Indicators of Warning (IoW): Definition and Examples


What’s on this page
Threat intelligence has never been in short supply. Every week brings new vulnerabilities, fresh phishing campaigns, new malicious domains and another threat actor in the headlines. The hard part is deciding which of these deserve your attention today. Most security teams don't struggle to find threats. They struggle to tell which ones actually apply to them. That's the gap Indicators of Warning (IoWs) fill within CTM360's Next-Gen Cyber Threat Intelligence model.
What is an Indicator of Warning (IoW)?
An Indicator of Warning (IoW) is a threat signal with an evidence-backed link to your organization, spotted before anyone confirms you are being targeted.
That link can come from several places: your Digital Asset Register, your technology stack, your third parties, your sector, your geography or your peer group. When outside threat intelligence connects to any of these with real evidence, it stops being general news and becomes a warning for you.
Here's the difference in practice. A new vulnerability published online is just threat intelligence. But if it affects the exact web server version running on one of your public-facing systems, it's now your problem, and that's what makes it a warning.
When does a vulnerability become an IoW?
A CVE doesn't become an IoW for everyone the moment it's disclosed. It becomes one for you when it matches something you actually run.
Say a critical flaw in a popular VPN appliance is published overnight and quickly makes the news. For most organizations, it's one more headline to skim. For a team whose CTM360 view shows that exact version running on two of its internet-facing hosts, it means something else entirely.
That team knows which systems to patch first, and knows it before anyone has tried to exploit them. It's possible because the Digital Asset Register already knows what's running where.
Can a phishing campaign become an IoW?
Yes, though context decides. A campaign hitting a company on another continent, in a different industry, with no shared technology or attacker pattern, probably has little to do with you.
It's a different story when the same phishing infrastructure starts showing up against several banks in your region. If you're a bank in that region too, the activity is moving closer. That's an IoW.
If the attacker then starts using your brand or impersonating your executives, you've moved from being nearby to being the target. In CTM360's model, that moves it from an Indicator of Warning to an Indicator of Attack (IoA).
Is a lookalike domain automatically an IoW?
No. A newly registered domain that resembles your company name is worth a look, but registration alone doesn't prove anyone is planning an attack. Some lookalikes belong to small businesses with similar names, some are parked by resellers, and some are never used at all.
A lookalike becomes meaningful when other evidence links it to malicious activity, such as shared campaign infrastructure, suspicious registration patterns, hosting relationships, the content on the page or known attacker behavior.
Waiting for that evidence keeps your team from treating every odd registration as an emergency. It's also one of the simplest ways to cut down threat intelligence noise.
What are some examples of Indicators of Warning?
Depending on the evidence and your organization's context, an IoW can be:
- A CVE affecting technology confirmed on your internet-facing infrastructure
- Exploitation activity involving technology your organization uses
- A phishing campaign aimed at your sector or peer group
- Suspicious infrastructure linked to a developing campaign that's relevant to you
- Threat activity hitting a critical third party you depend on
What they all share is a credible, evidence-backed connection between the threat and your organization.
IoE vs IoW vs IoA: what's the difference?
CTM360's Next-Gen CTI model goes beyond traditional Indicators of Compromise (IoCs) with three layers of intelligence, each specific to your organization.
An easy way to remember it: IoE is what's exposed, IoW is what's getting closer, and IoA is what's already aimed at you.
IoCs still have their place. They describe malicious artifacts that have already been seen somewhere in the world. The three-layer model adds what IoCs leave out: what those developments mean for your organization right now.
What role does the Digital Asset Register play?
You can't judge whether a threat is relevant until you know what you have. That's why CTM360's Next-Gen CTI model starts with the Digital Asset Register: a continuously maintained view of your domains, hosts, IP addresses, technologies, brands, applications and everything else that makes up your internet-facing presence.
Correlating threat intelligence against that inventory changes the message your team receives. "A critical CVE has been disclosed" becomes "This critical CVE affects one of our internet-facing servers." Only the second one gives your team somewhere to start.
From threat news to a warning you can act on
Threat intelligence tells you what's happening out there. An Indicator of Warning tells you when it's starting to happen to you, while there's still time to do something about it.
That's the real job of IoW in CTM360's model. It takes the constant stream of global threat news and narrows it down to the handful of things worth your team's attention this week.
Frequently asked questions
What does IoW mean in cybersecurity?
In CTM360's Next-Gen Cyber Threat Intelligence model, IoW stands for Indicator of Warning: a threat signal with an evidence-backed link to an organization, identified before active targeting has been confirmed.
Is every CVE an Indicator of Warning?
No. A CVE becomes an IoW only when it's relevant to the organization, for example, when it affects a technology and version confirmed on its internet-facing infrastructure.
What is the difference between IoE and IoW?
An IoE is a weakness in your own environment that an attacker could use, like an exposed service. An IoW is an outside threat that is developing and has a credible link to you, like a newly disclosed vulnerability in software you run.
What is the difference between IoW and IoA?
An IoW means a developing threat is relevant to you. An IoA means malicious activity is already targeting your organization, brand, people, customers or digital assets.
Is a lookalike domain an Indicator of Warning?
Not on its own. It becomes one when further evidence, such as related campaign infrastructure or attacker behavior, ties it to malicious activity.



