Cross-Org Response Timelines
Same Threat. Two IR Teams. Seven IOCs and Four IOCs. No Sharing. Ten Total Missed.
5 min read · 12 August 2026 · Security
A healthcare technology company and one of their primary data analytics vendors were both targeted in the same threat actor campaign , a sophisticated group conducting espionage operations against healthcare organisations. The campaign used consistent infrastructure, similar techniques, and the same credential theft methodology across multiple targets in the healthcare sector. The healthcare company's SOC identified the intrusion through anomalous authentication events and initiated their IR process, identifying four indicators of compromise over the following three days. Meanwhile, the analytics vendor's SOC had independently identified the same threat actor in their environment six days earlier, had completed a more extensive investigation, and had identified seven IOCs including malware samples, C2 domains, and specific credential manipulation techniques. Neither party had any mechanism to share IOCs with the other during their concurrent investigations. The vendor had not identified the customer as a co-targeted organisation. The customer had not considered whether the vendor might be experiencing the same campaign. When the vendor's notification to the customer arrived on day twelve , a breach notification rather than a threat intelligence share , the customer's IR team discovered that the additional three IOCs in the vendor's investigation could have accelerated their own timeline by an estimated three days. The attacker had used the customer's environment for nine days before detection. Three of those days might have been prevented by IOC sharing with a co-targeted vendor.
What are Cross-Org Response Timeline Problems, Really?
Cross-organisation response timeline problems arise when security incidents affecting multiple organisations , particularly supply chain incidents targeting vendors and their customers in the same campaign , are investigated independently by each affected organisation rather than through coordinated information sharing. The result is duplicated investigation effort, delayed detection for the party with less intelligence, and failure to prevent the attacker from exploiting the information asymmetry between independently investigating organisations.
The supply chain campaign targeting pattern is the specific threat context. Sophisticated threat actors who target organisations through their supply chain frequently target multiple organisations in the same sector simultaneously , the vendor and several of their customers, or multiple vendors in a shared supply chain. The intelligence gathered by one targeted organisation is directly relevant to the investigation of other targeted organisations facing the same adversary. Independent investigation prevents this intelligence from flowing between co-targeted organisations in the timeframe when it would accelerate mutual detection and response.
The IOC sharing inhibition problem is the structural barrier to cross-org coordination. Sharing IOCs and incident details across organisational boundaries during active incidents involves legal review, privacy considerations, liability exposure, and competitive sensitivity concerns that inhibit or delay sharing even when sharing would benefit all parties. Organisations that have pre-established information sharing agreements and trusted communication channels can share more rapidly during incidents than those who must initiate the sharing relationship during the incident itself.
- Independent investigation of shared threat , same attacker, separate IR teams, no coordination
- IOC sharing inhibition , legal and competitive barriers to real-time IOC exchange
- No pre-established sharing mechanism , sharing relationship initiated during incident
- Co-targeting recognition gap , neither party considering whether vendor or customer might share threat
- Dwell time extension from delayed mutual detection
Why this matters
Cross-org response timelines matter for TPRM because supply chain incidents frequently create co-targeting scenarios where coordinated response would produce faster detection and shorter attacker dwell time for all parties. The customer who maintains a pre-established threat intelligence sharing relationship with their highest-risk vendors benefits from the vendor's earlier detection of shared threats. The vendor who knows their customers will share IOCs during incidents can incorporate customer intelligence into their investigation timeline.
The ISAC coordination model demonstrates the value at sector level. Financial services ISACs, healthcare ISACs, and critical infrastructure information sharing organisations have demonstrated that sector-wide threat intelligence sharing accelerates detection for all participants. The same principle applies at the vendor-customer relationship level , direct sharing between co-targeted organisations that have a pre-established relationship and trust basis accelerates mutual response.
Where most teams get this wrong
The most consistent failure is not considering whether a co-targeting scenario exists when conducting incident response. IR teams focused on their own environment may not consider whether their vendor or customer is facing the same threat simultaneously , and whether contacting them during the investigation would reveal shared intelligence.
