{"id":13807,"date":"2022-11-04T19:01:01","date_gmt":"2022-11-04T19:01:01","guid":{"rendered":"https:\/\/v3it.com\/blog\/?p=13807"},"modified":"2022-11-07T19:30:12","modified_gmt":"2022-11-07T19:30:12","slug":"what-is-cyber-threat-intelligence","status":"publish","type":"post","link":"https:\/\/v3it.com\/blog\/what-is-cyber-threat-intelligence\/","title":{"rendered":"WHAT IS CYBER THREAT INTELLIGENCE?"},"content":{"rendered":"\n<p class=\"has-text-align-justify wp-block-paragraph\">Threats to cybersecurity, such as ransomware, DDoS attacks, security breaches, data thefts, and malware attacks, are becoming more frequent across the globe. Based on studies conducted by Ponemon Institute, the average cost of a data breach is $242 per record. The companies on an average lose more than $8 million in every single data breach. Hence being reactive in addressing these challenges is not an effective strategy anymore and organizations are slowly realizing that. They must take proactive steps by building robust and secure systems by investing in threat detection and response technologies. Threat intelligence programs are becoming more crucial than ever in order to identify and prevent cyberattacks before they happen, to minimize the damage.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In this blog we will discuss about what is threat intelligence, it\u2019s types and threat intelligence lifecycle.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"625\" height=\"345\" data-attachment-id=\"13810\" data-permalink=\"https:\/\/v3it.com\/blog\/what-is-cyber-threat-intelligence\/cloud-based-cybersecurity-solutions-secure-corporate-and-insti-2\/\" data-orig-file=\"https:\/\/i0.wp.com\/v3it.com\/blog\/wp-content\/uploads\/2022\/11\/cyber-threat-intelligence-1.jpg?fit=2000%2C1106&amp;ssl=1\" data-orig-size=\"2000,1106\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;Cloud-based Cybersecurity Solutions - Secure Corporate and Institutional Networks - Endpoint Protection - Security Service Edge and Secure Access Service Edge - 3D Illustration&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;Cloud-based Cybersecurity Solutions - Secure Corporate and Insti&quot;,&quot;orientation&quot;:&quot;1&quot;}\" data-image-title=\"Cloud-based Cybersecurity Solutions &amp;#8211; Secure Corporate and Insti\" data-image-description=\"\" data-image-caption=\"&lt;p&gt;Cloud-based Cybersecurity Solutions &amp;#8211; Secure Corporate and Institutional Networks &amp;#8211; Endpoint Protection &amp;#8211; Security Service Edge and Secure Access Service Edge &amp;#8211; 3D Illustration&lt;\/p&gt;\n\" data-large-file=\"https:\/\/i0.wp.com\/v3it.com\/blog\/wp-content\/uploads\/2022\/11\/cyber-threat-intelligence-1.jpg?fit=625%2C345&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/v3it.com\/blog\/wp-content\/uploads\/2022\/11\/cyber-threat-intelligence-1.jpg?resize=625%2C345&#038;ssl=1\" alt=\"Cyber Threat Intelligence\" class=\"wp-image-13810\" srcset=\"https:\/\/i0.wp.com\/v3it.com\/blog\/wp-content\/uploads\/2022\/11\/cyber-threat-intelligence-1.jpg?resize=1024%2C566&amp;ssl=1 1024w, https:\/\/i0.wp.com\/v3it.com\/blog\/wp-content\/uploads\/2022\/11\/cyber-threat-intelligence-1.jpg?resize=300%2C166&amp;ssl=1 300w, https:\/\/i0.wp.com\/v3it.com\/blog\/wp-content\/uploads\/2022\/11\/cyber-threat-intelligence-1.jpg?resize=768%2C425&amp;ssl=1 768w, https:\/\/i0.wp.com\/v3it.com\/blog\/wp-content\/uploads\/2022\/11\/cyber-threat-intelligence-1.jpg?resize=1536%2C849&amp;ssl=1 1536w, https:\/\/i0.wp.com\/v3it.com\/blog\/wp-content\/uploads\/2022\/11\/cyber-threat-intelligence-1.jpg?resize=624%2C345&amp;ssl=1 624w, https:\/\/i0.wp.com\/v3it.com\/blog\/wp-content\/uploads\/2022\/11\/cyber-threat-intelligence-1.jpg?w=2000&amp;ssl=1 2000w, https:\/\/i0.wp.com\/v3it.com\/blog\/wp-content\/uploads\/2022\/11\/cyber-threat-intelligence-1.jpg?w=1250&amp;ssl=1 1250w, https:\/\/i0.wp.com\/v3it.com\/blog\/wp-content\/uploads\/2022\/11\/cyber-threat-intelligence-1.jpg?w=1875&amp;ssl=1 1875w\" sizes=\"auto, (max-width: 625px) 100vw, 625px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"has-text-align-justify wp-block-paragraph\"><strong><span style=\"text-decoration: underline;\">WHAT IS THREAT INTELLIGENCE<br><\/span><\/strong>Threat intelligence is evidence-based knowledge, including context, mechanisms, indicators, implications and action-oriented advice about an existing or emerging menace or hazard to assets. This information is then used to inform decisions regarding the subject\u2019s response to that hazard, according to Gartner.<\/p>\n\n\n\n<p class=\"has-text-align-justify wp-block-paragraph\">The information that enables organizations to take proactive steps to prevent or minimise the effect of cyber-attacks is threat intelligence. It includes information about potential attackers, their intent, indicators of compromise. These insights can help organizations make quick &amp; informed security decisions in case of cyber threats.&nbsp;<\/p>\n\n\n\n<p class=\"has-text-align-justify wp-block-paragraph\">The development of threat intelligence is a circular and continuous process known as the Intelligence Cycle. Intelligence about attacks alone will not serve the purpose. Organizations should implement the correct tools &amp; strategies to safeguard their data, operations and customers.