Cyber Threat Alliance
The Cyber Threat Alliance (CTA) is a 501(c)(6) non-profit operating an automated cyber threat intelligence sharing platform for 30-plus member cybersecurity companies, using STIX and ATT&CK frameworks to enable near real-time, contextualized threat sharing and collective defense.
- Company typePrivate
- Founded2017
- HeadquartersArlington, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Cyber Threat Alliance does
The Cyber Threat Alliance (CTA) is a 501(c)(6) non-profit organization founded in 2014 by four major cybersecurity vendors (Palo Alto Networks, Fortinet, McAfee/Intel Security, and Symantec) and incorporated as an independent entity on January 23, 2017. Headquartered in Arlington, Virginia, CTA operates an automated threat intelligence sharing platform that enables its 30-plus member companies — which include cybersecurity vendors, MSSPs, platforms, ISPs, and telcos — to share curated, contextualized cyber threat intelligence at near real-time speed. The platform is built on MITRE's STIX (Structured Threat Information Expression) and ATT&CK (Adversarial Tactics, Techniques & Common Knowledge) frameworks, and requires observables to be submitted with mandatory context (kill chain phase, first-seen/last-seen dates, malware or attack pattern identification). Members have shared over 100 million cyber threat observables since 2017, with more than 1 million observables submitted weekly, and the public member shares repository contains 1,438 individual research entries.
CTA's core technology is the automated sharing platform, supplemented by member research repositories, joint analytic reports, early warning blog posts, recurring webinars, and curated recommended resources. The alliance differentiates itself from ad-hoc sharing groups by enforcing transparency (intelligence remains tagged to its submitter), mandating minimum sharing participation through bylaws, and enriching data with TTP context rather than accepting noisy anonymous submissions. Beyond the platform, CTA produces joint threat assessments (e.g., the Tokyo Olympics Threat Assessment), publishes white papers (e.g., the 2018 Federal Funding Recommendations for Secure Code), and convenes the Threat Intelligence Practitioners' Summit (TIPS) at the annual Virus Bulletin conference.
CTA's business model is a dues-funded, non-profit membership model. Revenue is generated primarily through recurring membership fees paid by member companies, supplemented by grants such as the 2023 Craig Newmark Philanthropies grant. Membership tiers include full members and a newer affiliate member category, with Uppsala Security joining as the first blockchain intelligence affiliate in August 2026. Pricing is not publicly disclosed; prospective members are directed to contact [email protected]. CTA does not sell commercial software products but rather facilitates intelligence exchange among competitors, with the shared intelligence ultimately flowing through members to their end customers. The organization is governed by a board composed of member company representatives and led by President and CEO Michael Daniel, former White House Cybersecurity Coordinator, and Chief Business Officer Jeannette Jarvis.
Cyber Threat Alliance firmographics
Firmographics- Name
- Cyber Threat Alliance
- Legal name
- Cyber Threat Alliance
- Website
- https://cyberthreatalliance.org
- Company type
- Private
- Founded year
- 2017
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- The Cyber Threat Alliance (CTA) is a 501(c)(6) non-profit operating an automated cyber threat intelligence sharing platform for 30-plus member cybersecurity companies, using STIX and ATT&CK frameworks to enable near real-time, contextualized threat sharing and collective defense.
- Ownership category
- akta.pro rank
Cyber Threat Alliance industry classification
Industry- Product category
- Threat Intelligence Sharing Platform
- NAICS
- Security Systems Services (except Locksmiths) (561621), Other Computer Related Services (541519), National Security (928110)
- SIC
- Services-Membership Organizations (8600), Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- Threat Intelligence Services (BPAEADAC)
- akta.pro secondary industries
- Deception Technology & Threat Hunting (HDADAGAI), Cyber Defense & Information Security (National Security) (BPAIAHAE)
Keywords
Where Cyber Threat Alliance is headquartered
LocationHeadquarters
- HQ city
- Arlington
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Cyber Threat Alliance business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales
Revenue model
- Membership Dues: CTA is a 501(c)(6) non-profit organization. The organization generates revenue primarily through membership dues paid by cybersecurity companies that join the alliance. Members commit to sharing threat intelligence as a condition of membership.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Membership-based access to CTA's threat intelligence sharing platform and community |
Go-to-market motion1 record
Distribution channels1 record
Marketing channels9 records
Cyber Threat Alliance product offering
Product offeringCore offering
The Cyber Threat Alliance operates an automated threat intelligence sharing platform that enables cybersecurity companies to share curated and contextualized cyber threat intelligence at near-real-time, machine speed. The platform requires observables to be accompanied by contextual information including kill chain phase, first-seen/last-seen dates, and malware or attack pattern references, using MITRE's STIX and ATT&CK frameworks for standardization. Members also gain access to joint analyses, early warning intelligence, member research shares, and a trusted community of cybersecurity practitioners.
