Developer docs
API playgroundTry for free, no card

Search company profiles

Cyber Threat Alliance

Full company profile

uuid000irgm

Namestring
Cyber Threat Alliance
Legal namestring
Cyber Threat Alliance
Company typeenum
Private
Founded yearint
2017
Descriptiontext

The Cyber Threat Alliance (CTA) is a 501(c)(6) non-profit organization founded in 2014 by four major cybersecurity vendors (Palo Alto Networks, Fortinet, McAfee/Intel Security, and Symantec) and incorporated as an independent entity on January 23, 2017. Headquartered in Arlington, Virginia, CTA operates an automated threat intelligence sharing platform that enables its 30-plus member companies — which include cybersecurity vendors, MSSPs, platforms, ISPs, and telcos — to share curated, contextualized cyber threat intelligence at near real-time speed. The platform is built on MITRE's STIX (Structured Threat Information Expression) and ATT&CK (Adversarial Tactics, Techniques & Common Knowledge) frameworks, and requires observables to be submitted with mandatory context (kill chain phase, first-seen/last-seen dates, malware or attack pattern identification). Members have shared over 100 million cyber threat observables since 2017, with more than 1 million observables submitted weekly, and the public member shares repository contains 1,438 individual research entries.

CTA's core technology is the automated sharing platform, supplemented by member research repositories, joint analytic reports, early warning blog posts, recurring webinars, and curated recommended resources. The alliance differentiates itself from ad-hoc sharing groups by enforcing transparency (intelligence remains tagged to its submitter), mandating minimum sharing participation through bylaws, and enriching data with TTP context rather than accepting noisy anonymous submissions. Beyond the platform, CTA produces joint threat assessments (e.g., the Tokyo Olympics Threat Assessment), publishes white papers (e.g., the 2018 Federal Funding Recommendations for Secure Code), and convenes the Threat Intelligence Practitioners' Summit (TIPS) at the annual Virus Bulletin conference.

CTA's business model is a dues-funded, non-profit membership model. Revenue is generated primarily through recurring membership fees paid by member companies, supplemented by grants such as the 2023 Craig Newmark Philanthropies grant. Membership tiers include full members and a newer affiliate member category, with Uppsala Security joining as the first blockchain intelligence affiliate in August 2026. Pricing is not publicly disclosed; prospective members are directed to contact [email protected]. CTA does not sell commercial software products but rather facilitates intelligence exchange among competitors, with the shared intelligence ultimately flowing through members to their end customers. The organization is governed by a board composed of member company representatives and led by President and CEO Michael Daniel, former White House Cybersecurity Coordinator, and Chief Business Officer Jeannette Jarvis.

Short descriptiontext

The Cyber Threat Alliance (CTA) is a 501(c)(6) non-profit operating an automated cyber threat intelligence sharing platform for 30-plus member cybersecurity companies, using STIX and ATT&CK frameworks to enable near real-time, contextualized threat sharing and collective defense.

Operating statusenum
Operating
Ownership categoryenum
Headcount rangeband
11–50
akta.pro rankint
HeadquartersArlington, United States
HQ citystring
Arlington
HQ countrystring
United States
HQ regionstring
North America
Markets served

Serves global market

Offices1 record

Each record includes

City, Country, Type, Description, Source

Keyword5 values
threat intelligence sharing, cybersecurity collaboration, cyber threat platform, security information exchange, collective cyber defense
Industry3 codes
1Threat Intelligence Services
CodeBPAEADACPrimaryYes
2Deception Technology & Threat Hunting
CodeHDADAGAIPrimaryNo
3Cyber Defense & Information Security (National Security)
CodeBPAIAHAEPrimaryNo
NAICS code3 codes
  • Security Systems Services (except Locksmiths)561621
  • Other Computer Related Services541519
  • National Security928110
SIC code2 codes
  • Services-Membership Organizations8600
  • Services-Computer Integrated Systems Design7373
Product category
Threat Intelligence Sharing Platform
GTM motion1 record

Each record includes

Type, Description, Source

Revenue model1 record
1Membership Dues
TypeSubscription Recurring
Description

CTA is a 501(c)(6) non-profit organization. The organization generates revenue primarily through membership dues paid by cybersecurity companies that join the alliance. Members commit to sharing threat intelligence as a condition of membership.

cyberthreatalliance.org
Marketing channels9 records

Each record includes

Title, Type, Stage, Description, Source

Distribution channels1 record

Each record includes

Title, Type, Scope, Target buyer, Description, Source

Cost components4 values
Personnel, Technology or R&D, Operations, Marketing or Sales
Pricing details1 tier
1Membership-based access to CTA's threat intelligence sharing platform and community
ModelSubscriptionBilling cadenceAnnual
Notes

Membership pricing is not publicly disclosed. Interested organizations contact [email protected] for details. Members are required to share a minimal level of threat intelligence as a condition of membership under CTA's bylaws.

cyberthreatalliance.org
GTM typeB2B
B2B
Offering typeSoftware
Software
Core offering1 text field

The Cyber Threat Alliance operates an automated threat intelligence sharing platform that enables cybersecurity companies to share curated and contextualized cyber threat intelligence at near-real-time, machine speed. The platform requires observables to be accompanied by contextual information including kill chain phase, first-seen/last-seen dates, and malware or attack pattern references, using MITRE's STIX and ATT&CK frameworks for standardization. Members also gain access to joint analyses, early warning intelligence, member research shares, and a trusted community of cybersecurity practitioners.

