Estimated reading time: 6 minutes
Threat intelligence has a timing problem. Most of it arrives after the damage. An indicator of compromise is a receipt, not a warning.
Silent Push announced on Aug. 4 that it will sell its underlying infrastructure data to other cybersecurity companies. The Reston, Virginia firm previously kept that data inside its own platform. Now product teams and threat intelligence groups can pipe it into their own tools. The company frames this as an application programming interface offering, meaning other vendors query the data directly from their software.
Silent Push states that it detects adversary infrastructure on average 104 days before attackers put it to use, and that assertion forms the whole basis of its commercial case.
Ken Bagnall, chief executive and co-founder at Silent Push, tied the move to product quality. “Cybersecurity products are only as effective as the intelligence behind them.”
What The Offering Actually Includes
The package includes a number of delivery routes and allows vendors to obtain data via the application programming interface for the purposes of enrichment, scoring, and bulk lookups. They are able to connect to the Model Context Protocol server, the standard developed by Anthropic which enables artificial intelligence tools to query a data source using plain language. CINI had already included that server when Silent Push released version 6.0 in June.
Buyers also get historical Domain Name System records, registration history, behavioral fingerprinting, and Traffic Origin data. Custom feeds can target a sector or a geography.
Nothing here is new technology. What changed is who gets to buy it.
The Number That Needs A Denominator
CINI wanted to know what 104 days actually amounts to, since this point is important to any underwriter who is reading this.
Silent Push has not published the sample size. It has not defined “weaponized.” It has not said whether the average covers all flagged infrastructure or only the subset later confirmed malicious. That last distinction is the whole ballgame. An average calculated only on confirmed hits will always look impressive.
None of this makes the figure wrong. It makes the figure unaudited. Underwriters should treat it as a vendor performance claim, not a measured lead time.
Specificity Versus Noise
Mees van Wickeren, senior threat analyst at Silent Push, argues the detection problem is one of convergence. A benign host might share one attribute with a threat actor. It rarely shares six.
“The signal is in the cluster, not any single data point,” van Wickeren told CINI. He named the combination the company looks for: a privacy-shielded registration, a fresh address in a hostile block, a certificate authority favored by one group, a matching favicon hash, and a fingerprint consistent with known command-and-control software.
Silent Push ships confidence scores rather than yes-or-no verdicts. Customers decide how hard to block.
The way that is framed is similar to an argument which CINI reported on last week, in which two security leaders maintained that binary questionnaire items lead to honest answers and rejected those claims; confidence scoring involves making the same objection but directed at a different target.
The Underwriting Argument
Van Wickeren makes a claim CINI’s audience should examine carefully. He believes preemptive intelligence belongs on the questionnaire beside multi-factor authentication and endpoint detection.
“Preemptive infrastructure intelligence reduces the probability of an attack landing at all,” he said. Traditional controls reduce the chance a breach follows an attack. His argument separates those two things.
The logic holds. The evidence does not. Multi-factor authentication and endpoint detection earned their place on applications because claims data eventually justified them. That took years.
Carriers are already moving pieces of this into place. Chubb named Arctic Wolf a preferred managed detection and response provider in February, tying constant monitoring to preferred pricing for policyholders with more than 100 employees. AXA XL agreed this month to buy the rest of S-RM, pulling forensics and incident data in-house. Terra Security pushed pentesting from a point-in-time exercise toward a continuous one.
All of those actions involve monitoring the insured’s own environment, but Van Wickeren is aiming for something else; he would like credit for monitoring the attacker’s environment.
What Changes After The Policy Binds
The stronger part of van Wickeren’s case concerns the policy period. Insurers assess risk at bind. They reassess at renewal. The twelve months between are mostly dark.
“An insured’s posture in month one is not their posture in month ten,” he said.
He describes three uses for continuous visibility. Portfolio exposure becomes visible when an actor stages against a whole sector. Third-party concentration becomes measurable when a shared vendor appears in staging activity. Mid-term drift becomes something an insurer can see.
The third-party point lands hardest. Verizon’s 2026 Data Breach Investigations Report found third-party involvement in 48% of confirmed breaches, up 60% year over year. Nearly half of the loss picture now sits outside the insured’s own network.
The Question Nobody Asked The Policyholder
Van Wickeren calls the endpoint a “dynamic risk partnership.” That phrase deserves a harder look.
Continuous visibility is not neutral. It gives the insurer information the insured did not volunteer. An insurer who sees mid-term deterioration can notify a policyholder. It can also reprice, restrict, or non-renew. It can build a coverage argument out of what it saw and when it saw it.
Van Wickeren’s own framing invites this. “The entire security model shifts from reactive to preemptive,” he said of the security side. The insurance side shifts too. Risk transfer becomes risk surveillance.
FAQ – Preemptive Threat Intelligence
It made its first-party infrastructure data available to other cybersecurity vendors via an application programming interface, a Model Context Protocol server, custom feeds, and full platform access.
It is the term that Silent Push has registered as a brand for infrastructure which seems to be being built in preparation for a future attack. This term is company branding and not an industry standard.
It is a vendor claim with no published methodology. Silent Push hasn’t disclosed the sample, the definition of weaponized, or whether the average covers only confirmed malicious infrastructure.
The report by Verizon for 2026 showed that third parties were involved in 48 per cent of the breaches that had been confirmed. It would be possible to assess the total exposure through a shared vendor if one had visibility into it before the claims arrived.
Because of continuous monitoring the insurers can justify mid-term changes in the rate, impose restrictions, or have disputes over the coverage. The same data that enables early warnings also enables action at a later stage.
Related Cyber Insurance Posts
- Allianz Renames Cyber360 Protect to Scam Protect, Still Calls It Personal Cyber Insurance
- Hackers Silenced The Water Alarms. Insurers Are Being Asked To Fix It.(Opens in a new browser tab)
- AI Risk Reshapes Cyber Insurance: Key Takeaways From Lockton Re and Armilla’s “Ready or Not”(Opens in a new browser tab)
- Dangling DNS Takeover Risk: Inside Silent Push’s “Danglegeddon” Study(Opens in a new browser tab)