with. v0.2 splits it into three tiers rather than diluting it into one. Each is a strict superset of the one below, so you can start at the top of this list and stop wherever your evidence runs out.
Pulse · 20 minutes · caps at L3
Where do we stand, roughly?
Twenty questions. No lattice, no ATT&CK, no evidence review. A band, the three things holding you back, and a quick-fix list.
Indicative, not defensible — and it says so on the report.
Baseline · 1–2 hours · caps at L4
What can we prove?
All 58 sub-capabilities with evidence levels, the containment lattice scoped to your crown jewels, the authority map, and response tempo.
Self-service, and defensible enough for a leadership team.
Assurance · 2–4 weeks · no ceiling
Can we stand behind it?
Baseline plus telemetry attributes per asset class, exercised scenarios with observed timings, and the governance layer — decision rights, calibration, second review.
Evidence-led interviews, not self-scoring.
A tier's band ceiling is not a punishment. The depth an assessment reaches is itself evidence about how far its result can be trusted.
The number nobody measures
Organisations have spent a decade getting better at detection. Almost none can say what happens in the ninety minutes after the alert fires — because the thing that decides the outcome is not the playbook, and not the tooling.
A validated detection that fires into an organisation which cannot contain is a very expensive alarm.
Three ways response fails
Each one is the structural parallel of a failure mode TID-CMM already exposes in detection.
Playbooks without authority
The procedure exists. It is well written. At 03:00 on a Sunday, the analyst who could execute it is not permitted to isolate a production domain controller, and the person who is permitted is unreachable for forty minutes.
The playbook was never the constraint.
Response without attack paths
A generic, NIST-shaped IR plan. It tells you how to run an incident, and nothing about which incidents you are structurally unable to stop — because it was never derived from your crown jewels or your modelled paths.
Generic planning violates the crown-jewel principle on contact.
Capability without rehearsal
Playbooks are written, automation is built, and neither is ever executed against a clock. Tabletops test the conversation, not the capability.
The failure surfaces exactly once, under maximum cost.
What the model does differently
Atomic unit
The Containment Lattice
Response does not vary per ATT&CK technique — you isolate a compromised laptop the same way whichever technique got in. It varies by where on the attack path you are and what kind of asset you are acting on.
Eight stages by eight asset classes, scoped down by your crown jewels to a working set of 24–38 cells. Each scored 0–3, and status 3 expires. The first stage is Prevent & Harden, and it carries the highest leverage in the model — prevention buys the one thing response cannot manufacture, which is time.
Headline metric
Containment Margin
Detection maturity is a coverage problem. Response maturity is a race. A model that scores response without reference to adversary tempo is measuring paperwork.
Breakout time minus detect, decide and contain. Negative margin means you lose, however good the radar looks — and MTTDecide is measured separately, because folding it into MTTR is what makes the most fixable failure in incident response invisible.
Honesty mechanism
Seven constraints you cannot argue with
Applied mechanically at scoring. They only ever lower a score.
- R1 — an unrehearsed playbook is an assumed capability
- R2 — automation you are not permitted to fire is a demo
- R3 — a score is capped at the strength of its evidence
- R4 — you cannot respond to what you never saw
- R5 — slower than the adversary is not level 3
- R6 — no option on a crown jewel is not threat-informed
- R7 — a result nobody challenged is not assurance
Position
Runs standalone. Completes TID-CMM if you have it.
You do not need a detection assessment to use this. The tool defaults to standalone: answer eight short questions on detection and threat modelling and you can assess response to L4. Supply nothing at all and the band caps at L3 — a self-assessment is enough to assess response, but claiming adaptive maturity on an unaudited detection figure is not credible.
TIR-CMM still contains no detection domain at all. It consumes detection maturity as an input constraint, which keeps the two models complementary and a combined assessment under two hours.
Import your TID-CMM export and it pre-fills crown jewels, attack paths, actors and the detection score — and the band ceiling lifts to L5. Both export upward into UTIOM's roadmap.
Output
It tells you what to do on Monday
Every one of the 58 sub-capabilities carries a concrete action, an effort tier and the role that must actually do it. The roadmap is ranked mechanically, then bucketed by what it takes: quick fixes (0–30 days, one person, no budget), ninety-day moves (1–3 months), and structural work (6–12 months, budget and procurement).
Twenty of the 58 are quick fixes — and authority and measurement work is almost all of it. The highest-leverage items in the model usually cost nothing but a decision.
Output
Three answers, in plain language
The same 58 sub-capabilities are re-cut against the questions leadership actually asks: respond — could we act in time; recover — could we get the business back, clean; resilience — could we keep running. Each reports what you claim and what you can prove.
Alongside them, a written current-state report and a ranked set of findings, each with a what to do — generated from your own numbers, not from a template.
Where TIR-CMM sits
UTIOM — the Unified Threat-Informed Operations Model — is the foundation. It is a complete lifecycle operating model for security operations, spanning three pillars and seven phases from vision through to continuous improvement, and it covers detection and response directly. If you run UTIOM, you already have the model you need to operate.
The modules do not fill gaps in UTIOM. They add measurement depth. UTIOM defines how security operations should work; a module tells you, with evidence, how well one part of it actually works in your organisation. You can run UTIOM without any of them. You reach for a module when intent is no longer enough and you need proof.
The foundation · all three pillars, all seven phases
UTIOM — the operating model
Leadership & governance · Engineering & enablement · Operations & analysis. Vision, strategy, crown jewels, threat visibility, threat detection, response and continuous improvement — connected as one lifecycle rather than separate functions. It carries its own maturity and capability assessments and the unified improvement roadmap.
The measurement modules, each deepening one pillar UTIOM already defines
Depth within engineering & enablement
TID-CMM & RSMM
TID-CMM measures detection capability and maturity: telemetry coverage per modelled threat, detection traceability, and validation depth. It answers “would we actually see it?” and produces the uncomfortable gap between detection claimed and detection proven.
RSMM — the Realistic SIEM Maturity Model — covers the operating platform underneath: ingestion, normalisation, correlation and search.
Depth within operations & analysis
TIR-CMM
Measures whether you can act on what you detect: authority to contain, playbooks that have been executed under a clock, containment options with known blast radius, and whether you move faster than the adversary. It answers “could we actually stop it?”
It contains no detection domain at all — it consumes detection maturity as a constraint, which is what keeps it complementary to TID-CMM rather than overlapping it.
You are here
TIR-CMM can be run standalone, without TID-CMM and without adopting UTIOM. The modules are instruments; the model is the foundation they measure against.
Run it on your own organisation
Four steps and twenty minutes for a Pulse; eleven steps and an afternoon for a Baseline. Bring your TID-CMM export if you have one, your crown jewel list, and whatever timing data your case system holds. If you cannot separate decision latency from containment time, that is not a blocker — it is your first finding.
The model is licensed CC BY-ND 4.0 and the schemas CC BY 4.0. Free to use, including commercially. Not vendor-aligned. Nothing to buy, nothing to install. Licence.
This is a v0.2 draft published for challenge. Seven questions are still open — including whether R1's rehearsal ceiling is too aggressive, and whether the L4 cap on a self-assessed detection figure is calibrated right. An organisation that ran the model and found a constraint wrong is the most valuable feedback there is. See the open questions →