Start from a neutral baseline and add what matters to you. Criteria are labeled by source — the platform baseline is architecture-neutral; buyer-contributed criteria are shown separately.
Build your evaluation
no account needed
Match on your requirements
no account needed
This evaluation is stored in your browser only. We cannot see it, and it is not tied to any account. Save it to a link or create an account to keep it across devices — you can export it at any time either way.
1. Weight what matters
38 criteria
baselineWhat intelligence sources feed the platform (open-source, proprietary human-collected, dark web/closed-forum monitoring, technical telemetry from sensors), and what proportion of indicators/reports come from each?
baselineDescribe how raw intelligence is enriched and scored for relevance to a specific customer's industry, geography, and tech stack, and quantify the noise/false-positive reduction versus a raw feed with a customer reference.
baselineHow does the platform deliver finished intelligence — machine-readable feeds (STIX/TAXII), API, or human-written analyst reports — and what is the update/refresh cadence for each?
baselineWhat is the actor and campaign attribution methodology, and how are confidence levels expressed and revised as new evidence emerges?
baselineDetail the integration path into SIEM/SOAR for automated indicator matching and alerting, including how false-positive indicators are suppressed or aged out without manual tuning.
baselineDoes the platform provide dark-web/credential-leak monitoring specific to the customer's domains and executives, and what is the average time-to-detection for a leaked credential compared to public breach disclosure?
baselineExplain the analyst-access model — can customers request bespoke research or ask an analyst questions directly, what are typical response SLAs, and is this included or a paid tier?
baselineHow is vulnerability intelligence (exploited-in-the-wild status, exploit maturity) correlated with the customer's own asset inventory to prioritize patching, versus generic CVSS scoring?
baselineDoes the platform provide sector-specific intelligence (e.g., financial services, healthcare, critical infrastructure) through ISAC/ISAO partnerships or dedicated vertical research teams, versus a single generic feed for all industries?
baselineDescribe brand and executive protection capabilities — detection of typosquat/impersonation domains, fake social media profiles, and leaked executive credentials — and the average takedown time for a confirmed malicious domain, with a customer reference.
baselineHow does the platform specifically track and profile active ransomware groups (leak-site monitoring, negotiation-tactic intelligence, decryptor availability), and how current is that tracking relative to a group's most recent activity?
baselineExplain intelligence-sharing and collaboration features — does the platform support TLP (Traffic Light Protocol) labeling, and can customers share curated intelligence with peers or industry groups directly from the platform?
baselineWhat is the pricing model — per analyst seat, per data volume/API call, or flat enterprise license — and how does cost scale when adding additional intelligence modules (e.g., dark web monitoring) to a base subscription?
baselineHow has the platform's false-positive/noise rate improved over the past 12-24 months, and what mechanism (customer feedback loop, ML retraining) drives that improvement — can this be shown with a concrete before/after metric?
baselineDetail API rate limits and enterprise-scale query volume support — can a large SOC/SIEM integration query the platform continuously at production scale without hitting throttling, and what is the documented rate limit?
baselineDoes the platform provide physical security or geopolitical risk intelligence (e.g., civil unrest, facility-proximity threats) alongside cyber intelligence, or is that entirely out of scope and requiring a separate vendor?
baselineUse the latest threat detection and response technologies including SIEM, EDR/MDR, and threat intelligence platforms with a well-defined process for detecting and responding to security threats and vulnerabilities.
baselineProvide continuous notifications concerning the latest and ongoing cybersecurity threats and vulnerabilities.
baselineProvide real-time threat intelligence, especially for zero-day or emerging threats, with up-to-date protection within its system(s).
baselineDo you enrich log data with contextual elements such as IP reputation, Geo IP, or assets? If so, describe.
baselineHow are you developing detections that exceed commodity threat intelligence?
baselineDo you have a dedicated team for security research? If so, describe the focus of the research and how they will work with the customer's IT team.
baselineAs you continuously research threats and trends, how quickly can you implement those findings into your systems?
baselineDoes your security research team develop threat reports? If so, how often? Please attach any relevant reports as examples.
