ETFOptimize | High-performance ETF-based Investment Strategies

Quantitative strategies, Wall Street-caliber research, and insightful market analysis since 1998.


ETFOptimize | HOME
Close Window

Four Ways to Incorporate AI into Threat Intelligence Programs

ISACA's new resource also provides guidance on selecting a threat intelligence program and developing a holistic, threat-led approach to improve operational impact

Threat environments have become more complex, especially with the rise of generative AI and the rapid commercialization of the cybercrime ecosystem. Enterprises have also long struggled to realize meaningful value from traditional cyberthreat intelligence programs. However, there are steps that cybersecurity professionals can take to improve the effectiveness of their threat intelligence programs, as outlined in ISACA’s new white paper, Building a Threat-Led Cybersecurity Program with Cyberthreat Intelligence, which provides a practical blueprint for building or strengthening a modern threat intelligence program and moving to a holistic threat-led approach.

Whether practitioners are looking to craft the foundations of a mature program or refine their existing program, the ISACA white paper shares steps to develop a threat model, establish priority intelligence requirements and create alignment between intelligence outputs and enterprise risk management objectives.

How to Improve Operational Impact

When determining how to operationalize a threat intelligence program, organizations should consider their technology stack, tool selection, and opportunities for automation.

Whether an enterprise plans to purchase multiple platforms to reduce the chances of missing a critical event, or has a lower security budget and plans to purchase a single platform to optimize costs, organizations should do the following when selecting a threat intelligence platform:

  • Capture intelligence requirements – Identify unmet technology needs to begin drafting the list of requirements. Share the list with a potential vendor early in the sales process to avoid wasting time on platforms that will not meet the requirements.
  • Engage stakeholders – Confer with teams within security, fraud, or governance, risk, and compliance to identify technical requirements from other parts of the organization.
  • Vendor Evaluation – Once potential vendors are identified, evaluate the vendor against technical requirements, how easy they are to work with, and how well they respond to requests.
  • Deployment – Integrate the selected platform with the team and operational processes. Build automations, processes, and workflows to leverage specific features and maximize the value derived.

Automated approaches can build upon an already successful program to improve maturity and reduce the mean time to detection (MTTD) and mean time to response (MTTR). Integrating AI into a threat intelligence program demands a cross-functional operating model with clear decision rights and controls. The white paper suggests:

  • Parsing of breached identities for prioritization: Apply automation to prioritize stealer logs that contain enterprise credentials, using rules-based detection that classifies each log by the relative risk of the domains and assets it references.
  • Large Language Model-Enabled Initial Access Broker (IAB) Analysis: Identify IAB posts and assist in processing and analyzing massive amounts of unstructured text data from the dark web, hacker forums, and other sources.
  • Breached Credential Verification and Remediation: Establish a relationship with a trusted threat intelligence provider to receive timely alerts when employee email addresses and credentials appear in criminal marketplaces or stealer logs.
  • IoC Feeds for Threat Hunting: Curate high-fidelity feeds that enhance detection capabilities without overwhelming analysts with false positives.

"An effective threat intelligence program is the cornerstone of a cybersecurity governance program. To put this in place, companies must implement controls to proactively detect emerging threats, as well as have an incident handling process that prioritizes incidents automatically based on feeds from different sources. This needs to be able to correlate a massive amount of data and provide automatic responses to enhance proactive actions," says Carlos Portuguez, Sr. Director BISO, Concentrix, and member of the ISACA Emerging Trends Working Group. "In order for companies to achieve this, though, they need to overcome challenges like data overload, integration with cybersecurity products, knowledge and experience limitations within their cybersecurity teams, lack of automation initiatives and slow adoption of best practices and security frameworks."

To access the complimentary white paper, visit www.isaca.org/building-a-threat-led-cybersecurity-program. For other cybersecurity resources, including the Advanced in AI Security Management (AAISM) and Certified Cybersecurity Operations Analyst (CCOA) certifications from ISACA, visit www.isaca.org/cybersecurity.

About ISACA

For more than 55 years, ISACA® (www.isaca.org) has empowered its community of 185,000+ members with the knowledge, credentials, training and network they need to thrive in fields like information security, governance, assurance, risk management, data privacy and emerging tech. With a presence in more than 190 countries and with more than 230 chapters worldwide, ISACA offers resources tailored to every stage of members’ careers. Through the ISACA Foundation, ISACA also expands IT and education career pathways, fostering opportunities to grow the next generation of technology professionals.

ISACA's new resource also provides guidance on selecting a threat intelligence program and developing a holistic, threat-led approach to improve operational impact.

Contacts

Recent Quotes

View More
Symbol Price Change (%)
AMZN  210.00
+2.08 (1.00%)
AAPL  264.18
-8.77 (-3.21%)
AMD  200.21
-3.47 (-1.70%)
BAC  49.83
-2.47 (-4.72%)
GOOG  311.43
+4.28 (1.39%)
META  648.18
-8.83 (-1.34%)
MSFT  392.74
-8.98 (-2.24%)
NVDA  177.19
-7.70 (-4.16%)
ORCL  145.40
-4.91 (-3.27%)
TSLA  402.51
-6.07 (-1.49%)
Stock Quote API & Stock News API supplied by www.cloudquote.io
Quotes delayed at least 20 minutes.
By accessing this page, you agree to the Privacy Policy and Terms Of Service.


 

IntelligentValue Home
Close Window

DISCLAIMER

All content herein is issued solely for informational purposes and is not to be construed as an offer to sell or the solicitation of an offer to buy, nor should it be interpreted as a recommendation to buy, hold or sell (short or otherwise) any security.  All opinions, analyses, and information included herein are based on sources believed to be reliable, but no representation or warranty of any kind, expressed or implied, is made including but not limited to any representation or warranty concerning accuracy, completeness, correctness, timeliness or appropriateness. We undertake no obligation to update such opinions, analysis or information. You should independently verify all information contained on this website. Some information is based on analysis of past performance or hypothetical performance results, which have inherent limitations. We make no representation that any particular equity or strategy will or is likely to achieve profits or losses similar to those shown. Shareholders, employees, writers, contractors, and affiliates associated with ETFOptimize.com may have ownership positions in the securities that are mentioned. If you are not sure if ETFs, algorithmic investing, or a particular investment is right for you, you are urged to consult with a Registered Investment Advisor (RIA). Neither this website nor anyone associated with producing its content are Registered Investment Advisors, and no attempt is made herein to substitute for personalized, professional investment advice. Neither ETFOptimize.com, Global Alpha Investments, Inc., nor its employees, service providers, associates, or affiliates are responsible for any investment losses you may incur as a result of using the information provided herein. Remember that past investment returns may not be indicative of future returns.

Copyright © 1998-2017 ETFOptimize.com, a publication of Optimized Investments, Inc. All rights reserved.