Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - 5 Myths about Threat Intelligence
Articles

5 Myths about Threat Intelligence

ISB Editorial StaffBy ISB Editorial StaffJuly 20, 20155 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
equation malware
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

In the spirit of The Washington Post’s regular column, “5 Myths,” here is “a challenge to everything you think you know” about Threat Intelligence.

You may already know that cyber threat intelligence from both internal and external sources can provide value when it is researched, analyzed and disseminated correctly. The benefits include:

  • Changing an organization’s security model from reactive to proactive
  • Shrinking the security alert problem that is overwhelming most security teams
  • Driving better, more informed responses to security incidents
  • Extending the life of aging security technologies and turbo charging new defenses by feeding them real-time intelligence updates to enable blocking of rapidly emerging threats
  • Enhancing communications between the security team, management and board members
  • Driving better investment strategies and more directly connecting security priorities with business risk management priorities

Marketing departments would have you believe, it’s easy.  Just sign this Purchase Order and the magic happens. Here are 5 myths about Threat Intelligence.

  1. You can buy it

Actually you can only buy threat data feeds. Converting this “data” to intelligence requires many steps. You have to collect data from your network, match against the threat data feed, examine matches for validity, weed out false positives, investigate the remainder and apply remediation.

  1. More expensive is better

This one is obvious – only if it is relevant to your needs. For example, a high quality feed about threats that your organization does not face is not very useful. For example, is it meaningful to you to get great intel on the threat landscape local to Uzbekistan? Not unless you have network assets there. Most feeds cover specific activities, technologies, and industries. Just because they are high quality, it doesn’t follow they are useful to your organization.

Also ask the question if you can actually use what information is provided. For example, a feed that updates by the minute requires that you be able to act immediately on notification. However, if you can only act the following business day (lack of dedicated staff?), then why pay for the real time update?

You may have heard “the best things in life are free.” It can be true in the case of Threat Intel feeds.

  1. It’s a one-time cost

See the answer to #1 above. Feed data updates regularly. Applying it to your local environment is also a continuous process. The one-time cost is to buy a subscription to a data feed. Security, you may have heard, is a process, not a project.

An easy comparison is to vulnerability scan results. Users of such products will quickly recognize that one must carefully tune the tests that the scanner runs to avoid disrupting or crashing some products (one just can’t enable a test against all endpoints). Further, many results must be masked because they cannot be remediated for good reasons and a compensating control may have been applied. These are all ongoing costs.

  1. The benefits are automatic 


Actually no. In order to get benefits from threat intelligence feeds, a series of steps must be completed as outlined above, mostly in the area of tuning the feeds to eliminate false positives. Most Intrusion Detection System (IDS) users will recognize this problem easily. Enable an IDS with all available data feeds and you will get bombarded with false positives, and likely get depressed that the process is not “automatic.” Obtaining value from such feeds requires attention and tuning.

  1. It’s easy to use

While threat intelligence may be easy to incorporate into any product, by itself it’s not inherently “easy to use.” That depends on the device that is using threat intelligence. For example, many Next Generation Firewalls (NGFW) offer subscriptions to threat intelligence.  They update themselves and take the configured action (report or block undesirable traffic). However, it is still up to the administrator to review these alerts for correct behavior. Administrators of anti-spam devices or proxy servers will quickly recognize this. Those devices also incorporate threat intelligence but require review for proper functioning.

Threat intelligence is a crucial need for any organization, but it isn’t a one-size-fits-all proposition, nor is it a plug and play way to secure data.  Businesses and their IT teams must understand that security is a process, one that is grown out of attention to need and should come complete with an administrator to oversee  anomalies.  Once organizations better understand this fact, we’ll be well on our way to data security.[su_box title=”About A.N. Ananth” style=”noise” box_color=”#336588″]A. N. AnanthAs the co-founder and CEO of EventTracker, A.N. Ananth was one of the original architects of the EventTracker product, an enterprise log management solution. With an extensive background in product development and operations for telecom network management, he has consulted for many companies on their compliance strategies, audit policies, and automated reporting processes. He is a leading expert in IT compliance, with more than 20 years’ experience in IT-control and operations, and he speaks frequently on these topics. Ananth was involved in product development for various companies including Ciena, Westinghouse Wireless, and Equatorial Communications. He holds an MSEE from the University of Texas and remains active in strategic product direction at EventTracker.[/su_box]

ISB Editorial Staff
  • ISB Editorial Staff
    Navigating the Cyber Threat Landscape: Key Insights from Trellix ARC’s Q1 2023 Report
  • ISB Editorial Staff
    Experts’ Responses: Cyber Security Predictions 2022
  • ISB Editorial Staff
    ISB Virtual Conference: Key Cyber Security Challenges and Solutions in 2021
  • ISB Editorial Staff
    Cyber Security Predictions 2021: Experts’ Responses

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}