<\/p>\n\n\n\n<p class=\"has-text-align-justify wp-block-paragraph\"><strong><span style=\"text-decoration: underline;\">WHY IS THREAT INTELLIGENCE IMPORTANT AND WHO BENEFITS FROM IT?<\/span><\/strong><br>To learn more about threats, create robust security strategies, and mitigate attacks before happening, organizations leverage the key data about threat actors. According to Grand View Research, the threat intelligence market is expected to grow at 17.4% CAGR from 2017 to 2025. It would potentially earn revenues of nearly $12.6 billion in 2025.<\/p>\n\n\n\n<p class=\"has-text-align-justify wp-block-paragraph\">The security measures of most organizations are also weakened because of huge amounts of data and shortage of skilled cybersecurity professionals. It leads to a gap between what threats should be addressed and what the organization is capable of addressing. It certainly leads to situations where serious threats are not noticed. Most SOC teams can only investigate 56% of alerts, while only 34% of them are legitimate. The security experts spend about 25% of their time investigating false positives, according to Ponemon Institute studies. These indicates wastage of time and resources, and dissolves the purpose of cybersecurity programs. A&nbsp;cyber threat intelligence solution&nbsp;should address such issues and strengthen the security by identifying the intent, motivation of attackers, actions to minimise such attacks, integrating disparate data to give timely warnings, and promoting proactive decision making.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Threat intelligence benefits everyone involved in security:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Security Analysts<\/strong>: It improves the cyber defense strategies of organizations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Intelligence Analyst<\/strong>: It helps in identifying threat actors to stop the misuse of information assets.<\/p>\n\n\n\n<p class=\"has-text-align-justify wp-block-paragraph\"><strong>Computer Security Incident Response Team (CSIRT)<\/strong>: It looks into incident investigations, and analyses threats to mitigate the losses.<\/p>\n\n\n\n<p class=\"has-text-align-justify wp-block-paragraph\"><strong>SOC<\/strong>: It provides solutions to strengthen internal warnings, alerts and enable better incident response.<\/p>\n\n\n\n<p class=\"has-text-align-justify wp-block-paragraph\">Threat intelligence is also important for executive leadership. It empowers them to understand cyber risks &amp; make data-driven decisions to reduce their impact.<\/p>\n\n\n\n<p class=\"has-text-align-justify wp-block-paragraph\"><strong><span style=\"text-decoration: underline;\">THE THREAT INTELLIGENCE LIFECYCLE<\/span><br><\/strong>The process of understanding, analyzing, prioritizing and utilizing threat information is not a linear one-time process, but it is part of a continuous lifecycle. A threat intelligence strategy that uses Machine Learning is iterative &amp; adapting to strengthen the security techniques of an organization and enables security experts to maximize the value of the intel they receive. The threat intelligence lifecycle has following six phases:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>REQUIREMENTS GATHERING AND PLANNING<\/strong><\/p>\n\n\n\n<p class=\"has-text-align-justify wp-block-paragraph\">The security teams set the objectives, align them with the core vision of the organization, and predict the impact of decisions made based on this intelligence. They also uncover information about threat actors, magnitude of the attack, and methods to increase security.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>DATA COLLECTION<\/strong><\/p>\n\n\n\n<p class=\"has-text-align-justify wp-block-paragraph\">After the requirements are gathered, the team collects relevant threat data. This may include indicators of compromise (like malicious IP addresses, emails, URLs and domains) or other vulnerable information. This data is collected by looking at multiple sources such as, network event logs, traffic logs, open web, dark web, social media, paste sites, industry thought leaders, subject matter experts, etc.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>DATA PROCESSING<\/strong><\/p>\n\n\n\n<p class=\"has-text-align-justify wp-block-paragraph\">The data gathered in previous stage is sorted, organized and filtered to support further analysis. The redundant, irrelevant information is removed and metadata tags are added. The manual process of adding data to spreadsheets, encrypting, decrypting files is automated.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>DATA ANALYSIS<\/strong><\/p>\n\n\n\n<p class=\"has-text-align-justify wp-block-paragraph\">The processed data is now analyzed in this stage. The teams understand the data, check whether the data satisfies the requirements identified in the first stage, and identify for potential security risks.&nbsp;The data is then converted into a format (report, presentation deck, threat list) the senior executives can understand. The security experts highlight the key action items to mitigate threats.