Information Security Forum Launches - Threat Intelligence Report

The Information Security Forum (ISF), the world's leading, independent authority on cyber security and information risk management, recently released Threat Intelligence: React and Prepare, the organisation's latest report which equips organisations to gain value from threat intelligence by implementing the ISF Approach for Managing a Threat Intelligence Capability. 

Since its inception, threat intelligence has been growing in prominence. 

Most organisations have considered building a threat intelligence capability, however, many question the potential value. The answer lies in understanding how threat intelligence is produced and its content.

"While organisations continue to rely on well-established security practices, many are seeking additional ways to keep pace with the increasing torrent of attacks," said Steve Durbin, Managing Director, ISF. "To efficiently manage cyber risks, organisations must build an accurate view of the threats they face, their capabilities, intentions and actions, and respond accordingly. 

“Many organisations are looking to threat intelligence for this view of their adversaries, but often find it to be ill-defined, costly to buy or produce, and difficult to integrate into decision making. This leads to a failure to deliver the expected business aims."

Threat intelligence is information about past, present and predicted attacks against an organisation from adversarial threats and is produced through analysis of available information. 

This insight supports information security professionals to make better decisions when managing cyber risk and enables actions that prepare the organization to not only react to today's threats, but also prepare for the future. In today's climate of insecurity, threat intelligence is fast becoming a crucial tool which delivers advantage over adversaries and competitors.

However, ISF research has found that threat intelligence is failing to deliver on its promise. While 82% of ISF Members surveyed have a threat intelligence capability, with the remaining 18% planning to implement one in the next twelve months, only 25% of those surveyed believe their capability is fully delivering the expected business objectives. 

Threat Intelligence: React and Prepare addresses the five common problems that cause this failure and explains how to build and manage a threat intelligence capability which delivers palpable value. Only once these actions have been taken will threat intelligence deliver on its promised value, supporting those business goals which so often remain unfulfilled.

"While threat intelligence seldom leads to control over adversaries, it enables the organisation to make more informed decisions in the areas it does control, the vulnerabilities and associated business impact," continued Durbin. "To ensure threat intelligence delivers value, we recommend that organisations use the ISF Approach for Managing a Threat Intelligence Capability, which provides the ISF definition for threat intelligence, reinforced by three key concepts: the production, content and use of threat intelligence. 

“The ISF Approach for Managing a Threat Intelligence Capability uses the intelligence cycle to produce threat intelligence which meets the requirements to inform decisions and enable actions. It also addresses a number of practical considerations which affect the management of a threat intelligence capability." 

Organisations must prepare themselves for unprecedented levels of collaboration to counter threats. Innovations such as machine learning, big data and predictive analytics are already being explored by leading organisations to transform threat intelligence capabilities. 

The ISF Approach for Managing a Threat Intelligence Capability explains the concepts of effective threat intelligence and how they can be achieved using the intelligence cycle. Requirements-driven and skillfully produced through analysis, threat intelligence harnesses the expertise and experience of others to provide insight into past, present and predicted attacks against an organisation. 

Threat Intelligence: React and Prepare is aimed at senior business executives, up to and including board level, who are considering, planning, building or operating a threat intelligence capability. 

Founded in 1989, the Information Security Forum (ISF) is an independent, not-for-profit association of leading organisations from around the world. The organisation is dedicated to investigating, clarifying and resolving key issues in cyber, information security and risk management and developing best practice methodologies, processes and solutions that meet the business needs of its Members.

ISF Members benefit from harnessing and sharing in-depth knowledge and practical experience drawn from within their organizations and developed through an extensive research and work program. The ISF provides a confidential forum and framework, which ensures that Members adopt leading-edge information security strategies and solutions.

By working together, ISF Members avoid the major expenditure required to reach the same goals on their own. Consultancy services are available and provide ISF Members and Non-Members with the opportunity to purchase short-term, professional support activities to supplement the implementation of ISF products.

PR Log:

You Might Also Read:

Getting Threat Intelligence Right:

How To Integrate Threat Intelligence:

Threat Intelligence Starter Resources:

 

« UK Fraud Hotspots Revealed
IoT Will Change (Almost) Everything In Cybersecurity »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Resecurity, Inc.

Resecurity, Inc.

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

FT Cyber Resilience Summit: Europe

FT Cyber Resilience Summit: Europe

27 November 2024 | In-Person & Digital | 22 Bishopsgate, London. Business leaders, Innovators & Experts address evolving cybersecurity risks.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

CloudSigma

CloudSigma

CloudSigma, a pure-cloud IaaS provider offers flexible and innovative cloud hosting solutions for companies of all sizes both in Europe and the US.

Cyber Security Audit Corp (C3SA)

Cyber Security Audit Corp (C3SA)

C3SA specializes in architecting, operating, managing and improving defensible and resilient IT infrastructures for Canada's public and private sectors.

Clari5

Clari5

Clari5 redefines real-time, cross channel banking Enterprise Fraud Management using a central nervous system approach to fight financial crime.

IXDen

IXDen

IXDen provides a novel software-based approach to OT systems protection, covering Industrial IoT cybersecurity and sensor data integrity.

InterVision

InterVision

InterVision is a leading Strategic Services Provider, assisting businesses in driving value and gaining a competitive edge by helping IT Leaders solve the most crucial challenges they face.

Centre for Multidisciplinary Research, Innovation & Collaboration (C-MRiC)

Centre for Multidisciplinary Research, Innovation & Collaboration (C-MRiC)

C-MRiC collaborates on initiatives, ranging from national cyber security, enterprise security, information assurance, protection strategy, climate control to health and life sciences.

GuardRails

GuardRails

GuardRails provides continuous security feedback that empowers developers to find, fix, and prevent vulnerabilities.

MPC Alliance

MPC Alliance

A consortium of developers and practitioners of multiparty computation (MPC), committed to accelerating market awareness and adoption of MPC to increase the security and privacy of online services.

Visible Statement

Visible Statement

Visible Statement is a computer-based delivery system designed to insure the retention and recall of your most important security training messages.

VLATACOM Institute

VLATACOM Institute

Vlatacom Institute is privately owned accredited research and development institute, system integrator and turn-key solution provider. Areas of expertise include encryption and authentication.

TryHackMe

TryHackMe

TryHackMe is an online platform that teaches cyber security through short, gamified real-world labs. We have content for both complete beginners and seasoned hackers.

FiVerity

FiVerity

FiVerity provides financial institutions with cyber fraud defense to combat a dangerous and growing threat - the convergence of fraud-related theft with sophisticated, high-volume cyber attacks.

Trellix

Trellix

Trellix is an extended detection and response (XDR) solutions provider created from a merger of McAfee Enterprise and FireEye Products.

Schillings

Schillings

Shillings defends your rights to privacy, reuptation and security. We fight passionately against breaches of your privacy, attacks on your reputation and threats to your security.

Casepoint

Casepoint

Casepoint is the legal technology platform of choice for corporations, government agencies, and law firms to meet their complex eDiscovery, investigations, and compliance needs.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.