CIS Cyber Threat Intelligence Team


U.S.-based cybersecurity experts who provide proactive cyber threat intelligence tailored to U.S. SLTT members of the MS-ISAC.


Cyber Threat Intelligence Purpose Built for U.S. SLTTs

Cyber Threat Intelligence iconThe Center for Internet Security® (CIS®) Cyber Threat Intelligence (CTI) team is a complimentary benefit of membership to the Multi-State Information Sharing and Analysis Center® (MS-ISAC®). It is part of the MS-ISAC's Security Operations & Intelligence (SO&I) division.

The CIS CTI team helps U.S. State, Local, Tribal, and Territorial (SLTT) governments stay ahead of cyber threats with timely, actionable, and relevant intelligence delivered in the formats they need.

From strategic insights to machine-readable indicators, CIS CTI's intelligence reduces uncertainty, speeds decision making, and strengthens U.S. SLTTs' cyber defenses amid constantly evolving threats and limited public sector resources for staying ahead of them.

A Unified Effort: U.S. SLTT Collective Cyber Defense

Unified Effort iconThe CIS CTI team is part of a unified defense ecosystem built specifically for U.S. SLTTs, delivering cyber threat intelligence tailored to their unique environments. As a result, organizations experience greater confidence that risks are considered by experts who understand U.S. SLTT priorities, simplifying a complex threat landscape and guiding proper response efforts.

Here's how the CIS CTI team collaborates with four other SO&I teams who support U.S. SLTT cybersecurity through the MS-ISAC.

CIS Security Operations Center

Around-the-clock monitoring and triage through the 24x7x365 U.S.-based CIS Security Operations Center (SOC) means member reports are passed to the CIS CTI team, which uses them to share indicators of compromise (IOCs). The team also looks at cases from the CIS SOC for activity of interest to write on, and it runs targeted queries across CIS SOC monitoring to determine widespread member impact, reducing dwell time and enabling faster protection of critical services.

CIS Cyber Incident Response Team

Engagements with the CIS Cyber Incident Response Team (CIRT) often lead to CIS CTI threat intelligence products, and the CIS CTI team uses CIS CIRT for technical review. This strengthens the relevance of threat intelligence products to real-world incidents experienced by U.S. SLTTs, removing the guesswork from how they can take meaningful action to defend against complex threats.

CIS Multidimensional Threats Team

The CIS CTI team regularly produces joint products with the CIS Multidimensional Threats (MDT) team, ensuring U.S. SLTT organizations receive timely, relevant insights so they can act decisively on what matters most without needing to interpret complex intelligence, including of multidimensional threats, on their own.

CIS Red Team

The CIS CTI team continuously coordinates with the CIS Red Team (CRT), which incorporates insights from the CTI team into their pentration testing and vulnerability assessment engagements. Through this collaboration, U.S. SLTT organizations receive engagements that reflect real, current threats to their environments, uncovering more gaps than a standard assessment would.


Already an MS-ISAC Member?

Sign into the CIS Portal to learn about the newest threats tracked by the CIS CTI team.

Log in Now

Not yet an MS-ISAC Member?

Join today to experience the difference of Collective Cyber Defense for U.S. SLTTs.

Apply Now