Share these talks and lectures with your colleagues
Invite colleaguesIntelligence led risk: Leveraging threat operations to deliver effective risk management
Abstract
Cyberattacks pose a significant threat to organisations, presenting substantial business risks. Chief executive officers (CEOs) and boards must allocate investments to mitigate these risks effectively. Many leaders, however, struggle to incorporate cyber risk into their broader enterprise risk management strategies, often citing its technical complexity as a challenge. Yet, other risks — such as regulatory or financial — are also technical but do not face the same integration difficulties. This paper contends that cyber risk is challenging not due to its technical nature, but because it is non-deterministic. Unlike other risks, cyberattacks stem from human actions. Humans are unpredictable with diverse motivations, therefore estimating the likelihood of a cyber event is inherently more difficult than forecasting other more deterministic risks. Traditionally, threat operations teams focus on operational goals such as improving protective monitoring and strengthening security architecture. By assessing the intent, capability and opportunity of threats, however, these teams can also aid leadership in evaluating the probability of cyber incidents causing an impact, thereby enhancing overall risk management. This paper introduces a threat operations framework that integrates threat intelligence, hunting and emulation to provide a more precise likelihood assessment. By developing ‘cyber narratives’, these teams can translate technical risks into business risks, offering strategic insights for informed decision making.
The full article is available to subscribers to the journal.
Author's Biography
Keith Nicholson serves as the Chief Security Officer (CSO) for the Office for National Statistics (ONS), where he leads the organisation’s security strategy encompassing cyber security, protective security, governance risk and compliance. Prior to this role, he was the Head of Cyber Security Operations at His Majesty’s Revenue and Customs (HMRC), overseeing the security of some of the UK’s most vital financial systems and services. Before joining HMRC Keith delivered cyber security risk management and security transformation initiatives at the Department for Work and Pensions (DWP). With extensive experience across multiple government departments and bringing a wealth of knowledge from operational and strategic roles, Keith is passionate about improving public sector cyber resilience and securing digital services.