Differentiator
Functional benefit
Problem solved
Quantifiable outcome1 of 4 values shown
  • Over 100 million cyber threat observables shared since founding as independent non-profit in 2017, with 1,348 days to reach the milestone and over 1 million observables submitted weekly.
+3 more records
Product overview1 text field

The Cyber Threat Alliance (CTA) is a 501(c)(6) non-profit organization that operates a threat intelligence sharing ecosystem rather than a traditional product portfolio. Its core offering is an automated platform enabling cybersecurity companies to share curated, contextualized cyber threat intelligence at machine speed. The platform is supplemented by member research sharing (Member Shares), educational webinars, and curated resource recommendations. CTA supports different membership tiers including full member and affiliate member categories, with affiliates like blockchain intelligence providers contributing specialized threat data. The organization does not sell commercial software products but rather facilitates intelligence exchange among competitors in the cybersecurity industry.

Product and service2 records
1CTA Automated Threat Intelligence Sharing Platform
CategoryThreat Intelligence Sharing Platform
Description

An automated platform that enables cybersecurity member companies to share curated and actionable cyber threat intelligence at near-real-time, machine speed. Observables submitted must include required context (kill chain phase, first-seen/last-seen dates, malware name or attack pattern), with all data standardized using MITRE's STIX and ATT&CK frameworks. Members gain enriched, validated intelligence plus joint analyses, early warnings, and a trusted community of practitioners. For cybersecurity organizations seeking to enhance their threat intelligence capabilities.

2Member Shares Research Repository
CategoryThreat Intelligence Research
Description

A repository of threat intelligence research, adversary playbooks, malware analyses, and threat reports contributed by CTA member companies including Palo Alto Networks (Unit 42), Fortinet (FortiGuard Labs), Cisco (Talos), McAfee, Sophos, and Check Point. Contains over 1,400 individual research entries shared with the membership and pre-publication access to member research.

Scale indicator5 records

Each record includes

Type, Value, Description, Source

Partnership17 partners
Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2026-08-06
Description

Uppsala Security, a Singapore-based blockchain intelligence and crypto forensics company, became CTA's first blockchain intelligence company to join as an Affiliate Member. The membership enables Uppsala Security to contribute on-chain threat intelligence—including malicious wallet activity and suspicious transaction patterns—to CTA's existing threat-sharing community. The alliance strengthens cross-border cooperation between cybersecurity companies, blockchain intelligence providers, financial institutions, digital asset businesses, and law enforcement agencies responding to cybercrime involving digital assets.

Strategic tierMinorTypeStrategic or Co-development PartnerAnnounced on2026-07-08
Description

The Paris Peace Forum launched INTAiC (Integrated Network for Trusted AI in Cyberspace) to assess AI-related threats to global internet infrastructure. CTA shares overlapping mission focus on assessing and addressing cyber threats but is not formally named as a partner.

Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2026-06-02
Description

IT-ISAC (Information Technology - Information Sharing and Analysis Center) works extensively with government and collaborates with CTA on industry-wide cybersecurity collaboration. IT-ISAC Executive Director Scott Algeier authored a CTA blog on industry collaboration as a team sport, emphasizing the need for public-private partnerships and intelligence sharing.

4Nonprofit Cyber
Strategic tierMinorTypeStrategic or Co-development PartnerAnnounced on2026-05-01
Description

CTA supports World Password Day and aligns with Nonprofit Cyber's Common Guidance on Passwords, which has been endorsed by more than 130 organizations. CTA publishes content promoting stronger authentication practices consistent with Nonprofit Cyber's evidence-based recommendations.

cyberthreatalliance.org
Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2026-01-19
Description

CTA maintains leadership roles in the WEF Centre for Cybersecurity, Partnership Against Cybercrime, and Cybercrime Atlas initiative. CTA's Chief Security Strategist Derek Manky participated in a WEF Davos panel with Europol and CTA to discuss intelligence sharing and deterrence strategies against global cybercrime. CTA also contributed to WEF's sustainable cybersecurity finance mechanism proposal.

Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2026-01-19
Description

Europol participated in a WEF Annual Meeting panel alongside Fortinet and CTA, discussing intelligence sharing and deterrence strategies against global cybercrime. The collaboration exemplifies CTA's public-private partnership model for coordinated cybercrime disruption.

Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2026-01-19
Description

Fortinet and Crime Stoppers International co-launched the Cybercrime Bounty program, aimed at financially disrupting criminal markets. CTA participates in related WEF panel discussions on cybercrime disruption, intelligence sharing, and deterrence strategies involving this initiative.

Strategic tierMinorTypeStrategic or Co-development PartnerAnnounced on2025-06-15
Description

The CyberPeace Institute is one of seven members of the secretariat coordinating the Common Good Cyber Fund, which aims to support nonprofits protecting the internet with a proposed $50 million yearly budget. CTA is indirectly aligned through shared mission of improving global cybersecurity.

Strategic tierMinorTypeStrategic or Co-development PartnerAnnounced on2025-06-15
Description

Shadowserver Foundation is one of seven secretariat members of the Common Good Cyber Fund, alongside Global Cyber Alliance and CyberPeace Institute. CTA shares a common mission of improving global cybersecurity through collective action.