baselineDemonstrate the ability to deliver anonymized, aggregated threat data to a separate platform for collective analysis and information sharing.
baselineFocus on actionable events for customer notification and real-time monitoring schemes that reduce/prioritize the volume of data requiring quick analysis; apply knowledge of external threats and of the types/numbers of attacks encountered across all monitored customer devices to add value to alert analysis for the agency.
baselineMust integrate with real-time threat intelligence feeds to detect and alert on known Indicators of Compromise (IOCs).
baselineShould provide an up-to-date database of known malicious IPs, domains, and signatures.
baselineIntegrate and monitor all logs through a SIEM; create correlation rules, customize existing rules and use cases for effective security monitoring and incident reporting; use proven threat feeds to proactively identify threats in the environment.
baselineThreat Intelligence Integration: integrate threat intelligence feeds, configure IOC ingestion and automated enrichment, and enable threat correlation.
baselineSolution should provide case management features to store raw and analysed data for a specific alert or set of alerts, provide run books for investigation steps corresponding to different types of attacks, and support integration with open source or commercial IOC sources — list the supported sources and integration approach.
baselineService should support integration of machine-readable threat intelligence from open and commercial sources with weighting/noise-reduction algorithms, support STIX/TAXII for automated integration of actionable intelligence, and analyse the financial institution's susceptibility to strategic threat intelligence shared by the organization, providing IOCs and mitigation steps for each advisory.
baselineFunctional requirements: ability to protect critical infrastructure from ongoing security threats; 24x7 log and security event monitoring across IT infrastructure, WAN, ATM, Internet banking, mobile banking and interfaces (servers, routers, firewalls, IDS); evaluation of cyber security incidents including origin-of-threat identification, chain-of-custody/evidence preservation, and proactive threat intelligence impact assessment.
baselineSolution should detect multiple event types (inappropriate application use, fraud, advanced low-and-slow threats, APTs), collect Layer 7 network flow data from switches/routers/firewalls/DHCP, correlate global threat intelligence feeds against collected logs to identify IOC activity, and analyze user activity patterns for anomaly/behavioral detection across applications, hosts, users and network.
baselineContractor shall provide support for Cyber Hygiene by developing and executing procedures for capturing and tracking through to remediation all vulnerabilities reported by federal sources (e.g. DHS Binding Operational Directive 22-01), generating specific reports at least bi-weekly.
baselineDemonstrate advanced operational security capabilities, including custom tooling and proprietary techniques (not exclusively relying on public frameworks), OPSEC practices to avoid premature detection, threat actor emulation based on MITRE ATT&CK, anti-forensics/artifact minimization techniques, and ability to operate covertly for extended engagements.
baselineIndicate your industry involvement, including membership(s) in industry organizations, participation in standards bodies and participation in the threat intelligence community, and provide a list of your solution partners.
baselineHow do you protect against outside threats?
Signing up adds sharing with your team, sending this as an RFP to vendors, and private document sharing. Nothing above is taken away, and nothing here is sent anywhere until you choose to.
Platform baseline
neutral · staff-reviewed
RFIWhat intelligence sources feed the platform (open-source, proprietary human-collected, dark web/closed-forum monitoring, technical telemetry from sensors), and what proportion of indicators/reports come from each?Answer key — what a strong answer shows
Strong answers give a real breakdown by source type; be skeptical of vendors who can't say roughly how much of their feed is OSINT versus genuinely proprietary collection.
RFPDescribe how raw intelligence is enriched and scored for relevance to a specific customer's industry, geography, and tech stack, and quantify the noise/false-positive reduction versus a raw feed with a customer reference.Answer key — what a strong answer shows
Look for a concrete relevance-scoring methodology and a real noise-reduction figure backed by a named customer, not a generic 'tailored intelligence' claim.
RFIHow does the platform deliver finished intelligence — machine-readable feeds (STIX/TAXII), API, or human-written analyst reports — and what is the update/refresh cadence for each?Answer key — what a strong answer shows
Strong answers state a specific cadence per delivery format; a vendor offering only a generic PDF report with no machine-readable feed is weaker for SOC integration.
