Building your Threat Intelligence dream team

Fujitsu / February 12, 2025

As cyber security threats grow more sophisticated, organizations increasingly rely on Threat Intelligence (TI) to anticipate, identify, and mitigate risks. This guide explores the essential elements, methodologies, and best practices for building an effective TI capability.

What is Threat Intelligence?

TI involves collecting, analyzing, and applying information about cyber threats to enhance security. It enables organizations to anticipate risks, improve decision-making, strengthen incident response, support compliance, safeguard reputation, and gain a competitive edge.
An effective TI capability follows a structured methodology approach.
1. Requirements definition: Identifying the intelligence needs and objectives of the organisation.
2. Data collection: Gathering relevant threat data from a variety of internal and external sources.
3. Data processing: Cleaning, normalising, and enriching the raw data to make it usable for analysis.
4. Analysis: Identifying patterns, trends, and actionable insights from the processed data.
5. Dissemination: Sharing the insights with relevant stakeholders in an understandable and actionable format and with security tools such as Firewalls, IDS*, SIEM, SOAR, Endpoints as examples.
6. Feedback and refinement: Continuously refining the Threat Intelligence process based on stakeholder feedback and evolving requirements.

Categories of Threat Intelligence

Businesses may consume one or more of the listed TI forms based on its purpose and scope.
Strategic TI: High-level insights for long-term decision-making, ideal for executives and risk managers. While non-technical, Intel looks further ahead, focusing on long-term risks, emerging adversaries, geopolitical factors as examples. Sources include OSINT, ISACs*, NGOs and media news publications alongside whitepapers and research reports.
Operational TI: Immediate threat information to support incident response and threat hunting activities. Sources include dark web and forums, malware analysis, security feeds/alerts and social media platforms.
Tactical TI: Attack patterns and methods to strengthen defenses. Sources include cyber security community forums, threat databases, Dark Ops and public attack surface monitoring.
Technical TI: Short-term indicators of compromise, such as malicious IPs and domains. Sources include threat data feeds, research reports, communities, hacker forums and learnings from an attacked organization.

Loading component...

Loading component...

Loading component...

Loading component...