10Ransomware Task Force (RTF)
Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2021-04-01
Description

CTA actively implements recommendations from the Ransomware Task Force, sponsored by the Institute for Security & Technology. The RTF brought together over 50 expert volunteers from software companies, cybersecurity vendors, government agencies, non-profits, and academic institutions to combat ransomware.

cyberthreatalliance.org
Strategic tierMinorTypeStrategic or Co-development PartnerAnnounced on2020-10-15
Description

CTA works with the Global Cyber Alliance, an international cross-sector organization dedicated to reducing cyber risk. CTA republished GCA's blog content on cybersecurity vigilance ('Get Your Spidey Sense On') and collaborates on resources for working from home and online safety.

Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2020-10-01
Description

CTA sponsors and coordinates the Threat Intelligence Practitioners' Summit (TIPS) track at the annual Virus Bulletin conference. TIPS brings together international experts from government, business, and civil society focused on threat intelligence. CTA's CBO Jeannette Jarvis serves on the Virus Bulletin advisory board.

Strategic tierMinorTypeStrategic or Co-development PartnerAnnounced on2020-01-01
Description

CTA partners with the Cybercrime Support Network, a nonprofit that supports cybercrime victims. CTA published guest blog content from Cybercrime Support Network and collaborates on reducing the effects of cybercrime on individuals and organizations.

Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2014-01-01
Description

Palo Alto Networks co-founded CTA in 2014 alongside Fortinet, McAfee (Intel Security), and Symantec. The company shares threat intelligence through CTA's automated platform and contributes to joint analyses, threat assessments, and early sharing. Palo Alto Networks Unit 42 team is an active contributor to member shares.

Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2014-01-01
Description

Fortinet co-founded CTA in 2014 alongside Palo Alto Networks, McAfee, and Symantec. Fortinet's FortiGuard Labs team contributes threat intelligence, participates in working groups, and engages in public-private partnerships including WEF panels alongside CTA representatives on cybercrime deterrence and intelligence sharing.

Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2014-01-01
Description

McAfee (formerly Intel Security) co-founded CTA in 2014 alongside Palo Alto Networks, Fortinet, and Symantec. McAfee contributes threat intelligence through CTA's platform and participates in collaborative analyses and joint outputs.

Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2014-01-01
Description

Symantec (now part of Broadcom) co-founded CTA in 2014 alongside Palo Alto Networks, Fortinet, and McAfee. As a founding member, Symantec contributes threat research to CTA's automated sharing platform.

Recent move6 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight6 records

Each record includes

Type, Description

Peers10 records
TypeBroad incumbent
Description

MITRE develops and maintains the ATT&CK and STIX frameworks that CTA's platform is built upon, making it the foundational infrastructure provider for CTA's core technology. MITRE also operates CVE and several federally-funded R&D centers, positioning it as a much larger incumbent whose standards CTA standardizes on.

TypeDirect peer
Description

GCA is an international cross-sector nonprofit dedicated to reducing cyber risk through collective action, with a mission and operational model highly parallel to CTA's. CTA is a documented GCA partner (republishing GCA content), confirming the two organizations operate as adjacent peers in the cross-sector cyber collective-defense space.

TypeEmerging player
Description

ThreatConnect is a commercial threat intelligence operations platform that combines threat intel aggregation, sharing, and analytics with STIX/TAXII support. Like Anomali, it competes with CTA's platform in enabling automated threat sharing workflows, though it is a commercial vendor rather than a neutral alliance.

TypeEmerging player
Description

Anomali is a commercial threat intelligence platform that ingests, correlates, and shares threat data with STIX/TAXI support. While CTA member Anomali Threat Research contributes to CTA, Anomali as a vendor offers overlapping threat-sharing and enrichment capabilities that compete for share of member mind and budget.

5OASIS Cyber Threat Intelligence (CTI) Technical Committee
TypeOthers
Description

OASIS CTI TC is the standards body that developed and maintains STIX and TAXII, the exact standards CTA's platform standardizes on. It is an enabling/ecosystem peer rather than a direct competitor, but its roadmap decisions directly shape CTA's technology evolution.

6Health-ISAC (Health Information Sharing and Analysis Center)
TypeDirect peer
Description

Health-ISAC is a sector-specific threat intelligence sharing community for healthcare organizations and vendors, operating under the same member-funded, automated-platform ISAC model. Directly comparable to CTA as a community-led threat sharing organization with similar governance and operational structure.

TypeDirect peer
Description

IT-ISAC is a sector-specific threat information sharing organization for the IT industry, with a comparable member-driven model of cross-competitor intelligence sharing. CTA and IT-ISAC are documented collaborators (IT-ISAC Executive Director Scott Algeier authored a CTA blog), making them the most directly comparable alliance model in the space.

TypeDirect peer
Description

FS-ISAC is the leading sector-specific threat intelligence sharing organization for financial services, operating a member-funded model with automated threat sharing akin to CTA's platform. It is the gold-standard reference for the ISAC sharing model that CTA parallels at a cross-sector level.

TypeEmerging player
Description

MISP is an open-source threat intelligence sharing platform widely used by CSIRTs, ISACs, and private organizations. It competes with CTA in the threat-sharing platform layer but offers a free, open-source alternative that some members may use in parallel to CTA's commercial membership platform.