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>DISSEMINATION<\/strong><\/p>\n\n\n\n<p class=\"has-text-align-justify wp-block-paragraph\">The results from analysis stage are presented to the stakeholders. Every piece of intelligence is tracked to maintain continuity between threat intelligence cycles.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>FEEDBACK AND ADJUSTMENTS<\/strong><\/p>\n\n\n\n<p class=\"has-text-align-justify wp-block-paragraph\">After the reports are presented, stakeholder feedback is solicited to determine any changes to objectives, threat intelligence operations and procedures and priorities.<\/p>\n\n\n\n<p class=\"has-text-align-justify wp-block-paragraph\"><strong><span style=\"text-decoration: underline;\">THREE TYPES OF THREAT INTELLIGENCE<br><\/span><\/strong>Each threat type has a different purpose and is aimed at a specific audience. The threat intelligence types are:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>STRATEGIC THREAT INTELLIGENCE<\/strong><\/p>\n\n\n\n<p class=\"has-text-align-justify wp-block-paragraph\">Key audience: Senior\/C-Suite managers (CISO, CTO, etc.), company board members.<br>What it does: It provides a big picture of the organization\u2019s threat landscape, threat actors, risks and trends. This intelligence is less technical since the target audience is stakeholders.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>OPERATIONAL (TECHNICAL) THREAT INTELLIGENCE<\/strong><\/p>\n\n\n\n<p class=\"has-text-align-justify wp-block-paragraph\">Key audience: Threat hunters, CSIRT, SOC analysts, vulnerability management teams.<br>What it does: This focuses on understanding important operational aspects, including threat actor capabilities, infrastructure and TTPs. It includes technical information from threat intelligence feeds. The security teams use this to optimize cybersecurity operations with targeted actions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>TACTICAL THREAT INTELLIGENCE<\/strong><\/p>\n\n\n\n<p class=\"has-text-align-justify wp-block-paragraph\">Key audience: SOC analysts, system architects, SIEMs, firewalls, endpoints.<br>What it does: This includes contextual information about TTPs and targeted vulnerabilities. The security teams use this to understand threat vectors and mitigate potential attacks. The teams leverage this information to strengthen existing security controls and accelerate incident response.<\/p>\n\n\n\n<p class=\"has-text-align-justify wp-block-paragraph\">Cyber Threat Intelligence&nbsp;has become crucial in our globally expanding threat landscape. With targeted proactive threat intelligence, organizations can make their security systems more robust as well as mitigate the risks that could damage their reputation and financial health, thus keeping them few steps ahead of cybercriminals.<\/p>\n\n\n\n<p class=\"has-text-align-justify wp-block-paragraph\"><a href=\"http:\/\/www.v3it.com\" target=\"_blank\" rel=\"noreferrer noopener\">V3iT<\/a>\u2122 will help you in protecting your systems from&nbsp;targeted attacks. You can either implement your own custom solution or use cyber threat intelligence feed. <a rel=\"noreferrer noopener\" href=\"http:\/\/www.v3it.com\" target=\"_blank\">Contact us<\/a>&nbsp;today to learn about&nbsp;V3iT\u2122&nbsp;services and solutions &amp;&nbsp;how we can help your business.<\/p>\n\n\n\n\n","protected":false},"excerpt":{"rendered":"<p>Threats to cybersecurity, such as ransomware, DDoS attacks, security breaches, data thefts, and malware attacks, are becoming more frequent across the globe. Based on studies conducted by Ponemon Institute, the&#8230; <a href=\"https:\/\/v3it.com\/blog\/what-is-cyber-threat-intelligence\/\">Read more &raquo;<\/a><\/p>\n","protected":false},"author":9,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"nf_dc_page":"","_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"jetpack_post_was_ever_published":false},"categories":[58,100,102,101,1],"tags":[],"class_list":["post-13807","post","type-post","status-publish","format-standard","hentry","category-artificial-intelligence","category-cyber-attack","category-cyber-awareness","category-cyber-security","category-other"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p7GsDS-3AH","jetpack-related-posts":[],"_links":{"self":[{"href":"https:\/\/v3it.com\/blog\/wp-json\/wp\/v2\/posts\/13807","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/v3it.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/v3it.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/v3it.com\/blog\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/v3it.com\/blog\/wp-json\/wp\/v2\/comments?post=13807"}],"version-history":[{"count":3,"href":"https:\/\/v3it.com\/blog\/wp-json\/wp\/v2\/posts\/13807\/revisions"}],"predecessor-version":[{"id":13812,"href":"https:\/\/v3it.com\/blog\/wp-json\/wp\/v2\/posts\/13807\/revisions\/13812"}],"wp:attachment":[{"href":"https:\/\/v3it.com\/blog\/wp-json\/wp\/v2\/media?parent=13807"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/v3it.com\/blog\/wp-json\/wp\/v2\/categories?post=13807"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/v3it.com\/blog\/wp-json\/wp\/v2\/tags?post=13807"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}