DOI: 10.69554/phxg6806 ISSN: 2398-5119

Demystifying cyber threat intelligence: A first-principles approach to capability development and vendor evaluation

Aaron Aubrey Ng
Cyber threat intelligence (CTI) is considered an essential element of a robust cyber security programme. Given the relative nascency of the discipline, however, there is a degree of ambiguity among the community around what it takes to establish a credible CTI capability in support of the cyber security mission. At the same time, there is now a thriving industry offering commercial CTI products and services in support of the customer’s capability development efforts, with many instances of opportunistic vendors poised to exploit this fledgling market. This has spurred the growth of research and advisory companies that attempt to present an objective review and offer guidance around CTI vendor selection. Their perspective, however, is often heavily influenced by a small group of select vendors and the evaluation criteria is often incomplete and skewed towards the participating vendors. This paper makes the case for a first-principles approach that CTI teams can adopt as an unbiased anchor to guide their decisions around establishing an adequate CTI capability, and offers pragmatic recommendations to assist CTI teams with qualifying their prospective vendors to ensure good fit. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.

More from our Archive