TypeRegional player
Description

ECS is a European cross-sector cybersecurity public-private partnership that coordinates threat intelligence sharing and policy advocacy at the EU level. It parallels CTA's mission with a regional focus, making it a regional peer addressing the same intelligence-sharing need across a different geography.

Market position
Strengths5 records

Each record includes

Headline, Details, Source

Weaknesses5 records

Each record includes

Headline, Details, Source

Competitive moat4 records

Each record includes

Type, Details

Key risks5 records

Each record includes

Headline, Details, Source

Key highlights7 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Named customers28 records

Each record includes

Name, Industry, Type, Use case, Source, UUID

Segment4 records

Each record includes

Title, Type, Primary, Description, Pain point addressed, Use case, Source

Ideal customer profile3 records

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

Technology focused
Yes
API detail
Has APIbool
No

Docs URL, Description

AI maturity
App detail

Has app

Feature5 records

Each record includes

Title, Differentiator, Description, Source

Core technology
Revenue estimate
Valuation estimate
Number of profiles
Profiles2 records

Each record includes

Name, Designation, Designation category, Overview, Profile commentary, Source

No data
No data
Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds1 record

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors1 record

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Cyber Threat Alliance

Threat Intelligence Sharing Platformcyberthreatalliance.org

The Cyber Threat Alliance (CTA) is a 501(c)(6) non-profit operating an automated cyber threat intelligence sharing platform for 30-plus member cybersecurity companies, using STIX and ATT&CK frameworks to enable near real-time, contextualized threat sharing and collective defense.

What Cyber Threat Alliance does

The Cyber Threat Alliance (CTA) is a 501(c)(6) non-profit organization founded in 2014 by four major cybersecurity vendors (Palo Alto Networks, Fortinet, McAfee/Intel Security, and Symantec) and incorporated as an independent entity on January 23, 2017. Headquartered in Arlington, Virginia, CTA operates an automated threat intelligence sharing platform that enables its 30-plus member companies — which include cybersecurity vendors, MSSPs, platforms, ISPs, and telcos — to share curated, contextualized cyber threat intelligence at near real-time speed. The platform is built on MITRE's STIX (Structured Threat Information Expression) and ATT&CK (Adversarial Tactics, Techniques & Common Knowledge) frameworks, and requires observables to be submitted with mandatory context (kill chain phase, first-seen/last-seen dates, malware or attack pattern identification). Members have shared over 100 million cyber threat observables since 2017, with more than 1 million observables submitted weekly, and the public member shares repository contains 1,438 individual research entries.

CTA's core technology is the automated sharing platform, supplemented by member research repositories, joint analytic reports, early warning blog posts, recurring webinars, and curated recommended resources. The alliance differentiates itself from ad-hoc sharing groups by enforcing transparency (intelligence remains tagged to its submitter), mandating minimum sharing participation through bylaws, and enriching data with TTP context rather than accepting noisy anonymous submissions. Beyond the platform, CTA produces joint threat assessments (e.g., the Tokyo Olympics Threat Assessment), publishes white papers (e.g., the 2018 Federal Funding Recommendations for Secure Code), and convenes the Threat Intelligence Practitioners' Summit (TIPS) at the annual Virus Bulletin conference.

CTA's business model is a dues-funded, non-profit membership model. Revenue is generated primarily through recurring membership fees paid by member companies, supplemented by grants such as the 2023 Craig Newmark Philanthropies grant. Membership tiers include full members and a newer affiliate member category, with Uppsala Security joining as the first blockchain intelligence affiliate in August 2026. Pricing is not publicly disclosed; prospective members are directed to contact [email protected]. CTA does not sell commercial software products but rather facilitates intelligence exchange among competitors, with the shared intelligence ultimately flowing through members to their end customers. The organization is governed by a board composed of member company representatives and led by President and CEO Michael Daniel, former White House Cybersecurity Coordinator, and Chief Business Officer Jeannette Jarvis.

Cyber Threat Alliance firmographics

Firmographics
Name
Cyber Threat Alliance
Legal name
Cyber Threat Alliance
Website
https://cyberthreatalliance.org
Company type
Private
Founded year
2017
Operating status
Operating
Headcount range
11–50 employees
Short description
The Cyber Threat Alliance (CTA) is a 501(c)(6) non-profit operating an automated cyber threat intelligence sharing platform for 30-plus member cybersecurity companies, using STIX and ATT&CK frameworks to enable near real-time, contextualized threat sharing and collective defense.
Ownership category
akta.pro rank

Cyber Threat Alliance industry classification

Industry
Product category
Threat Intelligence Sharing Platform
NAICS
Security Systems Services (except Locksmiths) (561621), Other Computer Related Services (541519), National Security (928110)
SIC
Services-Membership Organizations (8600), Services-Computer Integrated Systems Design (7373)
akta.pro primary industry
Threat Intelligence Services (BPAEADAC)
akta.pro secondary industries
Deception Technology & Threat Hunting (HDADAGAI), Cyber Defense & Information Security (National Security) (BPAIAHAE)

Keywords

  • Threat intelligence sharing
  • Cybersecurity collaboration
  • Cyber threat platform
  • Security information exchange
  • Collective cyber defense

Where Cyber Threat Alliance is headquartered

Location

Headquarters

HQ city
Arlington
HQ country
United States
HQ region
North America

Offices1 record

Markets served

Cyber Threat Alliance business model

Business model
GTM type
B2B
Offering type
Software
Cost components
Personnel, Technology or R&D, Operations, Marketing or Sales

Revenue model

  1. Membership Dues: CTA is a 501(c)(6) non-profit organization. The organization generates revenue primarily through membership dues paid by cybersecurity companies that join the alliance. Members commit to sharing threat intelligence as a condition of membership.

