Tidal Cyber’s cover photo
Tidal Cyber

Tidal Cyber

Computer and Network Security

A New Era in Threat-Led Defense Begins Here. Redefining Detection and Defense.

About us

Tidal Cyber is redefining how modern security teams think about exposure, detection, and readiness. No longer bound by CVE counts, asset inventories, or checkbox compliance, Tidal Cyber's Threat-Led Defense provides a level of specificity not seen before. Organizations can now reduce risk proactively with the precision to answer the most important question in cybersecurity: "Can I defend against the latest threat?" Through TTPs and procedural-level insights mapped to MITRE ATT&CK, adversary groups and their behavior are embedded into your security strategy, shifting to a proactive, continuous threat-led defense first. Built by former MITRE ATT&CK® experts and the co-founder of MITRE's Center for Threat-Informed Defense, Tidal Cyber's threat-led platform introduces a breakthrough level of specificity by mapping techniques and sub-techniques to operationalize adversary procedures. This shift transforms how organizations understand, measure, and act on threat exposure. Unlike traditional, reactive, or vulnerability-first approaches, Tidal Cyber delivers procedural-level granularity across the MITRE ATT&CK framework, offering unmatched visibility into the "how" of attacker behavior. Their coverage mapping calculates residual risk for each technique and provides stack-specific visibility, highlighting exposures based on how real-world adversaries operate.

Industry
Computer and Network Security
Company size
11-50 employees
Headquarters
Washington D.C.
Type
Privately Held
Founded
2022
Specialties
cybersecurity, threat intelligence, security architecture, cyber defense, detection engineering, risk quantification, threat hunting, threat-informed defense, threat exposure management, threat profiling, coverage mapping, and mitre attack product mapping

Locations

Employees at Tidal Cyber

Updates

  • View organization page for Tidal Cyber

    8,089 followers

    “Everyone talks today about being Threat-Led, but many organizations struggle to know whether they could actually stop a real attack in real-time. What’s been missing, and why did Tidal Cyber create the Threat-Led Defense category?” Rick Gordon and Steven Gerry answer this question in their latest Information Security Media Group (ISMG) interview recorded during Black Hat 2026. #ThreatLedDefense really comes down to being able to answer a basic security question: ❓Can I effectively defend against the tradecraft that adversaries who are attacking us are using, and if not, how do I most optimally allocate resources to reduce residual risk❓ Watch the Full Interview: https://okt.to/VcAFYn

  • Tidal Cyber reposted this

    The CyberLounge wrapped up last week, and it was everything we hoped it would be and more! 🎉 Over two days, the event was filled with fresh perspectives from across the cybersecurity community and conversations that stayed with us long after it ended. Thank you to everyone who stopped by and to our partners who helped make it happen. We're already looking forward to the next one! Arcova, formerly MorganFranklin Cyber Team, BreachRx, Team Cymru, CLEAR, Tidal Cyber

    • No alternative text description for this image
    • No alternative text description for this image
    • No alternative text description for this image
    • No alternative text description for this image
    • No alternative text description for this image
      +3
  • Tidal Cyber reposted this

    What an absolute honor it was to host the Blackhat Boots & Bourbon event this year. We had the privilege of hearing from Anomali, Invicti, Tidal Cyber, and Zenity — who shared valuable insights over good conversation and even better company. And yes… we did it right. Guests got to taste some of the best Pappy Van Winkle whiskey and get fitted for a custom pair of Tecovas boots. Cybersecurity meets boots and bourbon — it doesn’t get much better than that. Grateful to everyone who joined us, the incredible speakers who made the evening special. Moments like these remind me why I love this community. If you missed this event but want to join the next one, send me a DM. Here’s to more great conversations, strong partnerships, and unforgettable experiences. Video by Cyber Concierge

