The Relevance Doctrine, Part 2: Making "Relevant" a Calculation

Chief Product Officer, Cyware

This is the second installment of The Relevance Doctrine. Part 1 made the case that relevancy, not volume, determines whether a threat intelligence program works. This installment takes on the obvious follow-up question: what exactly is relevancy calculated from?
In Part 1, I argued that relevancy is the way out of the noise. The fair question back is the one I would ask too: relevant according to what?
If relevant stays a matter of analyst instinct, it does not scale, it is not repeatable, and it will not keep pace with an adversary operating at machine speed. It is also unauditable. No security leader can explain to a board why one threat was chased and another was set aside when the answer lives in a judgment call made at hour six of a triage shift.
So the goal is to make relevancy a calculation. One the platform runs continuously, and one it can explain. Let me define the inputs.
The external threat is only half the picture
Feeds describe the outside world: actors, campaigns, malware, vulnerabilities, and who they target. That is necessary and nowhere near sufficient. A critical CVE that touches nothing you run is someone else's emergency.
Prioritizing by severity alone is precisely the habit that broke once the NVD backlog made exploitability and asset criticality the real control plane rather than CVSS scores. The same pattern shows up in the data on why CVSS-only prioritization is failing as CVE volume climbs. A score that describes a vulnerability in the abstract cannot tell you whether it belongs to you.
Relevancy needs the other half. It needs your internal reality.
The four inputs of a relevancy calculation
Internal asset and attack-surface context. What you actually run, including custom and shadow assets, exposed edge devices, and your crown jewels. Exposure management defines the surface a threat could land on. Without it, every calculation is theoretical.
Telemetry and observed behavior. What your SIEM, EDR, and identity systems are already seeing. Note the pivot here, from indicators of compromise to indicators of behavior. Behavior survives when infrastructure rotates. Indicators do not.
External threat and targeting. The actors, TTPs, campaigns, and vulnerabilities in play, and whether their targeting intersects your sector, your geography, and your supplier ecosystem.
Correlation and scoring. The connective tissue. Fusing tactical and technical data, mapping to MITRE ATT&CK, and producing a risk-based score that reflects the intersection rather than any single dimension.
Run those four together and "is this relevant?" stops being a debate. A vulnerability lights up when it sits on an asset you run, is exploitable in the wild, is favored by an actor known to hit your sector, and is adjacent to behavior your telemetry is already surfacing. That convergence is signal. Everything short of it is context you can hold lightly.
The distinction matters more than it sounds. Most programs treat every input as an alert. A relevancy calculation treats most inputs as background and reserves attention for the intersection.
Correlation answers two questions, not one
Correlation is usually described as a way to decide whether something is relevant. That undersells it.
Correlation does two jobs at once. It tells you whether a threat is relevant, and it tells you how far that threat reaches across your environment, which is the radius, and where you are already covered.
Relevance without radius produces a yes or no on a single object. Relevance with radius produces a scope of action: these assets, these business units, these controls already hold, these do not. That second answer is the one that determines what a team does on a Tuesday morning.
Why this has to be AI-native
No human team correlates thousands of daily threat objects against a live asset inventory and streaming telemetry at the tempo an AI-armed adversary sets. This is not an efficiency argument. It is an arithmetic one.
This is the work Cyware AI was built for: native correlation, analysis, and an AI correlation engine with predictive capability, threaded through the Cyware Intelligence Suite. Matching runs two ways at once, semantic similarity that understands meaning alongside precise indicator and behavior matching, so a report about a new campaign surfaces even when it never names your specific indicators.
That dual path matters because adversary reporting rarely arrives in the shape your infrastructure expects. Exact matching alone misses the campaign described in prose. Semantic matching alone is imprecise about the artifacts on your network. You need both, running continuously, on data that has already been cleaned and connected.
In Cyware Intel Exchange, customizable risk scoring and MITRE-aligned mapping already do this at ingest, and AI agents unify aliases, enrich indicators, and map adversary behavior so correlation operates on clean, connected data rather than on a pile of duplicates.
The Relevancy Index
On top of that correlation layer sits a Relevancy Index: a scoring layer that expresses, per threat, how much it matters to you given your assets, your exposure, and your observed activity.
This is signal-to-noise made computable and continuous. Not a severity score inherited from the outside world, and not a static tag applied once and forgotten. A number that moves as your environment and the threat landscape move, and that can be inspected to understand why it moved.
That last property is the one I would not trade away. A score nobody can interrogate is just a different kind of noise.
A relevancy score still needs an owner
Here is the honest limit of pure analytics. A relevancy score, on its own, is a number without an owner.
To become an intelligence program, relevancy has to be anchored to a decision someone actually needs to make, and to a person who needs to make it, whether that is an analyst, a SOC lead, or an executive. Computing relevancy against a defined requirement is what turns a dashboard into a discipline.
That discipline has a name, and it is the subject of Part 3: Priority Intelligence Requirements.
SEE RELEVANCY COMPUTED
See how Cyware's Relevancy Index, AI correlation, and MITRE-aligned scoring bring the external threat and your internal reality into one prioritized view. Book a demo or Explore Cyware Intel Exchange
About the Author

Sachin Jade
Chief Product Officer, Cyware