Pricing tiers

ModelBillingPrice
SubscriptionAnnualMembership-based access to CTA's threat intelligence sharing platform and community

Go-to-market motion1 record

Distribution channels1 record

Marketing channels9 records

Cyber Threat Alliance product offering

Product offering

Core offering

The Cyber Threat Alliance operates an automated threat intelligence sharing platform that enables cybersecurity companies to share curated and contextualized cyber threat intelligence at near-real-time, machine speed. The platform requires observables to be accompanied by contextual information including kill chain phase, first-seen/last-seen dates, and malware or attack pattern references, using MITRE's STIX and ATT&CK frameworks for standardization. Members also gain access to joint analyses, early warning intelligence, member research shares, and a trusted community of cybersecurity practitioners.

Product overview

The Cyber Threat Alliance (CTA) is a 501(c)(6) non-profit organization that operates a threat intelligence sharing ecosystem rather than a traditional product portfolio. Its core offering is an automated platform enabling cybersecurity companies to share curated, contextualized cyber threat intelligence at machine speed. The platform is supplemented by member research sharing (Member Shares), educational webinars, and curated resource recommendations. CTA supports different membership tiers including full member and affiliate member categories, with affiliates like blockchain intelligence providers contributing specialized threat data. The organization does not sell commercial software products but rather facilitates intelligence exchange among competitors in the cybersecurity industry.

Differentiator

Problem solved

Functional benefit

Products and services

  • CTA Automated Threat Intelligence Sharing Platform An automated platform that enables cybersecurity member companies to share curated and actionable cyber threat intelligence at near-real-time, machine speed. Observables submitted must include required context (kill chain phase, first-seen/last-seen dates, malware name or attack pattern), with all data standardized using MITRE's STIX and ATT&CK frameworks. Members gain enriched, validated intelligence plus joint analyses, early warnings, and a trusted community of practitioners. For cybersecurity organizations seeking to enhance their threat intelligence capabilities.
  • Member Shares Research Repository A repository of threat intelligence research, adversary playbooks, malware analyses, and threat reports contributed by CTA member companies including Palo Alto Networks (Unit 42), Fortinet (FortiGuard Labs), Cisco (Talos), McAfee, Sophos, and Check Point. Contains over 1,400 individual research entries shared with the membership and pre-publication access to member research.

Quantifiable outcome

  • Over 100 million cyber threat observables shared since founding as independent non-profit in 2017, with 1,348 days to reach the milestone and over 1 million observables submitted weekly.
  • +3 more outcomes

Companies that use Cyber Threat Alliance

Customer profile

Named customers28 records

Segments4 records

Ideal customer profiles3 records

Cyber Threat Alliance technology and API

Technology

Technology focussed Yes

API detail

Has API
No
API docs
API detail

Core technology

AI maturity

App detail

Feature5 records

Cyber Threat Alliance partnerships and signals

Strategic signal

Partnerships

17 partnerships are on record, tiered core and minor.

