Skip to main content

Understand threats. Know what to do.

Serify connects current threat intelligence to your infrastructure and questions. Your team gets reasoned recommendations, investigates relationships and creates its own analyses and reports.

Cyber threat intelligence for IT operations, SOC, CTI and CSIRT teams · Demonstrator in development

Example

Does CISA ICSA-25-023-02 on RTU500 (CVE-2024-2617) affect us?

Affected sites
North (13.5.2) and South (13.4.3), both high criticality. West: inventory unclear.
Source and evidence
CISA ICSA-25-023-02: 13.4.1–13.4.4 and 13.5.1–13.5.3 affected if secure update is not enabled on all CMUs.
Next step
Verify secure update at North and South, assess updates to 13.5.4 or 13.7.7, collect West’s inventory.

Research and support

TU DarmstadtPEASECHIGHESTMILShub31Futury

Why now

The work is growing faster than the teams.

Analysts absorb more sources, more alerts, and now the output of AI systems they still have to check. European regulation adds fixed clocks on top.

81%
say their security workload grew over the past year.
44%
of team time still goes on manual, repetitive work.
76%
report emotional exhaustion, reduced motivation or mental fatigue.

From a survey of more than 1,800 security leaders and practitioners. 99% of them already run AI somewhere in the stack, and the manual share did not fall. Tines Voice of Security 2026

And the clocks are already running

  • NIS2In force since October 2024

    An early warning within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours. The Commission estimates over 160,000 entities now fall in scope.

    NIS2 Article 23
  • DORAIn force since January 2025

    More than 22,000 financial entities. Initial notification within four hours of classifying an incident as major, and no later than 24 hours after detection.

    DORA Article 19
  • CRAIn force since 11 September 2026

    Manufacturers must report actively exploited vulnerabilities to ENISA and their national CSIRT within 24 hours of becoming aware, with a technical notification at 72 hours.

    CRA reporting obligations

What you can do with it

From a report to a reasoned next decision.

Serify is being developed for IT operations, SOC, CTI and CSIRT teams that want to turn threat information into practical actions and their own analyses.

  1. See what affects you

    Automatically compare supplied SBOM and infrastructure data with new reporting.

  2. Understand relationships

    Trace evidenced links between vulnerabilities, indicators, actors and campaigns.

  3. Put findings to work

    Review, investigate and report results shaped for each role and question.

Interactive examples

One question. The context your team needs.

Choose a perspective and explore the response, from practical actions to campaign analysis.

Serify

You

Follow-up on CISA ICSA-25-023-02 (CVE-2024-2617): which of our RTU500 sites need further investigation, and what is missing for a decision?

Advisory, version ranges and SBOM inventory of four sites matched· Reconstructed · real advisory, fictional sites

Serify

North and South are in the affected range. West is a data gap.

The CMU firmware at North (13.5.2) and South (13.4.3) falls within the affected version ranges; both sites are recorded as high criticality. The vulnerability is only exploitable if secure update is not enabled on all CMUs. No evidence of that configuration has been supplied yet.

  • Nord · high · 2× 13.5.2Verify secure update on both CMUs; assess an update to 13.5.4 or later.
  • South · high · 2× 13.4.3Verify secure update on both CMUs; assess an update to 13.7.7 or later.
  • West · high · unclearThe export from 20 Aug lists one CMU on 13.5.4 but is neither confirmed as current nor complete. Collect a current inventory.
  • OT lab · low · 13.5.4Outside the range. Usable as a reference device for a compatibility test.
View source, remediations and limits

CISA ICSA-25-023-02, Update B of 3 Mar 2026 · CVE-2024-2617 · CVSS 7.2. Authenticated, authorised users can bypass secure update and install unsigned firmware if secure update is not enabled on all CMUs of an RTU500. Affected: CMU firmware 13.2.1–13.2.7, 13.4.1–13.4.4 and 13.5.1–13.5.3.

Vendor remediation: 13.4.x to 13.7.7 or later, 13.5.x to 13.5.4 or later; in both cases enable secure update on all CMUs.

Limits: the version match does not establish exploitability. An update target is not an operational approval; compatibility testing and a maintenance window are pending. 13.5.4 is not a general all-clear; other advisories need separate review.

Data as of: SBOM inventory from 15 Sep 2026, West from 20 Aug 2026. Sites, criticality and operator details are fictional; the advisory is real.

Knowledge base in development

Each analysis builds on existing knowledge.

