This is a div block with a Webflow interaction that will be triggered when the heading is in the view.

Security teams struggle with many challenges. A shortage of signals is not one of them. At some point in the past decade, the threat intelligence domain became a volume game - more feeds, broader coverage, more indicators. A recent survey by Malanta found that most enterprises now operate five to eight feeds, with some managing as many as 53. Yet 100% of respondents identified the same breakdown point: connecting signals to real threats. Meaning - the problem is not volume. It is context. For example, a newly registered domain is a data point. A newly registered domain that shares certificate attributes with infrastructure previously used against financial services firms, and that resolves to an IP range scanning your customer portal - that is a priority data point. The difference between the two is not the data point itself. It is what the data point maps to. We call this contextual risk. It's the difference between knowing a signal exists and knowing what it means for your organization. Without that distinction, teams sort through volume instead of acting on relevance. The signals that deserve immediate action often sit alongside hundreds that do not, and there is no reliable way to tell them apart.
This e-book provides a structured approach to making that distinction operational. It covers the setup window where attackers are most exposed, how to correlate pre-attack signals to what your organization stands to lose, and how to move from prioritization to action before the window closes.
Key findings
- 100% of enterprises surveyed by Malanta identified the same breakdown point: connecting signals to real threats, despite most running five to eight feeds and some managing 53.
- Breakout time between initial access and lateral movement dropped to 29 minutes in 2025, a 65% increase in speed from 2024, per the CrowdStrike 2026 Global Threat Report.
- The Infoblox 2025 DNS Threat Landscape Report identified over 100 million newly observed domains in a single year, with more than 25 percent classified as malicious or suspicious.
- 66% of SOC teams cannot keep pace with incoming alert volumes, according to the SANS 2025 SOC Survey, making ownership and routing essential for pre-attack signals.
- IoPAs fall into four categories: domain registration patterns, certificate issuance activity, infrastructure placement signals, and reconnaissance and identity probing.
- MTTP, Mean Time to Preempt, measures the time from first pre-attack signal to completed preventive action, translating prevention into financial terms boards understand.
What is inside
- Executive Summary
- Signal Overload Is Actually a Context Problem
- The Setup Window: Where Context Matters Most
- What Signals Are Already Telling You
- Correlating Signals to What Attackers Are Targeting
- A Prioritization Framework
- From Prioritization to Action: Closing the Ownership Gap
- Making Contextual Risk Measurable
- From More Data to Better Decisions
Frequently asked questions
What is contextual risk?
Contextual risk is the difference between knowing a signal exists and knowing what it means for your organization. It evaluates a pre-attack signal for what it is aimed at and what the cost would be if it reached its target, so teams act on relevance instead of volume.
What is the setup window?
The setup window is the finite preparation phase where attackers register domains, provision servers, issue certificates, and configure delivery paths before any payload is deployed. It anchors to reconnaissance and TA0042, Resource Development, and its signals surface days or weeks before execution begins.
What is an IoPA?
An IoPA, Indicator of Pre-Attack, is a validated signal that adversary infrastructure is being prepared before use. IoPAs fall into four categories: domain registration patterns, certificate issuance activity, infrastructure placement signals, and reconnaissance and identity probing.
How is an IoPA different from an IOC?
An IOC documents malicious activity that already occurred. An IoPA identifies validated evidence of infrastructure preparation before execution. They describe different phases and support different actions.
How do teams prioritize IoPAs?
Teams correlate each IoPA against three layers: enterprise assets, customer-facing exposure, and brand and revenue risk. A five-stage model - Collect, Correlate, Validate, Enrich, Disrupt - narrows incoming signals into a small, high-confidence set of priorities tied to real targets.
What is MTTP?
MTTP means Mean Time to Preempt. It measures the interval between observing adversary preparation and taking defensive action against it. Unlike MTTD and MTTR, which measure speed after the fact, MTTP measures prevention before execution.
Download the full Contextual Risk. Prioritizing Pre-Attack Signals That Matter (PDF)








