The category
Security Knowledge
Intelligence
Security Knowledge Intelligence
noun
The discipline of transforming years of organizational security evidence into enduring institutional knowledge.
Every pentest, red-team operation, incident, and architecture review teaches an organization something about itself. Security Knowledge Intelligence is the practice of engineering that learning so it endures: structured instead of filed, connected instead of siloed, compounding instead of decaying.
It rests on three ideas: knowledge decay is the enemy, knowledge compounding is the method, and institutional memory is the outcome.
Terms of the discipline
The Felswerk Lexicon
A discipline needs a vocabulary. These are the terms we use everywhere — on this site, in the whitepaper, and inside the product.
- Knowledge Decay
- When institutional security knowledge is lost between engagements.
- Knowledge Compounding
- When each engagement strengthens the value of previous engagements.
- Institutional Memory
- The retained understanding that survives personnel and vendor changes.
- Security Knowledge Intelligence
- The discipline of transforming years of organizational security evidence into enduring institutional knowledge.
Adjacent categories
Necessary. Not sufficient.
Modern security programs already run several disciplines that sound close. Each answers a real question. None of them is designed to answer this one: does what we learn endure?
CTEM
Continuous Threat Exposure Management asks: where are we exposed right now?
Its model is a recurring cycle optimized for the current snapshot. The lessons of previous loops typically live in tickets and decks rather than in a knowledge base the next loop starts from.
Exposure Management
Exposure management asks: which assets and vulnerabilities matter most today?
Its model is inventory-centric and present-tense. When a finding is remediated it usually leaves the queue — and with it, much of the understanding of why it existed and how often it has come back before.
GRC
Governance, risk, and compliance asks: can we evidence our controls to an auditor?
Its primary artifact is the attestation. A control marked effective says little about the three engagements that defeated it, or the lesson each one carried.
These disciplines may retain evidence and history, but their primary models are optimized for current exposure, control state, or workflow execution — not for preserving longitudinal organizational learning as a first-class asset. The pentest that informed this quarter's exposure priorities is a PDF by next quarter. Every one of these programs would be stronger sitting on top of knowledge that endures.
Security programs already consume knowledge.
The missing discipline preserves it.
That layer is Security Knowledge Intelligence.
Why the category exists today
The economics have changed.
Institutional memory was always the right answer, and it always failed for the same reason: turning unstructured reports into structured, connected, current knowledge was months of expert labor no team could spare.
Machine-assisted extraction and retrieval reduce that burden. Combined with provenance, human review, and source traceability, they make longitudinal security knowledge practical to maintain.
Felswerk exists to make Security Knowledge Intelligence possible.
Put the discipline to work.
Felswerk is the system engineered for Security Knowledge Intelligence.