Product overview
The Cyber Threat Alliance (CTA) is a 501(c)(6) non-profit organization that operates a threat intelligence sharing ecosystem rather than a traditional product portfolio. Its core offering is an automated platform enabling cybersecurity companies to share curated, contextualized cyber threat intelligence at machine speed. The platform is supplemented by member research sharing (Member Shares), educational webinars, and curated resource recommendations. CTA supports different membership tiers including full member and affiliate member categories, with affiliates like blockchain intelligence providers contributing specialized threat data. The organization does not sell commercial software products but rather facilitates intelligence exchange among competitors in the cybersecurity industry.
Differentiator
Problem solved
Functional benefit
Products and services
- CTA Automated Threat Intelligence Sharing Platform An automated platform that enables cybersecurity member companies to share curated and actionable cyber threat intelligence at near-real-time, machine speed. Observables submitted must include required context (kill chain phase, first-seen/last-seen dates, malware name or attack pattern), with all data standardized using MITRE's STIX and ATT&CK frameworks. Members gain enriched, validated intelligence plus joint analyses, early warnings, and a trusted community of practitioners. For cybersecurity organizations seeking to enhance their threat intelligence capabilities.
- Member Shares Research Repository A repository of threat intelligence research, adversary playbooks, malware analyses, and threat reports contributed by CTA member companies including Palo Alto Networks (Unit 42), Fortinet (FortiGuard Labs), Cisco (Talos), McAfee, Sophos, and Check Point. Contains over 1,400 individual research entries shared with the membership and pre-publication access to member research.
Quantifiable outcome
- Over 100 million cyber threat observables shared since founding as independent non-profit in 2017, with 1,348 days to reach the milestone and over 1 million observables submitted weekly.
- +3 more outcomes
Companies that use Cyber Threat Alliance
Customer profileNamed customers28 records
Segments4 records
Ideal customer profiles3 records
Cyber Threat Alliance technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature5 records
Cyber Threat Alliance partnerships and signals
Strategic signalPartnerships
17 partnerships are on record, tiered core and minor.
- Uppsala SecuritycoreUppsala Security, a Singapore-based blockchain intelligence and crypto forensics company, became CTA's first blockchain intelligence company to join as an Affiliate Member. The membership enables Uppsala Security to contribute on-chain threat intelligence—including malicious wallet activity and suspicious transaction patterns—to CTA's existing threat-sharing community. The alliance strengthens cross-border cooperation between cybersecurity companies, blockchain intelligence providers, financial institutions, digital asset businesses, and law enforcement agencies responding to cybercrime involving digital assets.
- Paris Peace Forum (INTAiC)minorThe Paris Peace Forum launched INTAiC (Integrated Network for Trusted AI in Cyberspace) to assess AI-related threats to global internet infrastructure. CTA shares overlapping mission focus on assessing and addressing cyber threats but is not formally named as a partner.
- IT-ISACcoreIT-ISAC (Information Technology - Information Sharing and Analysis Center) works extensively with government and collaborates with CTA on industry-wide cybersecurity collaboration. IT-ISAC Executive Director Scott Algeier authored a CTA blog on industry collaboration as a team sport, emphasizing the need for public-private partnerships and intelligence sharing.
- Nonprofit CyberminorCTA supports World Password Day and aligns with Nonprofit Cyber's Common Guidance on Passwords, which has been endorsed by more than 130 organizations. CTA publishes content promoting stronger authentication practices consistent with Nonprofit Cyber's evidence-based recommendations.
- World Economic Forum (WEF)coreCTA maintains leadership roles in the WEF Centre for Cybersecurity, Partnership Against Cybercrime, and Cybercrime Atlas initiative. CTA's Chief Security Strategist Derek Manky participated in a WEF Davos panel with Europol and CTA to discuss intelligence sharing and deterrence strategies against global cybercrime. CTA also contributed to WEF's sustainable cybersecurity finance mechanism proposal.
- EuropolcoreEuropol participated in a WEF Annual Meeting panel alongside Fortinet and CTA, discussing intelligence sharing and deterrence strategies against global cybercrime. The collaboration exemplifies CTA's public-private partnership model for coordinated cybercrime disruption.