Example with real reports: new sources add to existing evidence instead of replacing it. Continuous updates and notifications are planned.

  1. 01

    New report: CISA AA25-141A

    The joint advisory of May 2025 describes GRU unit 26165 (APT28) targeting Western logistics and IT companies.

  2. 02

    Link to existing knowledge

    The ANSSI report of April 2025 already attributes HeadLace and CVE-2023-23397 to APT28. The new advisory cites it; ANSSI co-sealed it.

  3. 03

    Extend the assessment

    Previously: government, defence and research in France. Now: also logistics, transport and IT in 13 countries, with checkable indicators. Not independent confirmation, as the sources are linked.

In development

Keep your data and decisions under your control.

European sovereignty starts with clear boundaries: public threat information as a shared knowledge base, separate from protected organisational context.

Knowledge base
Public sources and their evidence.
Organisation context
Your supplied inventories remain a separate context.
Models
Model choice is part of the intended flexible design.
Integration
Interfaces and local processing will be scoped with pilot teams.

Local processing and private knowledge bases are a target, not an available feature. Demonstrator in development.

Our team

The people behind Serify

We build Serify together with security teams. Philipp translates their requirements into the product. Markus develops the AI methods that extract information and prepare it for analysis.

Dr.-Ing. Philipp Kühn

Dr.-Ing. Philipp Kühn

Co-Founder & Product Owner

Philipp is responsible for product direction and requirements at Serify. He works with security teams to define use cases, prioritises workflows and translates feedback into the next development steps.

Dr. rer. nat. Markus Bayer

Dr. rer. nat. Markus Bayer

Co-Founder & AI Development Lead

Markus leads AI development at Serify. He develops the methods for extracting and connecting threat information, selects suitable models and evaluates the quality of the agent pipeline's results.

Selected research

Automate the intelligence cycle

Proactive Cyber Threat Intelligence · 2025

The research basis for turning sources into usable findings.

View publication

AI for security text with little data

Deep Learning in Textual Low-Data Regimes for Cybersecurity · 2025

Research on deep learning that understands security text from few training examples.

View publication
All publications

Our Journey

What we are working on

Full roadmap

2026In Progress

Platform Development

Building a functional demonstrator of the integrated Serify platform, comprising four core components: a cybersecurity Knowledge Base aggregating threat intelligence from 500,000+ monitored sources; an eight-agent multi-agent pipeline for automated extraction of IOCs, TTPs, threat actors, CVEs, and campaign data; a web-based Chat Interface enabling natural-language interaction with security analysts; and a REST API for programmatic integration. The demonstrator is jointly evaluated with CSIRT and SOC personnel to validate real-world applicability.

2026 Q4In Progress

Pilot Program

Launch of a structured pilot programme with 2–4 selected CSIRT and SOC teams in the DACH region. Pilot partners validate the platform in their operational environments and provide direct feedback to shape further development, supported by strong regulatory tailwinds driving urgent demand for automated threat intelligence.

Before you ask

The questions we get first.

Serify is a demonstrator in development, so these answers say what holds today and what is still a target. If something here does not survive contact with your environment, that is worth a conversation.

  • Where does our data live?

    On European infrastructure. Public threat information sits in a shared knowledge base. Anything you supply, such as an inventory, stays in a separate context and is not mixed into it.

  • Which model do you use, and does our data train it?

    Model choice is part of the intended design rather than a fixed dependency, and we are evaluating open-weight and commercial options during the pilot phase. Nothing you supply is used to train a model.

  • Can we run this on-premise?

    Not today. Local processing is a target for the platform, not a feature you can buy. Tell us what your environment requires and we will be specific about what the demonstrator can and cannot do inside it.

  • We already run MISP and OpenCTI. Why add this?

    Those store and share what you already hold. Serify is aimed at the step before: reading new public reporting, extracting what is in it, and connecting it to what you have. Open formats such as STIX and MISP are part of the intended design, so the goal is to feed those tools rather than replace them.

  • What does a pilot cost us?

    Your time, mainly. A pilot means bringing a real recurring task and enough context to judge whether the answers hold up. We are not selling licences yet.

Pilot project

Which part of your workflow needs less manual work?

Tell us about your team, your sources and a specific task. Together we can define what to explore with the demonstrator and how to measure its value.

Or write to us directly:

contact@serify.eu

We use what you send here to answer you, nothing else. Privacy policy