FocusTag® (FocusTags®)
FocusTags® are dynamic risk intelligence tags within the Black Kite platform that bridge global threats to your specific vendor ecosystem, down to the asset level. They are automatically assigned in the wake of significant cyber events like ransomware campaigns or newly disclosed Common Vulnerabilities and Exposures (CVEs), immediately surfacing which vendors in your portfolio are exposed. Users can also create custom tags to organize vendors by criteria such as personally identifiable information (PII) access or system integration depth. FocusTags® are a critical component of continuous monitoring, transforming raw threat intelligence into actionable, contextualized risk intelligence.
A FocusTag® is a Black Kite® risk intelligence marker that connects a global cyber threat to the specific vendors in your ecosystem affected by it. When a major vulnerability is actively exploited or a significant incident breaks, a FocusTag® identifies which of your third parties are exposed, down to the asset level, instead of telling you the threat exists.
The world doesn't wait, and neither should your cyber risk intelligence. Third-party risk programs have historically relied on vendors to self-report and then responded after the incident. FocusTags® invert that sequence by flagging affected vendors automatically, sometimes before those vendors know they're affected themselves.
What Is a FocusTag® and What Triggers One?
A FocusTag® is applied to the vendors affected by a specific, high-impact cyber event. It's triggered by events significant enough to demand action rather than by routine vulnerability disclosures, and Black Kite's research team decides what qualifies. Tags fall into four categories.
- Data breach tags: a confirmed breach at a vendor, or at a platform your vendors use, with downstream exposure.
- Ransomware tags: an active campaign or a group known to be operating against the affected software or sector.
- High-profile cyber event tags: an incident significant enough that boards and regulators will ask about it by name.
- KEV tags: a vulnerability listed in the CISA Known Exploited Vulnerabilities catalog, meaning exploitation is confirmed rather than theoretical.
The filter matters as much as the tag. Black Kite's 2026 Supply Chain Vulnerability Report puts the ratio in context. More than 48,000 CVEs were disclosed in 2025, an 18% increase over the prior year. Black Kite manually analyzed 1,240 high-priority ones, assigned 329 FocusTags®, and designated 58 as Code Red, meaning an imminent supply chain threat. A system that tagged everything would recreate the noise problem it exists to solve.
How Does a FocusTag® Turn a Global Threat Into a Vendor-Specific Finding?
They match the technical fingerprint of the threat against the observed attack surface of every vendor in your ecosystem. The tag isn't attached to the threat. It's attached to the vendors. That matching is the core of Black Kite's cyber risk intelligence capability.
When a qualifying event occurs, the affected software, service, or configuration is characterized in enough detail to be identified externally. That signature is matched against continuously collected data on your vendors. Vendors running the affected component, exposing the vulnerable service, or carrying the relevant misconfiguration are tagged, and the specific asset creating the exposure is identified with them.
That changes what you say to the vendor. Instead of asking "are you affected?" and waiting, you can tell them you've found a high-risk vulnerability affecting their systems. A vendor told they might be affected by a widely reported vulnerability will open a ticket and investigate for a week. A vendor told which of their hosts is running the exposed service can start remediating the same afternoon.
The SharePoint exploitation through the ToolShell remote code execution chain in 2025 illustrated the difference. Organizations with vendor-level visibility could name their exposed vendors while the advisory was still circulating. Organizations without it were emailing questionnaires into an actively exploited window.
What Makes a FocusTag® Risk Intelligence Rather Than Threat Intelligence?
A FocusTag® describes your ecosystem, not the world. That's the line between the two disciplines, and it's worth being precise about, because the terms get used interchangeably and should not be.
Threat Intelligence Describes the World
Threat intelligence is information about adversaries and their methods. Which groups are active, what they exploit, what they discuss on criminal forums. It's information about the world, and it's the same for every organization that receives it.
Risk Intelligence Describes Your Ecosystem
Risk intelligence maps that information onto your specific environment. A FocusTag® is the bridge between a global threat and your particular exposure. It doesn't tell you a breach is happening. It tells you where it's happening in your third parties, which vendor is affected, and which asset is the problem. Two organizations reading the same threat report get identical information. Two organizations looking at their FocusTags® get entirely different work.
How Do FocusTags® Change the First 48 Hours of a Vulnerability Response?
They remove the discovery phase, which is where most of the first 48 hours normally goes. In a conventional response, a team learns of a critical vulnerability, then spends days determining which vendors use the affected product, usually by sending questionnaires and waiting.
That sequence has an obvious flaw. The window in which a newly disclosed vulnerability is most dangerous is the same window the team spends asking who's affected. The timing data makes it worse than it sounds. Vulnerabilities are now exploited an average of seven days before public disclosure, and the median handoff from initial access to a ransomware operator has fallen to 22 seconds. Discovery by questionnaire loses that race before it starts.
Tagged Before the KEV Catalog Catches Up
Timing is also where the tag earns its keep. 95.2% of FocusTags® are applied before, or within 24 hours of, the vulnerability being added to the CISA KEV catalog. Combined with third party risk remediation through The Bridge™, findings go to the vendor with the technical context needed to fix them, and progress is tracked in one place rather than across an email thread.
How Do FocusTags® and the Vulnerability Intelligence Brief Work Together?
FocusTags® identify who is exposed. The Vulnerability Intelligence Brief™ explains how exploitable that exposure actually is. They answer sequential questions rather than competing ones.
Where a FocusTag® responds to an event already in motion, the VIB™ is proactive risk hunting. It combines EPSS, CVSS, KEV, and exploitability scoring to identify which vulnerabilities matter before they are weaponized, then shows which of your vendors run the affected software and how exploitable those specific instances are. A vendor running affected software behind compensating controls is a different problem from a vendor running it exposed to the internet with no authentication.
Used together they produce a defensible order of operations, and that order is what protects the downstream organization. Black Kite's 2026 Wholesale and Retail Cyber Exposure Report found 165 unique KEV vulnerabilities sitting in a single mapped supply chain, 24 of them already used in ransomware campaigns. When a vendor is compromised through one of them, the operational disruption, data exposure, and regulatory notification land on the customers behind that vendor rather than on the vendor alone.
See also: Microsoft SharePoint Under Siege: CVE-2025-53770 Exploited