P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Threat intelligence

Cyber threat intelligence

Threat intelligence scoped to actual exposure, in language a board can act on: adversary tracking, sector reporting, and intelligence that changes a decision rather than filling a feed.

Most threat intelligence is either a feed of indicators nobody has time to action, or a vendor report about an adversary that has never shown interest in your sector. Both feel like intelligence and neither changes a decision. Useful CTI starts from what you hold that somebody would want, and works outwards to who has historically gone after it and how.

2

Reports, one analysis

Technique detail and board consequence are different documents.

ICS

ATT&CK coverage where needed

Enterprise ATT&CK does not describe the plant floor.

5

Steps in the intelligence cycle

Feedback is the one commercial CTI usually skips.

CTI

Volunteer CSFI team lead

Including published adversary research.

What it uses

MITRE ATT&CK

Technique-level grounding so a finding connects to a detection you can build, rather than to a threat actor name that means nothing operationally.

ATT&CK for ICS

Where there is an operational technology estate, because enterprise ATT&CK does not describe what happens below the plant boundary.

Priority intelligence requirements

The discipline that separates intelligence from volume: the programme answers questions somebody actually asked.

The intelligence cycle

Direction, collection, analysis, dissemination, feedback. The last step is the one commercial CTI usually omits, and it is the one that improves the next cycle.

How the work runs

  1. 1

    Establish what is worth taking

    Data, access, or disruption. The answer determines which adversaries are relevant and rules out most of them.

  2. 2

    Map the exposure from outside

    What is reachable, what your suppliers expose on your behalf, and what your people have published without thinking about it.

  3. 3

    Scope the adversary set

    By sector and geography, with a stated basis for inclusion. A named actor with no history in your sector is noise wearing a costume.

  4. 4

    Translate to technique

    Adversary behaviour mapped to ATT&CK, so the output is a list of things to detect rather than a list of things to worry about.

  5. 5

    Report twice

    Technique detail for the security team, consequence for the board. Same intelligence, two documents, because one audience cannot use the other's version.

  6. 6

    Close the loop

    What was actioned, what was not, and what that says about the next set of requirements.

What you walk away with

  • An external exposure picture, including supplier-side exposure
  • A scoped adversary set with the reasoning for inclusion and exclusion
  • Technique-level findings mapped to MITRE ATT&CK, and to ATT&CK for ICS where relevant
  • Detection recommendations tied to specific techniques
  • Board-level reporting written in consequence terms
  • Priority intelligence requirements to direct the next cycle

How this plays out

Example scenario

An organisation subscribing to three commercial intelligence feeds.

The work: Review of what had been actioned over six months.

Almost nothing, because nothing was scoped to them. The subscriptions were replaced with a smaller set of standing requirements and the budget fell.

Example scenario

A manufacturer worried about a widely reported state actor.

The work: Historical targeting analysis for their sector and size.

No credible history of interest. The realistic threat was commodity ransomware through a supplier remote access route, which nobody had been briefed on.

Example scenario

A board asking whether they were a target.

The work: Exposure-first assessment rather than an adversary-first one.

A short answer they could act on, and the recognition that the more useful question is what an attacker would reach once inside.

Start the conversation

A question about this area, an invitation to speak, or a role you think fits: write, and you will get a straight answer.

Get in touch

Share this

Send it to whoever owns the budget or the risk.

← All areas

The problem

Most threat intelligence is either a feed of indicators nobody has time to action, or a vendor report about an adversary that has never shown interest in your sector. Both feel like intelligence and neither changes a decision.

Useful CTI starts from what you have that somebody would want, and works outwards to who has historically gone after it and how. That is a smaller, sharper question than "what are the current threats".

What you get

  • A picture of your exposure from an attacker's side: what is reachable, what is valuable, and what your suppliers expose on your behalf
  • Adversary tracking scoped to your sector and geography, mapped to MITRE ATT&CK so findings connect to detections you can actually build
  • Reporting written twice: technique-level detail for the security team, and consequence-level briefing for the board
  • Priority intelligence requirements, so the programme answers questions somebody asked rather than producing volume
  • Where relevant, ATT&CK for ICS coverage for operational technology estates

Proof point

Volunteer Cyber Threat Intelligence Team Lead at CSFI, with published adversary research including a 24-page bulletin on Iranian APT activity. Intelligence delivered by the person who wrote it, not a report handed on.