Today, we're proud to announce the launch of BCON Collective, the new name for our dedicated Threat Research and Cyber Threat Intelligence (CTI) practice, bringing together our renowned intelligence-led services, original threat research and expert analysts under a single practice with a unique identity. As cyber criminal groups collaborate, ransomware proliferates, attackers exploit trusted services and social engineering becomes more sophisticated, organisations need timely intelligence to anticipate threats, prioritise risk and stay ahead of rapidly evolving adversaries.
Threat intelligence has become far more than a feed of indicators or a periodic report. As attacks become faster, more targeted and driven by sophisticated criminal groups and nation-state actors, organisations are looking beyond traditional security monitoring and detection. Our extensive CNI portfolio of customers want to understand who is targeting them, how threat actors are carrying out their attacks and, most importantly, where they should focus their efforts before an attack occurs.
BCON Collective formalises a capability that has become an important part of our cyber security offering. Led by Gavin Knapp, Head of Cyber Threat Intelligence, the team delivers strategic, operational and tactical intelligence that underpins more effective decision-making, providing the context needed to proactively detect threats, prioritise vulnerabilities, guide incident response and inform long-term cyber resilience strategies.
“Threat intelligence has become its own discipline within cyber security. Organisations are progressing to see it as not just something that sits alongside security operations, rather they expect it to shape strategic decisions, inform vulnerability management and strengthen incident response. Gavin and the team have built an exceptional reputation for producing intelligence that is both technically rigorous and genuinely actionable. As customer demand for these services continues to grow, it made sense to give this capability its own identity while keeping it firmly rooted within Bridewell's wider cybersecurity expertise."
Our CTI team has established itself as a trusted source of original cyber threat research, providing timely analysis of some of the industry's most significant threats. The team has published in-depth research into ransomware groups including DragonForce, analysed the rapidly evolving tactics of Scattered Spider during its attacks against major UK retailers, investigated emerging phishing techniques such as FileFix and ConsentFix, and tracked nation-state activity linked to North Korea. Our annual Cyber Threat Intelligence Report has become an important resource for organisations seeking to understand how the threat landscape is evolving and what those changes mean for defenders.
"The biggest misconception about threat intelligence is that it's about collecting more information. It isn't. It's about reducing uncertainty. Every security team already has more data than it can realistically process. The challenge is knowing which threats actually matter, which risks deserve immediate attention and where to focus before attackers make the decision for you. Most importantly our threat research, threat intelligence and collaboration with both Bridewell offensive security, threat detection, and response capabilities allows us to provide the key components of a threat informed defense to our CNI client base. BCON Collective reflects the evolution of the work we've already been doing for our clients. It gives our threat research and intelligence capability its own identity and creates a platform through which we can share more of our research, collaborate more closely with customers and continue helping organisations stay one step ahead of an increasingly complex threat landscape."
Through BCON Collective, we will continue to deliver intelligence-led services to organisations across critical national infrastructure, the public sector and commercial organisations. Alongside its advisory services, the practice will expand its programme of original threat research, annual intelligence reports, threat actor profiling and strategic intelligence briefings, helping organisations understand what has happened as well what is likely to happen next.