  • Uppsala SecuritycoreStrategic or Co-development Partner · 6 August 2026Uppsala Security, a Singapore-based blockchain intelligence and crypto forensics company, became CTA's first blockchain intelligence company to join as an Affiliate Member. The membership enables Uppsala Security to contribute on-chain threat intelligence—including malicious wallet activity and suspicious transaction patterns—to CTA's existing threat-sharing community. The alliance strengthens cross-border cooperation between cybersecurity companies, blockchain intelligence providers, financial institutions, digital asset businesses, and law enforcement agencies responding to cybercrime involving digital assets.
  • Paris Peace Forum (INTAiC)minorStrategic or Co-development Partner · 8 July 2026The Paris Peace Forum launched INTAiC (Integrated Network for Trusted AI in Cyberspace) to assess AI-related threats to global internet infrastructure. CTA shares overlapping mission focus on assessing and addressing cyber threats but is not formally named as a partner.
  • IT-ISACcoreStrategic or Co-development Partner · 2 June 2026IT-ISAC (Information Technology - Information Sharing and Analysis Center) works extensively with government and collaborates with CTA on industry-wide cybersecurity collaboration. IT-ISAC Executive Director Scott Algeier authored a CTA blog on industry collaboration as a team sport, emphasizing the need for public-private partnerships and intelligence sharing.
  • Nonprofit CyberminorStrategic or Co-development Partner · 1 May 2026CTA supports World Password Day and aligns with Nonprofit Cyber's Common Guidance on Passwords, which has been endorsed by more than 130 organizations. CTA publishes content promoting stronger authentication practices consistent with Nonprofit Cyber's evidence-based recommendations.
  • World Economic Forum (WEF)coreStrategic or Co-development Partner · 19 January 2026CTA maintains leadership roles in the WEF Centre for Cybersecurity, Partnership Against Cybercrime, and Cybercrime Atlas initiative. CTA's Chief Security Strategist Derek Manky participated in a WEF Davos panel with Europol and CTA to discuss intelligence sharing and deterrence strategies against global cybercrime. CTA also contributed to WEF's sustainable cybersecurity finance mechanism proposal.
  • EuropolcoreStrategic or Co-development Partner · 19 January 2026Europol participated in a WEF Annual Meeting panel alongside Fortinet and CTA, discussing intelligence sharing and deterrence strategies against global cybercrime. The collaboration exemplifies CTA's public-private partnership model for coordinated cybercrime disruption.
  • Crime Stoppers InternationalcoreStrategic or Co-development Partner · 19 January 2026Fortinet and Crime Stoppers International co-launched the Cybercrime Bounty program, aimed at financially disrupting criminal markets. CTA participates in related WEF panel discussions on cybercrime disruption, intelligence sharing, and deterrence strategies involving this initiative.
  • CyberPeace InstituteminorStrategic or Co-development Partner · 15 June 2025The CyberPeace Institute is one of seven members of the secretariat coordinating the Common Good Cyber Fund, which aims to support nonprofits protecting the internet with a proposed $50 million yearly budget. CTA is indirectly aligned through shared mission of improving global cybersecurity.
  • Shadowserver FoundationminorStrategic or Co-development Partner · 15 June 2025Shadowserver Foundation is one of seven secretariat members of the Common Good Cyber Fund, alongside Global Cyber Alliance and CyberPeace Institute. CTA shares a common mission of improving global cybersecurity through collective action.
  • Ransomware Task Force (RTF)coreStrategic or Co-development Partner · 1 April 2021CTA actively implements recommendations from the Ransomware Task Force, sponsored by the Institute for Security & Technology. The RTF brought together over 50 expert volunteers from software companies, cybersecurity vendors, government agencies, non-profits, and academic institutions to combat ransomware.
  • Global Cyber Alliance (GCA)minorStrategic or Co-development Partner · 15 October 2020CTA works with the Global Cyber Alliance, an international cross-sector organization dedicated to reducing cyber risk. CTA republished GCA's blog content on cybersecurity vigilance ('Get Your Spidey Sense On') and collaborates on resources for working from home and online safety.
  • Virus BulletincoreStrategic or Co-development Partner · 1 October 2020CTA sponsors and coordinates the Threat Intelligence Practitioners' Summit (TIPS) track at the annual Virus Bulletin conference. TIPS brings together international experts from government, business, and civil society focused on threat intelligence. CTA's CBO Jeannette Jarvis serves on the Virus Bulletin advisory board.
  • Cybercrime Support NetworkminorStrategic or Co-development Partner · 1 January 2020CTA partners with the Cybercrime Support Network, a nonprofit that supports cybercrime victims. CTA published guest blog content from Cybercrime Support Network and collaborates on reducing the effects of cybercrime on individuals and organizations.
  • Palo Alto NetworkscoreStrategic or Co-development Partner · 1 January 2014Palo Alto Networks co-founded CTA in 2014 alongside Fortinet, McAfee (Intel Security), and Symantec. The company shares threat intelligence through CTA's automated platform and contributes to joint analyses, threat assessments, and early sharing. Palo Alto Networks Unit 42 team is an active contributor to member shares.
  • FortinetcoreStrategic or Co-development Partner · 1 January 2014Fortinet co-founded CTA in 2014 alongside Palo Alto Networks, McAfee, and Symantec. Fortinet's FortiGuard Labs team contributes threat intelligence, participates in working groups, and engages in public-private partnerships including WEF panels alongside CTA representatives on cybercrime deterrence and intelligence sharing.
  • McAfeecoreStrategic or Co-development Partner · 1 January 2014McAfee (formerly Intel Security) co-founded CTA in 2014 alongside Palo Alto Networks, Fortinet, and Symantec. McAfee contributes threat intelligence through CTA's platform and participates in collaborative analyses and joint outputs.
  • Symantec (Broadcom)coreStrategic or Co-development Partner · 1 January 2014Symantec (now part of Broadcom) co-founded CTA in 2014 alongside Palo Alto Networks, Fortinet, and McAfee. As a founding member, Symantec contributes threat research to CTA's automated sharing platform.

Scale indicators5 records

Recent moves6 records

Expansion highlights6 records

Cyber Threat Alliance competitors and assessment

Company assessment

Broad incumbents

  • MITRE Corporation: MITRE develops and maintains the ATT&CK and STIX frameworks that CTA's platform is built upon, making it the foundational infrastructure provider for CTA's core technology. MITRE also operates CVE and several federally-funded R&D centers, positioning it as a much larger incumbent whose standards CTA standardizes on.

