Definition · v0.2
What is TIR-CMM?
TIR-CMM is the Threat-Informed Response Capability Maturity Model, a free capability maturity model that measures whether an organisation can act on the attacks it detects. TIR-CMM scores response capability against adversary tempo, decision authority and evidence, and it is free to use, including commercially, under a Creative Commons licence.
TIR-CMM assesses eight domains and 58 sub-capabilities, scores a Containment Lattice of eight attack-path stages crossed with eight asset classes, and applies seven integrity constraints that can only lower a score. TIR-CMM produces a maturity band from L0 to L5, a Validated Response Score, a Containment Margin measured against the breakout time of the adversaries that matter to you, and a ranked roadmap of concrete actions.
TIR-CMM is the response module of UTIOM, the Unified Threat-Informed Operations Model, and the companion to TID-CMM, the Threat-Informed Detection Capability Maturity Model. TID-CMM answers the question would we see it? TIR-CMM answers the question could we stop it?
TIR-CMM version 0.2. Free to use. The assessment tool runs entirely in your browser — no data is transmitted, stored remotely, or analysed.
In one sentence
TIR-CMM is a free maturity model that measures whether an organisation can contain a real attack inside the adversary’s breakout window, with someone permitted to authorise the action, and whether it can prove it.
Everything else on this page is that sentence, expanded. TIR-CMM measures capability to act, not documentation about acting, and every score in TIR-CMM is capped by the strength of the evidence behind it.
Why TIR-CMM exists
Organisations have spent a decade getting better at detection, and almost none of them can say what happens in the ninety minutes after the alert fires. Detection maturity is now measurable: TID-CMM produces a validated coverage figure, and the gap it exposes between detection claimed and detection proven is uncomfortable but at least visible. Response has had no equivalent instrument, so the last link in the chain has stayed unmeasured.
A validated detection that fires into an organisation which cannot contain is a very expensive alarm. TIR-CMM exists to measure that second half.
Failure mode one
Playbooks without authority
The procedure exists and it is well written. At 03:00 on a Sunday, the analyst who could execute it is not permitted to isolate a production domain controller, and the person who is permitted is unreachable for forty minutes.
The playbook was never the constraint. Decision latency was.
Failure mode two
Response without attack paths
A generic incident response plan tells an organisation how to run an incident, and nothing about which incidents it is structurally unable to stop, because the plan was never derived from that organisation’s crown jewels or modelled attack paths.
A plan that could belong to any organisation belongs to none.
Failure mode three
Capability without rehearsal
Playbooks are written, automation is built, and neither is ever executed against a clock. Tabletop exercises test the conversation rather than the capability, and the failure surfaces exactly once, under maximum cost.
An unrehearsed playbook is an assumed capability.
Response is a race, not a coverage problem
Detection maturity is a coverage question: is the behaviour observable, and would the alert fire? Response maturity is a race against a clock that belongs to the adversary. Breakout time is the interval between an adversary establishing a foothold and moving laterally to a second host, and it is the clock every response capability is running against.
A model that scores response without reference to adversary tempo is measuring paperwork. This is why TIR-CMM refuses to award its two highest bands on documentation alone: constraint R5 caps the band at L2 where the sum of detect, decide and contain exceeds breakout time, and caps it at L3 where no tempo evidence is supplied at all.
A response capability structurally slower than the adversary is not a level 3 capability, whatever the documentation says.
What makes TIR-CMM different
Four design decisions separate TIR-CMM from the incident response sections of general security maturity models.
Atomic unit
The Containment Lattice
The Containment Lattice is a grid of eight attack-path stages crossed with eight asset classes, and it is the atomic scoring unit of TIR-CMM. Response does not vary meaningfully per ATT&CK technique, because a compromised laptop is isolated the same way whichever technique got in. Response varies by where on the attack path you are and what kind of asset you are acting on.
The full lattice is 64 cells and is deliberately never the working set. A typical scoped lattice is 24 to 38 cells, because a cell counts only where the asset class exists and a modelled attack path traverses that stage on it.
Headline metric
Containment Margin and MTTDecide
Containment Margin is breakout time minus the sum of mean time to detect, mean time to decide and mean time to contain. A negative Containment Margin means the adversary reaches its objective before containment lands, however good the detection coverage looks.
