Felswerk
Sign in

The category

Security Knowledge
Intelligence

01 — The definition

Security Knowledge Intelligence

noun

The discipline of transforming years of organizational security evidence into enduring institutional knowledge.

Every pentest, red-team operation, incident, and architecture review teaches an organization something about itself. Security Knowledge Intelligence is the practice of engineering that learning so it endures: structured instead of filed, connected instead of siloed, compounding instead of decaying.

It rests on three ideas: knowledge decay is the enemy, knowledge compounding is the method, and institutional memory is the outcome.

02 — The lexicon

Terms of the discipline

The Felswerk Lexicon

A discipline needs a vocabulary. These are the terms we use everywhere — on this site, in the whitepaper, and inside the product.

Knowledge Decay
When institutional security knowledge is lost between engagements.
Knowledge Compounding
When each engagement strengthens the value of previous engagements.
Institutional Memory
The retained understanding that survives personnel and vendor changes.
Security Knowledge Intelligence
The discipline of transforming years of organizational security evidence into enduring institutional knowledge.
03 — Adjacent categories

Adjacent categories

Necessary. Not sufficient.

Modern security programs already run several disciplines that sound close. Each answers a real question. None of them is designed to answer this one: does what we learn endure?

CTEM

Continuous Threat Exposure Management asks: where are we exposed right now?

Its model is a recurring cycle optimized for the current snapshot. The lessons of previous loops typically live in tickets and decks rather than in a knowledge base the next loop starts from.

Exposure Management

Exposure management asks: which assets and vulnerabilities matter most today?

Its model is inventory-centric and present-tense. When a finding is remediated it usually leaves the queue — and with it, much of the understanding of why it existed and how often it has come back before.

GRC

Governance, risk, and compliance asks: can we evidence our controls to an auditor?

Its primary artifact is the attestation. A control marked effective says little about the three engagements that defeated it, or the lesson each one carried.

These disciplines may retain evidence and history, but their primary models are optimized for current exposure, control state, or workflow execution — not for preserving longitudinal organizational learning as a first-class asset. The pentest that informed this quarter's exposure priorities is a PDF by next quarter. Every one of these programs would be stronger sitting on top of knowledge that endures.

Security programs already consume knowledge.
The missing discipline preserves it.

That layer is Security Knowledge Intelligence.

04 — Why now

Why the category exists today

The economics have changed.

Institutional memory was always the right answer, and it always failed for the same reason: turning unstructured reports into structured, connected, current knowledge was months of expert labor no team could spare.

Machine-assisted extraction and retrieval reduce that burden. Combined with provenance, human review, and source traceability, they make longitudinal security knowledge practical to maintain.

Felswerk exists to make Security Knowledge Intelligence possible.

Read our philosophy →

Put the discipline to work.

Felswerk is the system engineered for Security Knowledge Intelligence.

Explore the platform

Read the whitepaper