Direct peers

  • Global Cyber Alliance (GCA): GCA is an international cross-sector nonprofit dedicated to reducing cyber risk through collective action, with a mission and operational model highly parallel to CTA's. CTA is a documented GCA partner (republishing GCA content), confirming the two organizations operate as adjacent peers in the cross-sector cyber collective-defense space.
  • Health-ISAC (Health Information Sharing and Analysis Center): Health-ISAC is a sector-specific threat intelligence sharing community for healthcare organizations and vendors, operating under the same member-funded, automated-platform ISAC model. Directly comparable to CTA as a community-led threat sharing organization with similar governance and operational structure.
  • IT-ISAC (Information Technology Information Sharing and Analysis Center): IT-ISAC is a sector-specific threat information sharing organization for the IT industry, with a comparable member-driven model of cross-competitor intelligence sharing. CTA and IT-ISAC are documented collaborators (IT-ISAC Executive Director Scott Algeier authored a CTA blog), making them the most directly comparable alliance model in the space.
  • FS-ISAC (Financial Services Information Sharing and Analysis Center): FS-ISAC is the leading sector-specific threat intelligence sharing organization for financial services, operating a member-funded model with automated threat sharing akin to CTA's platform. It is the gold-standard reference for the ISAC sharing model that CTA parallels at a cross-sector level.

Emerging players

  • ThreatConnect: ThreatConnect is a commercial threat intelligence operations platform that combines threat intel aggregation, sharing, and analytics with STIX/TAXII support. Like Anomali, it competes with CTA's platform in enabling automated threat sharing workflows, though it is a commercial vendor rather than a neutral alliance.
  • Anomali: Anomali is a commercial threat intelligence platform that ingests, correlates, and shares threat data with STIX/TAXI support. While CTA member Anomali Threat Research contributes to CTA, Anomali as a vendor offers overlapping threat-sharing and enrichment capabilities that compete for share of member mind and budget.
  • MISP Project (Malware Information Sharing Platform & Threat Sharing): MISP is an open-source threat intelligence sharing platform widely used by CSIRTs, ISACs, and private organizations. It competes with CTA in the threat-sharing platform layer but offers a free, open-source alternative that some members may use in parallel to CTA's commercial membership platform.

Others

  • OASIS Cyber Threat Intelligence (CTI) Technical Committee: OASIS CTI TC is the standards body that developed and maintains STIX and TAXII, the exact standards CTA's platform standardizes on. It is an enabling/ecosystem peer rather than a direct competitor, but its roadmap decisions directly shape CTA's technology evolution.

Regional players

  • ECS (European Cyber Security Organisation): ECS is a European cross-sector cybersecurity public-private partnership that coordinates threat intelligence sharing and policy advocacy at the EU level. It parallels CTA's mission with a regional focus, making it a regional peer addressing the same intelligence-sharing need across a different geography.

Market position

Strengths5 records

Weaknesses5 records

Competitive moat4 records

Key risks5 records

Key highlights7 records

Customer concentration

Cyber Threat Alliance social profiles

Digital presence

Cyber Threat Alliance financial estimates

Financial estimate

Revenue estimate

Valuation estimate

Cyber Threat Alliance leadership team

Management profile

Number of profiles

Profiles2 records

Cyber Threat Alliance funding detail

Funding detail

Funding overview

Funding rounds1 record

Investors1 record

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

Cyber Threat Alliance M&A and investment

M&A and investment

M&A

Investments

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about Cyber Threat Alliance

What does Cyber Threat Alliance do?

The Cyber Threat Alliance operates an automated threat intelligence sharing platform that enables cybersecurity companies to share curated and contextualized cyber threat intelligence at near-real-time, machine speed. The platform requires observables to be accompanied by contextual information including kill chain phase, first-seen/last-seen dates, and malware or attack pattern references, using MITRE's STIX and ATT&CK frameworks for standardization. Members also gain access to joint analyses, early warning intelligence, member research shares, and a trusted community of cybersecurity practitioners.

Is Cyber Threat Alliance a public or private company?

Cyber Threat Alliance is a private company. It is classified as nonprofit foundation owned and is currently operating.

When was Cyber Threat Alliance founded?

Cyber Threat Alliance was founded in 2017. It employs 11 to 50 people.

Where is Cyber Threat Alliance based?

Cyber Threat Alliance is headquartered in Arlington, United States, in the North America region.

How does Cyber Threat Alliance make money?

One revenue line is on record: membership Dues.

Who are Cyber Threat Alliance's main competitors?

MITRE Corporation is listed as a broad incumbent. Direct peers are Global Cyber Alliance (GCA), Health-ISAC (Health Information Sharing and Analysis Center), IT-ISAC (Information Technology Information Sharing and Analysis Center) and FS-ISAC (Financial Services Information Sharing and Analysis Center). Emerging players are ThreatConnect, Anomali and MISP Project (Malware Information Sharing Platform & Threat Sharing). OASIS Cyber Threat Intelligence (CTI) Technical Committee is listed as an others. ECS (European Cyber Security Organisation) is listed as a regional player.

Does Cyber Threat Alliance have an API?

No public API is recorded for Cyber Threat Alliance.

What industry is Cyber Threat Alliance in?

Cyber Threat Alliance's product category is Threat Intelligence Sharing Platform. Its primary akta.pro industry code is BPAEADAC, Threat Intelligence Services, with a secondary code of HDADAGAI, Deception Technology & Threat Hunting. Its NAICS code is 561621 and its SIC code is 8600.