  • Tidal Cyber reposted this

    Can Threat-Informed Defense stop a critical infrastructure attack before it happens? The recent coordinated cyberattacks on over 30 Minnesota water systems—affecting municipalities like Plymouth and South St. Paul—highlight the stakes of OT security. With automated networks controlling clean water flow, manipulative attacks on chemical or operational set-points put hundreds of thousands of lives at risk. The guidance from Minnesota leadership to simply disconnect vulnerable equipment from the internet is both shocking and disappointing. Evaluating how Tidal Cyber could have prevented such an incident relies on two key architectural assumptions: 1️⃣ Security Stack Presence: The utility did NOT leave an unsegmented PLC exposed to the public internet without an upstream firewall or EDR. 2️⃣ Active Enforcement: The utility DID have a strong, active firewall or IPS in place to intercept traffic in real-time. How Tidal Cyber Could Have Stopped the Attack Under these conditions, Tidal Cyber’s SaaS platform stops the attack sequence before execution: * Eliminating "Dormant" Policies: Security tools often run with default settings. Tidal Cyber audits your stack against adversary TTPs, alerting teams to inactive rules—like blocking unauthenticated PLC management requests—that exist in your firewalls but sit unused. *Procedure-Level Precision: Broad framework categories don't explain how to write a detection. Tidal Cyber translates threat intel into exact procedure sightings (specific commands, ports, and exploitation scripts). Tidal Cyber *Prioritizing Relevant Risks: By mapping active campaigns targeting critical infrastructure, Tidal Cyber generates an automated coverage map pinpointing residual risk, giving teams a direct checklist to harden defenses before exploitation. Richard Struse Steven Gerry Mark Davidson Key Takeaway Tidal Cyber isn't an inline firewall—it is the intelligence layer ensuring your existing firewalls, IPS, and EDR tools are configured to block active adversary tactics.

  • In this latest blog from GigaOm, Rick Gordon sat down during #BlackHat to chat about how the job of every single person in security is to understand the threats against you and to know whether you can defend against it effectively by answering one basic question: “Out of everything I could do next, which of it reduces residual risk by the greatest amount?” This is where Tidal Cyber's Threat-Led Defense changes the approach by starting from an understanding of adversary tradecraft and aligning defenses accordingly, preventing efforts from being irrelevant to the actual attacks a business is likely to face. The Tidal Cyber platform takes this and makes it usable day-to-day by turning risk into a number you can actually act on by evaluating resistance against specific adversary behaviors based on the existing security stack, and then layering in a confidence score to help guide decisions about where to invest efforts. Read the full blog for more on how this approach relates to Rick’s past as a submarine officer and helps quantify security spend to the boardroom: https://okt.to/pPfiHk

    • No alternative text description for this image
  • Tidal Cyber is in Austin, Texas this week for the The Millennium Alliance Transformational CISO Assembly! While there, Rick Gordon and Steven Gerry will be hosting a discussion on operationalizing ATT&CK to align your defenses around adversary behavior. This roundtable discussion will be centered around how to decrease the probability of attacker likelihood while gaining the maximum value out of security tools, and will also cover: ✅ Getting value out of threat intel ✅ How everyone is approaching TTP layered defenses ✅ How to effectively reduce residual risk

    • No alternative text description for this image
  • View organization page for Tidal Cyber

    8,089 followers

    🌊 The Tidal Cyber team is back from a whirlwind of a week at Black Hat 2026! From the engaging discussions at our booth, to Cat S.'s standing-room only talk (recording coming soon!), to demos and meetings in the Cyber Lounge, to CISO Karaoke, to our Bourbon tasting and boot fitting, to our ISMG interview (recording also coming soon!), to our annual pool party, it was a week packed with great conversations, new connections, and plenty of memorable moments. A huge thank you to everyone who stopped to chat, joined us at an event, caught a demo, or shared ideas. We love hearing what’s top of mind for security teams and talking about how #ThreatLedDefense can help organizations reduce the probability of attacker success. Already looking forward to next year!

    • No alternative text description for this image
    • No alternative text description for this image
    • No alternative text description for this image
    • No alternative text description for this image
    • No alternative text description for this image
      +5
  • 🌊 The Tidal Cyber team had an amazing first day at Black Hat 2026, and are back at the booth for a busy day 2! 🏄 Make sure you ride the wave over to Booth 5910 (Look for the Neon Sign!) to chat with us, see Threat-Led Defense in action, and enter to win a Lego Great Wave! 🏖️ Once the show floor closes, come end the week in style at our Pool Party tonight featuring DJ Morgan Page Tailgate Beach Club, Mandalay Bay | 5:00-9:00pm

    • No alternative text description for this image
    • No alternative text description for this image

Similar pages

Browse jobs