European threat intelligence, from the attacker's perspective.
SAFA is an independent research house. We study how real adversaries operate, and turn that into intelligence European organisations can act on.
TeamT5: SAFA's Key Strategic Partner
We draw on TeamT5, a leading Taiwan-based research team, as one source feeding our Asia and China-nexus coverage. We fuse it with our own research and other sources to deliver intelligence built for European buyers.
Three ways we work, one discipline behind them.
We understand how attackers break real systems, from mobile and desktop to IoT. That understanding is the foundation everything else is built on.

Original research
We publish technical research on how attackers break real systems, from mobile and desktop to IoT. It is the foundation everything else is built on..

Adversary-led testing
We test defences the way adversaries do, aligned to the TIBER-EU and DORA frameworks, and answer the intelligence questions your team does not have time to.

Intelligence
Intelligence that fuses our own research with trusted sources, delivered for the organisations that need it most.
Fused coverage, not a single-region feed
Popular threat intelligence platforms may rely on open-source intelligence or broad, globally available data. ThreatVision is different. Focused on the APAC region, it takes you closer to hotspots for emerging threats like APTs, malicious code, and others, so you stay confidently ahead of cybercrime.
Asia coverage, from a specialist source
Our Asia and China-nexus coverage draws on TeamT5, a leading Taiwan-based research team tracking threats across the region. We fuse their coverage with our own, under a European flag, so our clients get one picture rather than a single-region feed.
Talk to us about your threat intelligence needs
Tell us what you're defending and we'll show you how our intelligence fits. No product demo required.
Selected research
Selected technical research from our team. We publish deliberately rather than often.
What to Expect During a Security and Vulnerability Assessment
A security and vulnerability assessment uncovers hidden weaknesses in your IT systems before attackers can exploit them. This structured process evaluates your network, software, and policies, prioritizes risks, and guides remediation efforts. Regular assessments help organizations stay compliant, reduce breach risks, and maintain stronger defenses against fast-evolving cyber threats.
What Is Security Information and Event Management (SIEM)?
Security Information and Event Management (SIEM) is a cybersecurity solution that provides real-time visibility into an organization’s IT environment by collecting, analyzing, and correlating security data from multiple sources. SIEM helps detect threats, support incident response, and ensure regulatory compliance by identifying unusual behavior and potential security incidents. With features like event correlation, real-time monitoring, and automated responses, SIEM enables organizations to proactively defend against cyberattacks and streamline security operations.
What is Ransomware? | Understanding & Defending Against It
Ransomware is a type of malicious software designed to block access to systems or encrypt files, demanding payment to restore access. It often spreads through phishing emails or compromised websites and can cause significant data loss and financial damage. There are two main types: locker ransomware, which locks users out of their systems, and crypto ransomware, which encrypts files. With ransomware-as-a-service and cryptocurrency making it easier for attackers, it's crucial to implement protective measures like regular backups, endpoint protection, and employee training to defend against these attacks.