Incident Response Maturity & Threat Intel
A SIM3 maturity assessment and STIX threat-intel structuring for a logistics SME
Context
An Incident Response & Cyber Threat Intelligence engagement (CSEC2002D) for “Winderby Logistics Group”, a realistic “digitally sideways” SME running a mixed IT/OT estate with a part-time analyst and an office-hours-only MSSP. The brief: measure how ready they actually are to handle an incident, and turn a live intrusion into shareable intelligence.
The problem
Incident-response capability that grows ad hoc is invisible until it fails. WLG had no formal IR mandate, no service description and almost no repeatable process — but no way to see or prioritise that. The work had to quantify maturity against a recognised baseline and convert a messy intrusion into structured, actionable threat intelligence.
My approach
I scored all 45 SIM3 v2 parameters (Organisation, Human, Tools, Process) on maturity of existence, documentation and enforcement, benchmarked each against the ENISA Basic target, and built a prioritised remediation roadmap. Separately I structured a warehouse-automation intrusion into STIX 2.1 objects and ran it through the NIST SP 800-61 lifecycle.
SIM3 maturity assessment
Each parameter was scored 0 (non-existent) to 4 (optimising) and compared to ENISA Basic, so every result reads as a gap to a recognised standard rather than an abstract number.
- Organisation: no formal IR mandate (O-1), authority “devolves to whoever is available” (O-3), only an informal service description (O-5)
- Process is the weakest domain — 16 of 17 parameters below ENISA Basic
- Tools are the relative bright spot (resilient comms/internet already exist for logistics)
Root cause & prioritised roadmap
The organisation-layer gaps are the systemic cause: without a mandate, authority or service description, investment in people, tools and process leaks away. The roadmap sequences the lowest-cost, highest-impact fixes first — a board-approved IR charter, service/SLA definitions, then core detection and resolution playbooks.
Threat intelligence — STIX 2.1 + NIST 800-61
A warehouse-automation intrusion (rogue scheduled task by a look-alike service account, C2 to Eastern-European infrastructure, USB exfiltration, telematics brute force) was mapped to STIX 2.1 objects and MITRE ATT&CK for Enterprise and ICS, then walked through the NIST SP 800-61 lifecycle — showing that preparation and detection, not heroics during containment, decide the outcome.
Outcome
A defensible, standards-based picture of an SME’s incident-response readiness with a costed roadmap to ENISA Basic, plus a worked example of turning a live intrusion into structured, shareable threat intelligence aligned to NIST SP 800-61.