- Crime Stoppers InternationalcoreFortinet and Crime Stoppers International co-launched the Cybercrime Bounty program, aimed at financially disrupting criminal markets. CTA participates in related WEF panel discussions on cybercrime disruption, intelligence sharing, and deterrence strategies involving this initiative.
- CyberPeace InstituteminorThe CyberPeace Institute is one of seven members of the secretariat coordinating the Common Good Cyber Fund, which aims to support nonprofits protecting the internet with a proposed $50 million yearly budget. CTA is indirectly aligned through shared mission of improving global cybersecurity.
- Shadowserver FoundationminorShadowserver Foundation is one of seven secretariat members of the Common Good Cyber Fund, alongside Global Cyber Alliance and CyberPeace Institute. CTA shares a common mission of improving global cybersecurity through collective action.
- Ransomware Task Force (RTF)coreCTA actively implements recommendations from the Ransomware Task Force, sponsored by the Institute for Security & Technology. The RTF brought together over 50 expert volunteers from software companies, cybersecurity vendors, government agencies, non-profits, and academic institutions to combat ransomware.
- Global Cyber Alliance (GCA)minorCTA works with the Global Cyber Alliance, an international cross-sector organization dedicated to reducing cyber risk. CTA republished GCA's blog content on cybersecurity vigilance ('Get Your Spidey Sense On') and collaborates on resources for working from home and online safety.
- Virus BulletincoreCTA sponsors and coordinates the Threat Intelligence Practitioners' Summit (TIPS) track at the annual Virus Bulletin conference. TIPS brings together international experts from government, business, and civil society focused on threat intelligence. CTA's CBO Jeannette Jarvis serves on the Virus Bulletin advisory board.
- Cybercrime Support NetworkminorCTA partners with the Cybercrime Support Network, a nonprofit that supports cybercrime victims. CTA published guest blog content from Cybercrime Support Network and collaborates on reducing the effects of cybercrime on individuals and organizations.
- Palo Alto NetworkscorePalo Alto Networks co-founded CTA in 2014 alongside Fortinet, McAfee (Intel Security), and Symantec. The company shares threat intelligence through CTA's automated platform and contributes to joint analyses, threat assessments, and early sharing. Palo Alto Networks Unit 42 team is an active contributor to member shares.
- FortinetcoreFortinet co-founded CTA in 2014 alongside Palo Alto Networks, McAfee, and Symantec. Fortinet's FortiGuard Labs team contributes threat intelligence, participates in working groups, and engages in public-private partnerships including WEF panels alongside CTA representatives on cybercrime deterrence and intelligence sharing.
- McAfeecoreMcAfee (formerly Intel Security) co-founded CTA in 2014 alongside Palo Alto Networks, Fortinet, and Symantec. McAfee contributes threat intelligence through CTA's platform and participates in collaborative analyses and joint outputs.
- Symantec (Broadcom)coreSymantec (now part of Broadcom) co-founded CTA in 2014 alongside Palo Alto Networks, Fortinet, and McAfee. As a founding member, Symantec contributes threat research to CTA's automated sharing platform.
Scale indicators5 records
Recent moves6 records
Expansion highlights6 records
Cyber Threat Alliance competitors and assessment
Company assessmentBroad incumbents
- MITRE Corporation: MITRE develops and maintains the ATT&CK and STIX frameworks that CTA's platform is built upon, making it the foundational infrastructure provider for CTA's core technology. MITRE also operates CVE and several federally-funded R&D centers, positioning it as a much larger incumbent whose standards CTA standardizes on.
Direct peers
- Global Cyber Alliance (GCA): GCA is an international cross-sector nonprofit dedicated to reducing cyber risk through collective action, with a mission and operational model highly parallel to CTA's. CTA is a documented GCA partner (republishing GCA content), confirming the two organizations operate as adjacent peers in the cross-sector cyber collective-defense space.
- Health-ISAC (Health Information Sharing and Analysis Center): Health-ISAC is a sector-specific threat intelligence sharing community for healthcare organizations and vendors, operating under the same member-funded, automated-platform ISAC model. Directly comparable to CTA as a community-led threat sharing organization with similar governance and operational structure.
- IT-ISAC (Information Technology Information Sharing and Analysis Center): IT-ISAC is a sector-specific threat information sharing organization for the IT industry, with a comparable member-driven model of cross-competitor intelligence sharing. CTA and IT-ISAC are documented collaborators (IT-ISAC Executive Director Scott Algeier authored a CTA blog), making them the most directly comparable alliance model in the space.
