Definition · v0.2

What is TIR-CMM?

TIR-CMM is the Threat-Informed Response Capability Maturity Model, a free capability maturity model that measures whether an organisation can act on the attacks it detects. TIR-CMM scores response capability against adversary tempo, decision authority and evidence, and it is free to use, including commercially, under a Creative Commons licence.

TIR-CMM assesses eight domains and 58 sub-capabilities, scores a Containment Lattice of eight attack-path stages crossed with eight asset classes, and applies seven integrity constraints that can only lower a score. TIR-CMM produces a maturity band from L0 to L5, a Validated Response Score, a Containment Margin measured against the breakout time of the adversaries that matter to you, and a ranked roadmap of concrete actions.

TIR-CMM is the response module of UTIOM, the Unified Threat-Informed Operations Model, and the companion to TID-CMM, the Threat-Informed Detection Capability Maturity Model. TID-CMM answers the question would we see it? TIR-CMM answers the question could we stop it?

TIR-CMM version 0.2. Free to use. The assessment tool runs entirely in your browser — no data is transmitted, stored remotely, or analysed.

In one sentence

TIR-CMM is a free maturity model that measures whether an organisation can contain a real attack inside the adversary’s breakout window, with someone permitted to authorise the action, and whether it can prove it.

Everything else on this page is that sentence, expanded. TIR-CMM measures capability to act, not documentation about acting, and every score in TIR-CMM is capped by the strength of the evidence behind it.

Why TIR-CMM exists

Organisations have spent a decade getting better at detection, and almost none of them can say what happens in the ninety minutes after the alert fires. Detection maturity is now measurable: TID-CMM produces a validated coverage figure, and the gap it exposes between detection claimed and detection proven is uncomfortable but at least visible. Response has had no equivalent instrument, so the last link in the chain has stayed unmeasured.

A validated detection that fires into an organisation which cannot contain is a very expensive alarm. TIR-CMM exists to measure that second half.

Failure mode one

Playbooks without authority

The procedure exists and it is well written. At 03:00 on a Sunday, the analyst who could execute it is not permitted to isolate a production domain controller, and the person who is permitted is unreachable for forty minutes.

The playbook was never the constraint. Decision latency was.

Failure mode two

Response without attack paths

A generic incident response plan tells an organisation how to run an incident, and nothing about which incidents it is structurally unable to stop, because the plan was never derived from that organisation’s crown jewels or modelled attack paths.

A plan that could belong to any organisation belongs to none.

Failure mode three

Capability without rehearsal

Playbooks are written, automation is built, and neither is ever executed against a clock. Tabletop exercises test the conversation rather than the capability, and the failure surfaces exactly once, under maximum cost.

An unrehearsed playbook is an assumed capability.

Response is a race, not a coverage problem

Detection maturity is a coverage question: is the behaviour observable, and would the alert fire? Response maturity is a race against a clock that belongs to the adversary. Breakout time is the interval between an adversary establishing a foothold and moving laterally to a second host, and it is the clock every response capability is running against.

A model that scores response without reference to adversary tempo is measuring paperwork. This is why TIR-CMM refuses to award its two highest bands on documentation alone: constraint R5 caps the band at L2 where the sum of detect, decide and contain exceeds breakout time, and caps it at L3 where no tempo evidence is supplied at all.

A response capability structurally slower than the adversary is not a level 3 capability, whatever the documentation says.

What makes TIR-CMM different

Four design decisions separate TIR-CMM from the incident response sections of general security maturity models.

Atomic unit

The Containment Lattice

The Containment Lattice is a grid of eight attack-path stages crossed with eight asset classes, and it is the atomic scoring unit of TIR-CMM. Response does not vary meaningfully per ATT&CK technique, because a compromised laptop is isolated the same way whichever technique got in. Response varies by where on the attack path you are and what kind of asset you are acting on.

The full lattice is 64 cells and is deliberately never the working set. A typical scoped lattice is 24 to 38 cells, because a cell counts only where the asset class exists and a modelled attack path traverses that stage on it.

How the Containment Lattice works →

Headline metric

Containment Margin and MTTDecide

Containment Margin is breakout time minus the sum of mean time to detect, mean time to decide and mean time to contain. A negative Containment Margin means the adversary reaches its objective before containment lands, however good the detection coverage looks.

MTTDecide is the mean time from a validated alert to an authorised containment decision, and TIR-CMM measures it separately from MTTR. Every maturity model in circulation folds decision latency into MTTR, where it disappears. Organisations that measure MTTDecide routinely discover it exceeds containment execution time by an order of magnitude — they are not slow at containing, they are slow at being allowed to contain.

The scoring mathematics →

Honesty mechanism

Seven constraints that only ever lower a score

The seven integrity constraints of TIR-CMM are applied mechanically at scoring time, and no constraint can raise a result. Each constraint encodes a claim that experience has shown to be unsafe.

  • R1 rehearsal ceiling — every domain other than validation is capped at the validation score plus one.
  • R2 authority ceiling — automation you are not permitted to fire is a demonstration, not a capability.
  • R3 evidence cap — an assertion caps at 1, a design or policy at 2, an implemented and tested control at 4, and only repeatable validation permits 5.
  • R4 detection dependency — you cannot respond to what you never saw.
  • R5 tempo ceiling — a capability slower than the adversary is not level 3.
  • R6 blind-cell gate — no response option on a crown jewel is not threat-informed.
  • R7 depth and governance ceiling — a result nobody challenged is not assurance.

The finding that lands

The engineered-versus-proven gap

TIR-CMM reports two rates side by side and refuses to average them. The engineered rate is the proportion of lattice cells where a documented, tooled, pre-authorised action exists, which means we believe we can act here. The proven rate is the proportion of cells where that action has been executed against a real incident or a live-fire exercise inside the recency window, which means we have shown we can act here.