- Co-targeting awareness absent during IR , not considering vendor/customer as potential co-targets
- No pre-established IOC sharing mechanism with vendors
- Legal review delaying sharing during active incidents
- No shared threat intelligence feed with critical vendors
- ISAC participation not coordinating with vendor-specific sharing
What good looks like
Mature cross-org response programmes pre-establish IOC sharing mechanisms with critical vendors and customers , through ISACs, bilateral sharing agreements, or direct threat intelligence exchange , and include co-targeting assessment as a standard early step in IR procedures for incidents involving shared threat actors.
- Pre-established bilateral sharing agreement with critical vendors and customers
- Co-targeting assessment step in IR procedures , is the vendor or customer facing the same threat?
- Trusted communication channel for IOC sharing during incidents
- ISAC participation for sector-wide sharing
- Legal pre-approval for IOC sharing during incidents , avoid delay during active response
Tooling
Threat Intelligence Sharing , MISP, OpenCTI, STIX/TAXII
Threat intelligence sharing platforms provide structured IOC exchange in formats that enable automated ingestion by receiving organisations' security tools. Pre-configuring STIX/TAXII feeds or MISP sharing groups with critical vendors enables faster IOC sharing during incidents than email-based exchanges. For TPRM practitioners, establishing structured threat intelligence sharing with critical vendors provides the mechanism for accelerated mutual detection.
ISACs , FS-ISAC, H-ISAC, IT-ISAC
Information Sharing and Analysis Centres provide sector-specific threat intelligence communities where shared threats are shared across participants simultaneously. For TPRM practitioners, ensuring both the customer and their critical vendors participate in the same ISAC provides a shared context for co-targeted scenario awareness.
Governance challenges
The governance challenge with cross-org sharing is the legal and competitive sensitivity barrier. Pre-establishing legal pre-approval for IOC sharing reduces sharing delays during active incidents. The bilateral sharing agreement that addresses liability, data handling, and competitive sensitivity concerns in advance enables faster sharing when the incident requires it.
- Establish bilateral threat intelligence sharing agreement with critical vendors
- Negotiate legal pre-approval for IOC sharing during mutual incidents
- Add co-targeting check to IR procedure , contact critical vendors when supply chain threat actor identified
- Establish MISP or STIX/TAXII sharing with critical vendors
- Participate in shared ISAC with critical vendor relationships
If you are a small team
Add one step to your IR procedure for any incident involving a threat actor potentially targeting your sector: contact the IR lead at each of your Tier 1 vendors and ask whether they have identified the same indicators in their environment. That step costs one phone call. In a co-targeting scenario, that call could provide IOCs that accelerate your investigation by days. Pre-establish the IR contact at each Tier 1 vendor so the call goes to the right person immediately.
- Add co-targeting check to IR procedure
- Establish IR-to-IR contacts at Tier 1 vendors for emergency sharing calls
- Negotiate bilateral IOC sharing agreement with critical vendors
- Participate in shared ISAC
What to require
Ask directly:
"If your SOC identifies a threat actor that might also be targeting your customers, what is your process for sharing threat intelligence with affected customers , and do you have a mechanism for sharing IOCs directly with our security team during an active investigation?"
Expect as evidence
- Customer notification process for co-targeting scenarios
- IOC sharing mechanism , STIX/TAXII, MISP, or bilateral agreement
- ISAC participation in shared sector
- Legal pre-approval for IOC sharing
A vendor who confirms mature independent IR should be asked whether co-targeting scenarios are part of their IR procedure and how IOC sharing with customers works during active investigations. Independent maturity is valuable. Coordinated maturity is more so.
How to evidence it
- Bilateral sharing agreement documentation
- Co-targeting assessment process records
- IOC sharing mechanism configuration
- ISAC participation records
Key Takeaway
Same threat. Two investigations. Seven IOCs and four IOCs. No sharing. Three days of preventable dwell time. The attacker targeted both parties simultaneously and benefited from their independent investigation. The combined IOC set that would have accelerated both investigations existed , distributed across two IR teams who had no mechanism to share during the active investigation. Pre-established bilateral sharing agreements, IOC exchange mechanisms, and a co-targeting check in the IR procedure address the structural barriers before the incident that reveals them. The threat is coordinated. The response should be too.
Speak to It™
The term you nodded along to, explained in ninety seconds, so you can speak to it professionally. It is how most readers find these articles.
Join the Association