- FS-ISAC (Financial Services Information Sharing and Analysis Center): FS-ISAC is the leading sector-specific threat intelligence sharing organization for financial services, operating a member-funded model with automated threat sharing akin to CTA's platform. It is the gold-standard reference for the ISAC sharing model that CTA parallels at a cross-sector level.
Emerging players
- ThreatConnect: ThreatConnect is a commercial threat intelligence operations platform that combines threat intel aggregation, sharing, and analytics with STIX/TAXII support. Like Anomali, it competes with CTA's platform in enabling automated threat sharing workflows, though it is a commercial vendor rather than a neutral alliance.
- Anomali: Anomali is a commercial threat intelligence platform that ingests, correlates, and shares threat data with STIX/TAXI support. While CTA member Anomali Threat Research contributes to CTA, Anomali as a vendor offers overlapping threat-sharing and enrichment capabilities that compete for share of member mind and budget.
- MISP Project (Malware Information Sharing Platform & Threat Sharing): MISP is an open-source threat intelligence sharing platform widely used by CSIRTs, ISACs, and private organizations. It competes with CTA in the threat-sharing platform layer but offers a free, open-source alternative that some members may use in parallel to CTA's commercial membership platform.
Others
- OASIS Cyber Threat Intelligence (CTI) Technical Committee: OASIS CTI TC is the standards body that developed and maintains STIX and TAXII, the exact standards CTA's platform standardizes on. It is an enabling/ecosystem peer rather than a direct competitor, but its roadmap decisions directly shape CTA's technology evolution.
Regional players
- ECS (European Cyber Security Organisation): ECS is a European cross-sector cybersecurity public-private partnership that coordinates threat intelligence sharing and policy advocacy at the EU level. It parallels CTA's mission with a regional focus, making it a regional peer addressing the same intelligence-sharing need across a different geography.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks5 records
Key highlights7 records
Customer concentration
Cyber Threat Alliance social profiles
Digital presenceCyber Threat Alliance financial estimates
Financial estimateRevenue estimate
Valuation estimate
Cyber Threat Alliance leadership team
Management profileNumber of profiles
Profiles2 records
Cyber Threat Alliance funding detail
Funding detailFunding overview
Funding rounds1 record
Investors1 record
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Cyber Threat Alliance M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Cyber Threat Alliance
What does Cyber Threat Alliance do?
The Cyber Threat Alliance operates an automated threat intelligence sharing platform that enables cybersecurity companies to share curated and contextualized cyber threat intelligence at near-real-time, machine speed. The platform requires observables to be accompanied by contextual information including kill chain phase, first-seen/last-seen dates, and malware or attack pattern references, using MITRE's STIX and ATT&CK frameworks for standardization. Members also gain access to joint analyses, early warning intelligence, member research shares, and a trusted community of cybersecurity practitioners.
Is Cyber Threat Alliance a public or private company?
Cyber Threat Alliance is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was Cyber Threat Alliance founded?
Cyber Threat Alliance was founded in 2017. It employs 11 to 50 people.
Where is Cyber Threat Alliance based?
Cyber Threat Alliance is headquartered in Arlington, United States, in the North America region.
How does Cyber Threat Alliance make money?
One revenue line is on record: membership Dues.
Who are Cyber Threat Alliance's main competitors?
MITRE Corporation is listed as a broad incumbent. Direct peers are Global Cyber Alliance (GCA), Health-ISAC (Health Information Sharing and Analysis Center), IT-ISAC (Information Technology Information Sharing and Analysis Center) and FS-ISAC (Financial Services Information Sharing and Analysis Center). Emerging players are ThreatConnect, Anomali and MISP Project (Malware Information Sharing Platform & Threat Sharing). OASIS Cyber Threat Intelligence (CTI) Technical Committee is listed as an others. ECS (European Cyber Security Organisation) is listed as a regional player.
Does Cyber Threat Alliance have an API?
No public API is recorded for Cyber Threat Alliance.
What industry is Cyber Threat Alliance in?
Cyber Threat Alliance's product category is Threat Intelligence Sharing Platform. Its primary akta.pro industry code is BPAEADAC, Threat Intelligence Services, with a secondary code of HDADAGAI, Deception Technology & Threat Hunting. Its NAICS code is 561621 and its SIC code is 8600.