A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the CIOReview Advisory Board.

LSEG

Are You Maximising The Benefit of Your Cyber Threat Intelligence?

Paul Kelly

Cyber Intelligence Optimizer

Cybersecurity threat intelligence (CTI) has become an essential part of modern cyber defence, as organisations seek to understand and respond to the increasingly complex and sophisticated threats facing them. CTI helps organisations identify and track potential threats, as well as provide real-time insights into emerging risks, by collecting and analysing data from multiple sources. However, organisations can often underestimate the full range of uses for CTI, limiting their ability to effectively manage their cybersecurity risks. In this article, we will explore two novel uses for CTI, which organisations may not have considered.

The first is Third Party Risk management. It’s a hot topic in many regulated industries. In particular, Financial Services where operational resilience regulations require more and more understanding of your third parties, the services they provide to you, and the connections you have to them. This covers not just vendors but the whole panoply of partners, affiliates, service providers, regulators, and anyone with whom your business has a connection or shares data. How do you currently approach this? Many organisations have some form of due-diligence questionnaire they ask their third parties to complete. Some even repeat the process on an annual basis. The question is though, is this really providing the insight you need to manage your risk?

Enter threat intelligence. A good CTI provider can provide you with a comprehensive view of the security posture of your third parties from the outside looking in. You can use this to shape the nature of your discussions with them. If there are anomalies in their attack surface, does this indicate a wider lack of security controls on the inside? It’s certainly a good place to start. But what about the long term? It’s worth considering adding threat intelligence into your strategy for monitoring third-party risk. An increased threat to one of your key suppliers or indeed a reduction in the efficacy of their attack surface management could be an indicator of the degradation of their controls more generally. What does that mean for your business? What does that mean for your risk? Is there anything you could do to compensate.?Your threat intelligence feed is not going to necessarily answer those questions for you, but it is going to help prompt you to ask them in sufficient time. Better to be alerted to a potential problem than become aware of it after the fact. In today’s modern dynamic threat environment can you really afford to just refresh your due diligence annually?

"A good CTI provider can provide you with a comprehensive view of the security posture of your third parties from the outside looking in"

The second use of CTI I’d like to explore is its potential use as a key component of cyber risk quantification. I would argue that these days cyber risk quantification is an important tool for CISOs. In particular, when communicating with the board; and of course, when negotiating for cyber insurance. In my mind there are two main types of CRQ, one is what could be called the ‘actuarial approach’ and the other the ‘fire-risk assessor’ approach. In the former, risk is quantified in the form of, “a business such as this, with these self-reported controls, and this level of NIST maturity is likely to lead to this level of exposure” (very much like the process to get your house insurance). In the latter, the risk is calculated through a detailed understanding of all assets and all controls inside the firm and likely uses a Mitre ATT&CK type framework to help calculate the likelihood of a breach and a detailed understanding of business revenue to calculate impact. (Not too dissimilar to a fire-risk inspector identifying lit candles next to curtains as a hazard and the business knowing the impact on revenue if the building burns down).

CTI has its role to play in both approaches. The first CTI can help with understanding the background threat level of similar businesses enabling a distinction between different sectors. The second CTI helps deliver a much more nuanced risk profile which reflects the exact nature of the risks the businesses face. Achieving this by using specific exploits and targeting information to inform the CRQ calculation, enables a more business-specific and efficient response to risk as well as gives the CISO confidence that what he or she is presenting to the board is an accurate rather than a generic reflection of the business’s position.

In conclusion, organisations can gain significant benefits from using CTI for third-party risk management and cyber risk quantification. By making the most of their CTI capabilities, organisations can better understand and respond to the threats they face, as well as manage their risks more effectively. Whether you are already using a threat feed or considering one, exploring these use cases can help you get the maximum value from your CTI investment.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.
Top