What does "cyber threat intelligence" mean?

The process manages the collection, analysis, integration and production of previously disjointed information for the purpose of extracting holistic, evidence-based insights regarding an organization's unique threat landscape. This intelligence can make a significant difference to the organization's ability to anticipate breaches before they occur, and its ability to respond quickly, decisively and effectively to confirmed breaches — proactively maneuvering defense mechanisms into place, prior to and during the attack.

36% of GISS respondents do not have a threat intelligence program

CTI focuses on identifying and analyzing the motivations, methods, capabilities and tools of adversaries who may seek to target an organization by pairing external analysis with data that was once segmented within the enterprise. While some organizations may choose to define CTI as solely a component or input driven service, it is important to note that a process based intelligence life cycle within an operational framework is required to deliver actionable results. Accordingly, a holistic CTI program consisting of processes for collecting, producing and disseminating tactical and strategic intelligence, continually augmented with timely situational awareness updates (also known as "current intelligence"), is required. This helps explain who the relevant adversary is, how and why they may be attacking the organization, what actions they could take following the initial compromise, where they may reside within the organization, and how to detect or respond to an attack.

EY's approach to cyber threat intelligence

Tactical intelligence
Strategic intelligence
Current intelligence

Intelligence reporting portals
Indicator repositories
Social media analysis
Threat intelligence platform
Indicator feeds and communities
Deep/dark web analysis
Visualization tools
Analysis platforms
Open source (OSINT) analysis
Open source (OSINT) analysis

Security operations support
Threat metrics and trending analysis
Business alignment
Attack campaigns
Social media
Indicator collection
Research, reporting and assessments
Risk assessments
Geopolitical events
Kill chain analysis
Prioritization
Threat modeling
Emerging capabilities
Hunting support
Decision support

EY's cybersecurity capabilities
EY's business resources

Information sharing partners and industry alliances
Security monitoring
Incident response
Vulnerability management
Attack and penetration
Active Defense
High value asset protection
Business SMRs
Industry SMRs
Regional SMRs