MTTDecide is the mean time from a validated alert to an authorised containment decision, and TIR-CMM measures it separately from MTTR. Every maturity model in circulation folds decision latency into MTTR, where it disappears. Organisations that measure MTTDecide routinely discover it exceeds containment execution time by an order of magnitude — they are not slow at containing, they are slow at being allowed to contain.
Honesty mechanism
Seven constraints that only ever lower a score
The seven integrity constraints of TIR-CMM are applied mechanically at scoring time, and no constraint can raise a result. Each constraint encodes a claim that experience has shown to be unsafe.
- R1 rehearsal ceiling — every domain other than validation is capped at the validation score plus one.
- R2 authority ceiling — automation you are not permitted to fire is a demonstration, not a capability.
- R3 evidence cap — an assertion caps at 1, a design or policy at 2, an implemented and tested control at 4, and only repeatable validation permits 5.
- R4 detection dependency — you cannot respond to what you never saw.
- R5 tempo ceiling — a capability slower than the adversary is not level 3.
- R6 blind-cell gate — no response option on a crown jewel is not threat-informed.
- R7 depth and governance ceiling — a result nobody challenged is not assurance.
The finding that lands
The engineered-versus-proven gap
TIR-CMM reports two rates side by side and refuses to average them. The engineered rate is the proportion of lattice cells where a documented, tooled, pre-authorised action exists, which means we believe we can act here. The proven rate is the proportion of cells where that action has been executed against a real incident or a live-fire exercise inside the recency window, which means we have shown we can act here.
The gap between the two is the finding. TIR-CMM is built to make that gap unavoidable rather than to flatter it, and proof expires after twelve months, or sooner if the tooling, the on-call model, the named owner or the architecture changes.
Response maturity is perishable in a way detection maturity is not.
TIR-CMM and the UTIOM family
TIR-CMM is the response module of UTIOM, the Unified Threat-Informed Operations Model, published at utiom.de. TIR-CMM is the companion to TID-CMM, the Threat-Informed Detection Capability Maturity Model, published at tid-cmm.com.
UTIOM organises security operations into three pillars: leadership and governance, engineering and enablement, and operations and analysis. TID-CMM measures the engineering pillar and answers would we see it? TIR-CMM measures the operations pillar and answers could we stop it?
Leadership & governance
UTIOM
UTIOM is the Unified Threat-Informed Operations Model, the parent operating model that supplies vision, strategy, crown jewels and the unified improvement roadmap. TIR-CMM and TID-CMM are its two capability maturity modules.
utiom.de →
Engineering & enablement
TID-CMM
TID-CMM is the Threat-Informed Detection Capability Maturity Model. TID-CMM measures threat visibility and detection engineering, and produces a Validated Coverage Score — the gap between detection claimed and detection proven.
tid-cmm.com →
Operations & analysis
TIR-CMM
TIR-CMM is the Threat-Informed Response Capability Maturity Model. TIR-CMM measures decision authority, containment, eradication, recovery and validation, and produces a Validated Response Score and a Containment Margin.
You are here
| Question | Answered by |
|---|---|
| Which adversaries matter to us? | TID-CMM — consumed by TIR-CMM as an input |
| What are our crown jewels and attack paths? | UTIOM and TID-CMM — consumed by TIR-CMM as an input |
| Would we observe the behaviour? | TID-CMM |
| Can we decide, contain, evict and restore? | TIR-CMM |
| Are we faster than the adversary? | TIR-CMM, through Containment Margin |
| Did we learn, and did it change detection? | TIR-CMM, feeding findings back to TID-CMM |
Why the two models complement rather than overlap
TIR-CMM deliberately contains no detection domain at all. TIR-CMM consumes detection maturity as an input constraint — constraint R4 caps response engineering, containment and forensics at the detection score plus one — rather than re-scoring detection itself. That single design decision is what makes the two models complementary rather than overlapping, and it is what keeps a combined detection-and-response assessment under two hours.
TIR-CMM can be used standalone
TIR-CMM can be used standalone, without TID-CMM and without UTIOM. The assessment tool defaults to standalone: eight short questions on detection and threat modelling replace a TID-CMM import, and a standalone assessment can reach band L4. Supplying no detection input at all caps the band at L3, because claiming adaptive response maturity on an unknown detection capability is not credible.
Importing a TID-CMM export pre-fills crown jewels, attack paths, priority actors and the detection score, and lifts the band ceiling to L5. Both models export upward into the UTIOM roadmap.
