Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Printer to Shredder – The Problem of Threat Intelligence
News & Analysis

Printer to Shredder – The Problem of Threat Intelligence

ISBuzz TeamBy ISBuzz TeamFebruary 12, 2015Updated:July 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
threat intelligence
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

You’re an IT executive, and your company receives regular cyber intelligence updates. They land in your inbox (or have been forwarded to you by your managers, flagged “urgent”) every once in a while. When opening one, you can find a brief summary of current events or alerts and an attachment, usually a PDF document. If it’s over 10 pages long, you will then print this and then… well, most likely keep it on your desk for several days. If you have some spare time you might even gaze into this document and maybe even highlight a paragraph or two for future use. But most likely, you will either ask one of your subordinates to read and summarize it for you or never look at this again before finally shredding it.

I know because in my previous job I’ve sold these exact reports.

Free eBook: Modern Retail Security Risk – Get your copy now.

And it was difficult since most potential customers were reluctant to pay for something they did not fully understand its need or value. But the really sad fact was that even the clients who were paying for this service were hardly gaining any benefit from using it. Some upon renewal said it was a complete waste of money, but he renewed anyway because, like insurance, deciding to stop buying it was psychologically more difficult than doing a proper Risk vs. Value estimation.

In short, most reports were hardly read and acted upon, and very little value was gained by the customers. I was baffled by this for a long time until I started to put myself in the clients’ shoes. If a report or an alert contained a specific, relevant piece of information pertaining to their organization, they all knew what to do: either block a specific IP address or range of IP addresses, or prepare for a hacktivist attack which would likely happen in exactly 48 hours. But if the intelligence wasn’t so specific, which was the case in about 99% of times, they had very little use of the information.

A new malware variation being sold on the underground? So what.

A new global APT campaign targeting their (and 5 other) industries? So what.

A discussion in a Blackhat forum about breaching the chip & pin system? So what…

In fact, I’ve heard the “so what” question so many times that it made me think, “What do we expect the IT security staff and management to do with a piece of non-specific information?”

One CISO even said to me once: “What do you expect me to do now that I know this new piece of troubling intelligence? Sleep less at night?”

You know what? He was right. If it wasn’t relevant or actionable, he couldn’t care less. He can’t configure new SIEM rules, he can’t patch systems (which their software maker are not yet aware of this new threat), and he can’t instruct his people to do things differently because some schmuck on the Underground asked for help in developing a new breed of POS malware.

But relevant and specific intelligence is very rare, so what are we to do? Ignore (or shred) all non- relevant information? Dilemma indeed. It seems the threat intelligence has an inherent “last mile gap” in its value proposition. So I would like to propose a different paradigm, one which will broaden the definitions of relevancy and actionability and could actually make sense to customers.

To begin with, customers need to be willing to except that not all applicable intelligence is specific. We would all love to find this incredibly sexy piece of intelligence which will alert the customers about an elaborate scheme to target their IT infrastructure by a cybercriminal mastermind, but the reality is that even if such campaign were taking place, it would be extremely difficult to send out an alert about it before or even during the activity. So instead of focusing on the 0.0001%, let’s try to use all the rest of the information which is out there and check the relevancy not by a direct link to the target/ victim but by a broader definition of industry and geography. For instance, when we stumble upon an intelligence alert about new cybercrime activity, we need to ask if it’s aimed at my industry (retail, healthcare, etc.), my geography (N. America, West Europe or even global) and my business assets (PII, transactions, IP, etc.). If the answer is yes to all, then it is relevant and should be taken into consideration. Taking this further, if we collect enough information from various sources, we can even identify geographical- and industry-related trends, which could be used for strategic decision-making.

So turning our attention now to the actionability question – how do we utilize this intelligence?  I believe that being actionable answers two questions:

What do I do now?

What do I do tomorrow (or next week, or next month)?

To read the answers to these questions, please view the remainder of the article on Cytegic’s blog here.

About Cytegic

cytegicCy-te-gic /pronounced: sʌɪ-ˈtē-jik/ adjective: A plan of action or strategy designed to achieve a long-term and overall successful Cyber Security Posture Optimization – “That firm made a wise Cytegic decision”.

Cytegic develops a full suite of cyber management and decision-support products that enable to monitor, measure and manage organizational cyber-security resources.

Cytegic helps organization to identify threat trends, assess organizational readiness, and optimize resource allocation to mitigate risk for business assets.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}