We are engaged in an exponentially growing cyber war that we are visibly losing. Within the next 3 years it has been estimated that the global cost will equal, or overtake, the UK GDP, and it is clear that our defences are inadequate and often ineffective. Malware and ransomer-ware continue to extort more money, and cause damage and inconvenience to individuals, organisations and society, whilst hacker groups, criminals and rogue states continue to innovate and maintain their advantage. At the same time, our defences are subverted and rendered ineffective as we operate in a reactive and prescriptive, after the fact, mode with no foresight or anticipation. In any war it is essential to know and understand as much about the enemy as possible, it is also necessary to establish the truth and validity of any situation or development. Doing this in the cyber domain is orders of magnitude more difficult than the real world, but some of the relevant tools are now available or at an advanced stage of development. For example; fully automated fact checkers and truth engines have been demonstrated, whilst situational awareness technologies are commercially available. However, what is missing is some level of context assessment on a continual basis. Without this we will continue to be ‘blind-sided’ by the actions and developments of the attackers as they maintain their element of surprise along every line of innovation. What do we need? In short ; a Context Engine that continually monitors networks, servers, routers, machines, devices and people for anomalous behaviours that flag pending attacks as behavioural deviations that are generally easy to detect. In the case of attacker groups we have observed precursor events and trends in network activity days ahead of some big offensive. However, this requires a shift in the defenders thinking and operations away for the reactive and short term, to the long term continual monitoring, data collection and analysis in order to establish threat assessments on a real time. The behavioural analysis of people, networks and ITC, is at the core of our ‘Context Engine’ solution which completes the triangle of: Truth; Situation; Context Awareness to provide defenders with a fuller and transformative picture. Most of the known precursor elements of this undertaken have been studied in some depth, with some behavioural elements identified on real networks and some physical situations. The unknown can only add more accuracy!