Who TIR-CMM is for
TIR-CMM is written for the people who are accountable for what happens after the alert fires.
CISOs and security leaders
A CISO can run the twenty-minute Pulse tier and leave with a band, the three things holding the organisation back, and a quick-fix list that costs nothing but decisions. The output is written in the language a board asks questions in.
SOC and incident response leads
A SOC or IR lead can run the Baseline tier in one to two hours and produce an honest internal baseline: 58 sub-capabilities with evidence levels, a scoped Containment Lattice, an authority map and measured response tempo.
Response and automation engineers
A response engineer can use the Containment Lattice to find the exact cells where no response option exists, and the roadmap to see which of the 58 sub-capabilities carries the most leverage per unit of effort.
Consultancies and assessors
Consultancies may run TIR-CMM assessments for clients and charge for the work, with no fee and no permission required. The Assurance tier is designed as a facilitated engagement with an assessment lead, business owners and an independent validator.
Regulated organisations
Organisations facing DORA and NIS2 testing obligations can use TIR-CMM to evidence that response capability is tested rather than documented. The validation domain and the governance domain map directly onto regulatory testing and reporting expectations.
Managed service customers
An organisation buying detection and response from a provider can use TIR-CMM to establish which containment actions the provider is actually authorised to take, and which remain with the customer. Status 3 expires when the provider or the retainer changes.
What TIR-CMM costs and what you may do with it
TIR-CMM is free to use, including commercially. There is nothing to buy, nothing to install, no account to create and no licence fee for any use of the model, including client work.
The TIR-CMM model — the domains, sub-capabilities, Containment Lattice, maturity bands, integrity constraints, scoring mathematics and written specification — is licensed under Creative Commons Attribution-NoDerivatives 4.0 (CC BY-ND 4.0). You may use it, share it, quote it and publish your results, with attribution. You may not publish a modified, rebranded or extended version of the model itself, because a score only means something if it means the same thing everywhere.
The JSON Schemas and the machine-readable model exports are licensed under CC BY 4.0, deliberately more permissive than the model, so that integration is frictionless. The tooling — the assessment tool, the site and the reference server — is source-available with all rights reserved: free to run, self-host and audit, but not to redistribute as your own product.
| You want to… | Permitted? |
|---|---|
| Assess your own organisation | Yes |
| Assess a client and charge for it | Yes |
| Publish the results of an assessment | Yes, the results are yours |
| Cite TIR-CMM in a paper, report or talk | Yes, with attribution |
| Self-host the tool for internal or air-gapped use | Yes |
| Build an integration against the published schemas | Yes, under CC BY 4.0 |
| Teach TIR-CMM on a training course | Yes, with attribution |
| Publish a modified or extended version of the model | No |
| Republish the assessment tool as your own product | No |
| Translate the model into another language | Ask — usually yes |
A reasonable citation is: TIR-CMM v0.2 — Threat-Informed Response Capability Maturity Model, Reza Adineh, https://tir-cmm.com
How to start
TIR-CMM runs at three depths, and each tier is a strict superset of the one below. Answers carry forward from one tier to the next, and nothing is ever rescored.
Pulse · 20 minutes · caps at L3
Where do we stand, roughly?
The Pulse tier is twenty questions with no lattice, no ATT&CK and no evidence review. Pulse produces a band, the three things holding you back, and a quick-fix list.
Indicative, not defensible — and the report says so.
Baseline · 1–2 hours · caps at L4
What can we prove?
The Baseline tier covers all 58 sub-capabilities with evidence levels, the Containment Lattice scoped to your crown jewels, the authority map and response tempo.
Self-service, and defensible enough for a leadership team.
Assurance · 2–4 weeks · no ceiling
Can we stand behind it?
The Assurance tier adds telemetry attributes per asset class, exercised scenarios with observed timings, the evidence register and the governance layer.
Evidence-led interviews, not self-scoring.
Bring your crown-jewel list, your TID-CMM export if you have one, and whatever timing data your case system holds. If you cannot separate decision latency from containment time, that is not a blocker — it is your first finding.
Everything runs in your browser. No assessment data is transmitted, stored remotely, or analysed.
Still deciding? The frequently asked questions page answers the questions people ask most often about TIR-CMM, and the glossary defines every term the model uses.