RFIWhat is the actor and campaign attribution methodology, and how are confidence levels expressed and revised as new evidence emerges?Answer key — what a strong answer shows
Look for explicit confidence levels (e.g., low/moderate/high with stated criteria) that get revised over time, versus static, unqualified attribution claims.
RFPDetail the integration path into SIEM/SOAR for automated indicator matching and alerting, including how false-positive indicators are suppressed or aged out without manual tuning.Answer key — what a strong answer shows
Strong answers describe automatic indicator aging/expiry and confidence-based filtering, not a firehose that requires constant manual suppression rules.
From other buyers
crowdsourced · anonymized
💬
No buyer-contributed criteria yet
Verified buyers can suggest criteria (anonymized before pooling).
RFIDoes the platform provide dark-web/credential-leak monitoring specific to the customer's domains and executives, and what is the average time-to-detection for a leaked credential compared to public breach disclosure?Answer key — what a strong answer shows
A concrete time-to-detection figure that beats public disclosure timelines is meaningful evidence; vague 'we monitor the dark web' claims are not.
RFPExplain the analyst-access model — can customers request bespoke research or ask an analyst questions directly, what are typical response SLAs, and is this included or a paid tier?Answer key — what a strong answer shows
Strong answers state a concrete SLA and clarify whether analyst access is included or gated behind a premium tier — pricing transparency matters here.
RFIHow is vulnerability intelligence (exploited-in-the-wild status, exploit maturity) correlated with the customer's own asset inventory to prioritize patching, versus generic CVSS scoring?Answer key — what a strong answer shows
Look for genuine asset-correlation (requires an asset inventory integration) rather than a standalone exploited-in-the-wild feed with no link to what the customer actually runs.
RFIDoes the platform provide sector-specific intelligence (e.g., financial services, healthcare, critical infrastructure) through ISAC/ISAO partnerships or dedicated vertical research teams, versus a single generic feed for all industries?Answer key — what a strong answer shows
Look for named ISAC/ISAO partnerships or a dedicated vertical research team; a vendor offering only one undifferentiated feed across all industries provides materially less relevant intelligence.
RFPDescribe brand and executive protection capabilities — detection of typosquat/impersonation domains, fake social media profiles, and leaked executive credentials — and the average takedown time for a confirmed malicious domain, with a customer reference.Answer key — what a strong answer shows
Strong answers include a concrete takedown-time figure and describe the actual takedown mechanism (registrar/host relationships), not just detection with no remediation path.
RFIHow does the platform specifically track and profile active ransomware groups (leak-site monitoring, negotiation-tactic intelligence, decryptor availability), and how current is that tracking relative to a group's most recent activity?Answer key — what a strong answer shows
Look for near-real-time leak-site monitoring and specific group-level profiles, not a static list of 'known ransomware families' updated infrequently.
RFPExplain intelligence-sharing and collaboration features — does the platform support TLP (Traffic Light Protocol) labeling, and can customers share curated intelligence with peers or industry groups directly from the platform?Answer key — what a strong answer shows
Native TLP support and peer-sharing workflows indicate a mature, community-integrated platform; a vendor with no sharing mechanism forces customers into manual, ad-hoc collaboration.
RFIWhat is the pricing model — per analyst seat, per data volume/API call, or flat enterprise license — and how does cost scale when adding additional intelligence modules (e.g., dark web monitoring) to a base subscription?Answer key — what a strong answer shows
Look for transparent incremental-module pricing; vendors who bundle everything into an opaque enterprise quote make budget comparison difficult.
RFIHow has the platform's false-positive/noise rate improved over the past 12-24 months, and what mechanism (customer feedback loop, ML retraining) drives that improvement — can this be shown with a concrete before/after metric?Answer key — what a strong answer shows
A vendor able to show a measured noise-reduction trend with a real mechanism behind it is stronger than one claiming static 'high accuracy' with no historical comparison.
RFPDetail API rate limits and enterprise-scale query volume support — can a large SOC/SIEM integration query the platform continuously at production scale without hitting throttling, and what is the documented rate limit?Answer key — what a strong answer shows
Strong answers state a specific rate limit or confirm unlimited enterprise-tier access; vague 'contact us for enterprise limits' answers should be pressed for real numbers before signing.