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales
Live signals
GlobeNewswireUppsala Security Becomes First Blockchain Intelligence Company to Join Cyber Threat AllianceUppsala Security announced it has joined the Cyber Threat Alliance (CTA) as an Affiliate Member, becoming the first blockchain intelligence company to join the alliance. The membership enables Uppsala Security to contribute on-chain threat intelligence—including malicious wallet activity and suspicious transaction patterns—to CTA's community of cybersecurity organizations. The alliance is expected to strengthen cross-border cooperation between cybersecurity companies, blockchain intelligence providers, financial institutions, digital asset businesses, and law enforcement agencies responding to cybercrime involving digital assets.GlobeNewswireUppsala Security Becomes First Blockchain Intelligence Company to Join Cyber Threat AllianceUppsala Security, a Singapore-based blockchain intelligence firm, joined the Cyber Threat Alliance as an Affiliate Member, becoming the first blockchain intelligence company to do so. The membership adds on-chain threat intelligence to CTA's community, aiming to improve incident analysis by combining blockchain data with traditional cyber indicators.Cyber Security NewsUppsala Security Becomes First Blockchain Intelligence Company to Join Cyber Threat AllianceUppsala Security, a Singapore-based blockchain intelligence and crypto forensics company, has joined the Cyber Threat Alliance as an Affiliate Member, becoming the first blockchain intelligence company in the alliance. The membership is designed to address cybercrime that spans both traditional digital infrastructure and blockchain networks by contributing on-chain threat intelligence such as malicious wallet activity and suspicious transaction patterns to CTA's existing threat-sharing community. Uppsala Security plans to use the membership to expand international information sharing and collaborate with cybersecurity companies, financial institutions, and law enforcement agencies on cross-border cybercrime cases.TechStartupsUppsala Security Becomes First Blockchain Intelligence Company to Join Cyber Threat AllianceUppsala Security, a Singapore-based blockchain intelligence and crypto forensics company, announced it has joined the Cyber Threat Alliance (CTA) as an Affiliate Member, becoming the first blockchain intelligence company in the alliance. The membership enables Uppsala Security to contribute on-chain threat intelligence—including malicious wallet activity, suspicious transaction patterns, and illicit fund movements—to CTA's existing community of cybersecurity organizations. The company plans to use this membership to expand international information sharing, exchange investigative experience with other members, and support coordinated responses to cross-border cybercrime involving digital assets.FortuneWhy investing in cybersecurity just became a ‘must-have’ for CFOsAs the U.S.–Iran conflict continues, banks and corporations face heightened risk of Iranian or proxy cyberattacks targeting their systems and supporting vendors, prompting cybersecurity experts to urge CFOs to treat vendor cyber resilience as a material balance-sheet risk integrated into annual planning and insurance renewals. The Cyber Threat Alliance advocates for continuous cybersecurity diligence, clear board-level communication about threats and risk transfer strategies, and a “Take Nine” cross-verification protocol to counter social engineering attacks. Experts argue that CFOs must shift from reactive incident response to proactive risk quantification, treating cybersecurity as a core enterprise discipline alongside AI investment.PaloaltonetworksHappy 9th Anniversary, CTA: A Celebration of Collaboration in Cyber DefenseThe Cyber Threat Alliance (CTA) marks its ninth anniversary, celebrating a decade of collaboration among former competitors in the cybersecurity industry that began when four major security vendors — Palo Alto Networks, Fortinet, McAfee (Intel Security), and Symantec — came together in 2014 to share threat intelligence. The organization, which onboarded Michael Daniel, former Cybersecurity Coordinator for President Obama, as its leader, has grown into a global institution that influences industry intelligence sharing, policy engagement, and collective defense against cyber threats. The founder writes that despite adversarial threats continuing to evolve and borders remaining irrelevant to cybercriminals, CTA's track record demonstrates that industry collaboration works and remains essential moving forward.CyberthreatallianceCyber Threat AllianceThe Cyber Threat Alliance (CTA) is a non-profit organization dedicated to improving global cybersecurity by facilitating real-time threat intelligence sharing among its member companies. Its mission focuses on protecting end users, disrupting malicious actors, and elevating overall security through collaborative defensive actions.BrandefenseThreat Intelligence Sharing: Can Competitors Collaborate to Strengthen Cyber Defense?The article explores the strategic benefits and challenges of cyber threat intelligence sharing among organizations, including direct competitors, to enhance collective digital defense. It highlights established frameworks like ISACs and the Cyber Threat Alliance as mechanisms for secure collaboration while maintaining competitive advantage.CenterforcybersecuritypolicyCyberNext Bru: A Quantum Shift in CybersecurityThe Cybersecurity Coalition and Cyber Threat Alliance are hosting the second annual CyberNext BRU conference in Brussels to address the impending threat of cryptographically relevant quantum computers to current encryption standards. The event will discuss the transition to Post-Quantum Cryptography (PQC), highlighting joint efforts by EU member states and standards released by the U.S. National Institute of Standards and Technology (NIST). Experts emphasize the urgent need for early adoption of PQC algorithms to mitigate risks associated with future decryption capabilities and long migration periods.FortinetStrengthening Cyber Resiliency through CollaborationAn opinion piece by Fortinet Strategic Advisory Council member Suzanne Spaulding argues that strengthening cyber resilience requires collaboration among federal, state, local, quasi-governmental and private entities, including information sharing and workforce development. It cites the Cyber Threat Alliance and CISA's Joint Cyber Defense Collaborative, and notes Fortinet's free cybersecurity training for K-12 districts supporting its pledge to train 1 million people by 2026.