The gap between the two is the finding. TIR-CMM is built to make that gap unavoidable rather than to flatter it, and proof expires after twelve months, or sooner if the tooling, the on-call model, the named owner or the architecture changes.

Response maturity is perishable in a way detection maturity is not.

TIR-CMM and the UTIOM family

TIR-CMM is the response module of UTIOM, the Unified Threat-Informed Operations Model, published at utiom.de. TIR-CMM is the companion to TID-CMM, the Threat-Informed Detection Capability Maturity Model, published at tid-cmm.com.

UTIOM organises security operations into three pillars: leadership and governance, engineering and enablement, and operations and analysis. TID-CMM measures the engineering pillar and answers would we see it? TIR-CMM measures the operations pillar and answers could we stop it?

The two models sit on one axis with identical band arithmetic and no overlapping domains.
Question Answered by
Which adversaries matter to us? TID-CMM — consumed by TIR-CMM as an input
What are our crown jewels and attack paths? UTIOM and TID-CMM — consumed by TIR-CMM as an input
Would we observe the behaviour? TID-CMM
Can we decide, contain, evict and restore? TIR-CMM
Are we faster than the adversary? TIR-CMM, through Containment Margin
Did we learn, and did it change detection? TIR-CMM, feeding findings back to TID-CMM

Why the two models complement rather than overlap

TIR-CMM deliberately contains no detection domain at all. TIR-CMM consumes detection maturity as an input constraint — constraint R4 caps response engineering, containment and forensics at the detection score plus one — rather than re-scoring detection itself. That single design decision is what makes the two models complementary rather than overlapping, and it is what keeps a combined detection-and-response assessment under two hours.

TIR-CMM can be used standalone

TIR-CMM can be used standalone, without TID-CMM and without UTIOM. The assessment tool defaults to standalone: eight short questions on detection and threat modelling replace a TID-CMM import, and a standalone assessment can reach band L4. Supplying no detection input at all caps the band at L3, because claiming adaptive response maturity on an unknown detection capability is not credible.

Importing a TID-CMM export pre-fills crown jewels, attack paths, priority actors and the detection score, and lifts the band ceiling to L5. Both models export upward into the UTIOM roadmap.

Who TIR-CMM is for

TIR-CMM is written for the people who are accountable for what happens after the alert fires.

CISOs and security leaders

A CISO can run the twenty-minute Pulse tier and leave with a band, the three things holding the organisation back, and a quick-fix list that costs nothing but decisions. The output is written in the language a board asks questions in.

SOC and incident response leads

A SOC or IR lead can run the Baseline tier in one to two hours and produce an honest internal baseline: 58 sub-capabilities with evidence levels, a scoped Containment Lattice, an authority map and measured response tempo.

Response and automation engineers

A response engineer can use the Containment Lattice to find the exact cells where no response option exists, and the roadmap to see which of the 58 sub-capabilities carries the most leverage per unit of effort.

Consultancies and assessors

Consultancies may run TIR-CMM assessments for clients and charge for the work, with no fee and no permission required. The Assurance tier is designed as a facilitated engagement with an assessment lead, business owners and an independent validator.

Regulated organisations

Organisations facing DORA and NIS2 testing obligations can use TIR-CMM to evidence that response capability is tested rather than documented. The validation domain and the governance domain map directly onto regulatory testing and reporting expectations.

Managed service customers

An organisation buying detection and response from a provider can use TIR-CMM to establish which containment actions the provider is actually authorised to take, and which remain with the customer. Status 3 expires when the provider or the retainer changes.

What TIR-CMM costs and what you may do with it

TIR-CMM is free to use, including commercially. There is nothing to buy, nothing to install, no account to create and no licence fee for any use of the model, including client work.

The TIR-CMM model — the domains, sub-capabilities, Containment Lattice, maturity bands, integrity constraints, scoring mathematics and written specification — is licensed under Creative Commons Attribution-NoDerivatives 4.0 (CC BY-ND 4.0). You may use it, share it, quote it and publish your results, with attribution. You may not publish a modified, rebranded or extended version of the model itself, because a score only means something if it means the same thing everywhere.

The JSON Schemas and the machine-readable model exports are licensed under CC BY 4.0, deliberately more permissive than the model, so that integration is frictionless. The tooling — the assessment tool, the site and the reference server — is source-available with all rights reserved: free to run, self-host and audit, but not to redistribute as your own product.

Summary only. The full terms are on the licence page.
You want to… Permitted?
Assess your own organisationYes
Assess a client and charge for itYes
Publish the results of an assessmentYes, the results are yours
Cite TIR-CMM in a paper, report or talkYes, with attribution
Self-host the tool for internal or air-gapped useYes
Build an integration against the published schemasYes, under CC BY 4.0
Teach TIR-CMM on a training courseYes, with attribution
Publish a modified or extended version of the modelNo
Republish the assessment tool as your own productNo
Translate the model into another languageAsk — usually yes

A reasonable citation is: TIR-CMM v0.2 — Threat-Informed Response Capability Maturity Model, Reza Adineh, https://tir-cmm.com

Read the full licence →

How to start

TIR-CMM runs at three depths, and each tier is a strict superset of the one below. Answers carry forward from one tier to the next, and nothing is ever rescored.

Bring your crown-jewel list, your TID-CMM export if you have one, and whatever timing data your case system holds. If you cannot separate decision latency from containment time, that is not a blocker — it is your first finding.

Everything runs in your browser. No assessment data is transmitted, stored remotely, or analysed.

Still deciding? The frequently asked questions page answers the questions people ask most often about TIR-CMM, and the glossary defines every term the model uses.