7 min read

Why Most Threat Intelligence Programmes Are Not Worth the Money

Threat intelligence is one of the most expensive parts of a security programme and one of the most under-used. Most programmes pay for feeds they do not read, run platforms they do not use, and produce reports that do not change anything. Here is the honest version of the work

Threat Modelling Purple Teaming

Threat intelligence is one of the most expensive parts of a security programme. It is also one of the most under-used. Most programmes pay for feeds they do not read, run platforms they do not use, hire analysts they do not deploy, and produce reports that do not change anything. The money is spent. The intelligence is not used. The programme is not worth the money.

Here is the honest version of the work.

What threat intelligence is actually for

Threat intelligence exists to inform decisions. The decisions are operational. Which threats do we plan against. Which threats do we ignore. Which detections do we prioritise. Which vulnerabilities do we patch first. Which red team emulations do we run. The threat intelligence is the input to those decisions. The decisions are the output.

Threat intelligence is not for the dashboard. Threat intelligence is not for the slide deck. Threat intelligence is not for the weekly report that nobody reads. Threat intelligence is for the decision that changes the detection, the patch, the emulation, the response.

If your threat intelligence programme is not changing the decision, the threat intelligence programme is not doing the work. The threat intelligence programme is collecting the intelligence, packaging the intelligence, and shipping the intelligence to a destination that is not using the intelligence. The threat intelligence programme is not worth the money.

The most common failure mode

The most common failure mode is the feed. The programme pays for a feed. The feed is a stream of indicators. The indicators are pushed into the SIEM. The SIEM fires on the indicators. The SOC analyst triages the alerts. The alerts are false positives. The SOC analyst suppresses the alerts. The feed is now noise.

The feed is now noise. The feed is no longer intelligence. The feed is no longer informing decisions. The feed is consuming analyst time. The feed is producing noise. The feed is a cost. The feed is not worth the money.

The fix is not to buy a better feed. The fix is to think about what the feed is for. The fix is to identify the specific decisions the feed is informing. The fix is to identify the specific operational changes the feed is driving. The fix is to track the changes. The fix is to measure the impact.

If the feed is not driving a specific operational change, the feed is not worth the money. Cancel the feed. Use the budget for the things that are worth the money.

The second most common failure mode

The second most common failure mode is the report. The programme produces a weekly report. The report is a list of the threats that are relevant to the industry. The report is sent to a distribution list. The distribution list includes the CISO, the SOC manager, the detection engineering lead, the red team lead, and twenty other people who should be reading the report. Nobody reads the report.

The report is the artefact. The report is not the work. The work is the changes that the report drives. The work is the detection rules that the report leads to. The work is the patch prioritisation that the report informs. The work is the red team emulations that the report shapes. The work is the operational changes.

If your threat intelligence programme is producing reports that are not driving operational changes, the threat intelligence programme is producing artefacts. The threat intelligence programme is not producing changes. The threat intelligence programme is not worth the money.

The fix is not to write a better report. The fix is to make the report a forcing function for operational change. The fix is to attach the operational change to the report. The fix is to track the change. The fix is to measure the change. The fix is to make the report the start of a process that ends in the change, not the start of a process that ends in the inbox.

The third most common failure mode

The third most common failure mode is the analyst. The programme hires a threat intelligence analyst. The analyst is a smart person. The analyst is capable. The analyst is not deployed. The analyst is sitting in a corner of the SOC reading feeds and writing reports. The analyst is not in the operational meetings. The analyst is not in the detection engineering reviews. The analyst is not in the red team planning. The analyst is not informing decisions. The analyst is consuming feeds and producing reports.

The analyst is the most expensive part of the threat intelligence programme. The analyst is the part of the programme that is most under-used. The analyst is the part of the programme that is the most obvious failure.

The fix is to deploy the analyst. The fix is to put the analyst in the operational meetings. The fix is to put the analyst in the detection engineering reviews. The fix is to put the analyst in the red team planning. The fix is to make the analyst part of the operational team, not part of the reporting function.

The analyst who is in the operational meetings is the analyst who is informing the decisions. The analyst who is in the operational meetings is the analyst who is producing the changes. The analyst who is in the operational meetings is the analyst who is worth the money.

What the work actually looks like

The work of a useful threat intelligence programme is not glamorous. The work is the meeting. The work is the conversation with the detection engineering lead about which threats are credible and which threats are not. The work is the conversation with the red team lead about which threats to emulate in the next quarter. The work is the conversation with the CISO about which threats the programme should be planning against and which threats the programme should be ignoring. The work is the conversation.

The conversation is the work. The conversation is where the threat intelligence becomes the operational change. The conversation is where the feed becomes the detection rule. The conversation is where the report becomes the patch prioritisation. The conversation is where the analyst becomes the part of the team.

The work is not the report. The work is not the feed. The work is not the platform. The work is the conversation.

The honest scope

The honest scope of a useful threat intelligence programme is small. A useful programme has one or two analysts. A useful programme has one or two feeds that the analysts actually use. A useful programme has a cadence of meetings where the analysts are talking to the operational teams. A useful programme has a clear set of decisions the threat intelligence is informing, and a clear way of tracking the changes the threat intelligence is driving.

A useful programme does not have a large team. A useful programme does not have a large platform. A useful programme does not have a large budget. A useful programme has the right size to be in the operational meetings. A useful programme has the right size to be informing the operational decisions.

The expensive threat intelligence programme is the one that is not informing the decisions. The expensive threat intelligence programme is the one that is collecting the intelligence, packaging the intelligence, and shipping the intelligence to a destination that is not using the intelligence. The expensive threat intelligence programme is the one that is not worth the money.

The small threat intelligence programme, deployed into the operational team, is the one that is informing the decisions. The small threat intelligence programme is the one that is worth the money.

The honest answer

The honest answer is that most threat intelligence programmes are not worth the money. The honest answer is that the small threat intelligence programme, deployed into the operational team, is the one that is worth the money. The honest answer is that the work is the conversation, not the report.

If you are running a threat intelligence programme, ask yourself whether the programme is informing the operational decisions. If the answer is no, the programme is not worth the money. If the answer is yes, the programme is worth the money. Either way, the work is the conversation.