RFIDoes the platform provide physical security or geopolitical risk intelligence (e.g., civil unrest, facility-proximity threats) alongside cyber intelligence, or is that entirely out of scope and requiring a separate vendor?Answer key — what a strong answer shows
This is a genuine scope question — not every buyer needs physical/geopolitical intelligence, but a vendor should be clear about the boundary rather than implying broader coverage than they actually have.
RFPUse the latest threat detection and response technologies including SIEM, EDR/MDR, and threat intelligence platforms with a well-defined process for detecting and responding to security threats and vulnerabilities.
RFPProvide continuous notifications concerning the latest and ongoing cybersecurity threats and vulnerabilities.
RFPProvide real-time threat intelligence, especially for zero-day or emerging threats, with up-to-date protection within its system(s).
RFPDo you enrich log data with contextual elements such as IP reputation, Geo IP, or assets? If so, describe.
RFPHow are you developing detections that exceed commodity threat intelligence?
RFPDo you have a dedicated team for security research? If so, describe the focus of the research and how they will work with the customer's IT team.
RFPAs you continuously research threats and trends, how quickly can you implement those findings into your systems?
RFPDoes your security research team develop threat reports? If so, how often? Please attach any relevant reports as examples.
RFPDemonstrate the ability to deliver anonymized, aggregated threat data to a separate platform for collective analysis and information sharing.
RFPFocus on actionable events for customer notification and real-time monitoring schemes that reduce/prioritize the volume of data requiring quick analysis; apply knowledge of external threats and of the types/numbers of attacks encountered across all monitored customer devices to add value to alert analysis for the agency.
RFPMust integrate with real-time threat intelligence feeds to detect and alert on known Indicators of Compromise (IOCs).
RFPShould provide an up-to-date database of known malicious IPs, domains, and signatures.
RFPIntegrate and monitor all logs through a SIEM; create correlation rules, customize existing rules and use cases for effective security monitoring and incident reporting; use proven threat feeds to proactively identify threats in the environment.
RFPThreat Intelligence Integration: integrate threat intelligence feeds, configure IOC ingestion and automated enrichment, and enable threat correlation.
RFPSolution should provide case management features to store raw and analysed data for a specific alert or set of alerts, provide run books for investigation steps corresponding to different types of attacks, and support integration with open source or commercial IOC sources — list the supported sources and integration approach.
RFPService should support integration of machine-readable threat intelligence from open and commercial sources with weighting/noise-reduction algorithms, support STIX/TAXII for automated integration of actionable intelligence, and analyse the financial institution's susceptibility to strategic threat intelligence shared by the organization, providing IOCs and mitigation steps for each advisory.
RFPFunctional requirements: ability to protect critical infrastructure from ongoing security threats; 24x7 log and security event monitoring across IT infrastructure, WAN, ATM, Internet banking, mobile banking and interfaces (servers, routers, firewalls, IDS); evaluation of cyber security incidents including origin-of-threat identification, chain-of-custody/evidence preservation, and proactive threat intelligence impact assessment.
RFPSolution should detect multiple event types (inappropriate application use, fraud, advanced low-and-slow threats, APTs), collect Layer 7 network flow data from switches/routers/firewalls/DHCP, correlate global threat intelligence feeds against collected logs to identify IOC activity, and analyze user activity patterns for anomaly/behavioral detection across applications, hosts, users and network.
RFPContractor shall provide support for Cyber Hygiene by developing and executing procedures for capturing and tracking through to remediation all vulnerabilities reported by federal sources (e.g. DHS Binding Operational Directive 22-01), generating specific reports at least bi-weekly.
RFPDemonstrate advanced operational security capabilities, including custom tooling and proprietary techniques (not exclusively relying on public frameworks), OPSEC practices to avoid premature detection, threat actor emulation based on MITRE ATT&CK, anti-forensics/artifact minimization techniques, and ability to operate covertly for extended engagements.
RFPIndicate your industry involvement, including membership(s) in industry organizations, participation in standards bodies and participation in the threat intelligence community, and provide a list of your solution partners.