Demystifying cyber threat intelligence: A first-principles approach to capability development and vendor evaluation
Abstract
Cyber threat intelligence (CTI) is considered an essential element of a robust cyber security programme. Given the relative nascency of the discipline, however, there is a degree of ambiguity among the community around what it takes to establish a credible CTI capability in support of the cyber security mission. At the same time, there is now a thriving industry offering commercial CTI products and services in support of the customer’s capability development efforts, with many instances of opportunistic vendors poised to exploit this fledgling market. This has spurred the growth of research and advisory companies that attempt to present an objective review and offer guidance around CTI vendor selection. Their perspective, however, is often heavily influenced by a small group of select vendors and the evaluation criteria is often incomplete and skewed towards the participating vendors. This paper makes the case for a first-principles approach that CTI teams can adopt as an unbiased anchor to guide their decisions around establishing an adequate CTI capability, and offers pragmatic recommendations to assist CTI teams with qualifying their prospective vendors to ensure good fit. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
The full article is available to subscribers to the journal.
Author's Biography
Aaron Aubrey Ng is a Senior Systems Engineer at CrowdStrike where he advises customers on their security needs and solutions. He is based in Dubai and supports the CrowdStrike business across the Middle East, Turkey, and Africa (META) region. Prior to his current role, Aaron served as a Strategic Threat Adviser, in which capacity he evangelised for the adoption of cyber threat intelligence to organisations across the public and private sectors in Asia Pacific and META. Prior to industry, Aaron served 12 years of active duty in the Singapore Armed Forces (SAF) as an Intelligence Officer, where he garnered experience in strategic planning and policy development and was instrumental in developing the masterplan for the digital service branch of the SAF. Outside of work, Aaron contributes to cyber security research and education. He has collaborated with the Stanford Gordian Knot Center for National Security Innovation on research covering emergent threats. Aaron serves as Adjunct Faculty at the Faculty of Computer Information Science of the Higher Colleges of Technology in the UAE. He sits on the CFP Review Board for RootCon in the Philippines and is a Goon at DEFCON Singapore.