Video: Unpacking the 2024 State of Threat Intelligence Report | Duration: 3516s | Summary: Unpacking the 2024 State of Threat Intelligence Report
Transcript for "Unpacking the 2024 State of Threat Intelligence Report":
Hello, everyone, and welcome to today's recorded future webinar. Give everyone just a few moments to, find their virtual seats, get their coffee or beverage of choice. We'll get started in just a moment. Alright. Perfect. Let's get into it. So, again, hello, everyone. Welcome to today's webinar where we're going to be unpacking the 2024 state of threat intelligence report with several of our recorded future experts. Just a couple quick notes before we get started. The webinar will be recorded and sent to the email you registered with, and feel free to drop your questions in the chat throughout. We will have dedicated time at the end, but, again, we can also cover them as they come up. And last thing, if you're a recorded future webinar regular, you might notice this experience is a little bit different. You know, we hope you like it, but definitely please let us know what you think in the post webinar survey. So with that, let's meet today's speakers. So in the considering we're coming up towards the end of the year, just a few a few months left till 2025 and a bunch of holidays coming up, I thought we'd go with it, an icebreaker to get to know our speakers of what is their favorite holiday activity or their favorite holiday dish to, bake, or cook. So I'll start with Jamie. Hi, everyone. Great to meet you. I had product here at Recorded Future, and, you know, my favorite holiday dish is probably making it as complicated as possible and cooking a full spread of turkey and all the sides and trying to have it all ready at the same time. Perfect. We'll go to Koppana. Next. Hi, everyone. I'm Koppana Singh. I lead marketing at Recorded Future, and my favorite holiday dish is stuffing. I have perfected a recipe that everybody in the in the family likes whether and I absolutely love it, and I can't wait for the day I can cook it. And, Nanda Holden? I'm Chris Holden. I run global services at Recorded Future, so all of the customer success and, professional services that we do here. I have family that's in the south of the United States. I love a good game of cornhole, during the holidays. And I gotta say, I'm with coconut. The stuffing number one seed is the best. Perfect. And lastly, Sam Meinorak, senior product marketing manager. As a hockey player growing up, I think when it gets nice and cold and the, the ponds and lakes freeze over, you know, play a little pond hockey, is my favorite activity, kind of the opposite of Holden's. And I also concur that I think stuffing is is one of the top top dishes for the holidays. So that's our that's our research report for you. Stuffing, top top dish of the holidays. But before we get into unpacking the research, I know I'm sure people wanna know how we got here. So let's take a quick look at how we actually got this data. So we partnered with user evidence to survey 554 cybersecurity executives, managers, and practitioners. And all the respondents came from organizations with over a 1000 employees at organizations across the globe. And over half the respondents are cybersecurity managers or directors. 80% of respondent organizations have a dedicated threat intelligence team, and all of our respondents are either very familiar or at least moderately familiar with their company's threat intelligence tools and policies. And we'll get into the specific data points, but at a high level, what we found in this research is that organizations are embracing threat intelligence that helps them to be more proactive. Teams are measuring success based on detection, response, and remediation outcomes. Internal research and threat intelligence vendors are how organizations are getting their threat intelligence, and support, efficiency, and actual insights are the top vendor traits organizations are looking for. Threat intelligence programs are continuing to mature, and lastly, security teams are spending more strategically on threat intelligence. So let's start unpacking the data by looking at if organizations are planning on investing more in threat intelligence or not. And according to our respondents, an overwhelming majority of them are planning to invest more in threat intelligence in 2025. And I have to imagine that's probably why you're on this call today, to figure out how to invest in threat intelligence and get the most out of your program. So throughout the rest of this webinar, we're going to talk through how to use threat intelligence tactically and strategically, what to look for vendors, and how you should be planning for the future. And as we go through the data points, please don't hesitate to put a question into the chat. So to start, let's look at which cybersecurity teams are using threat intelligence. Now according to our respondents, a number of teams are primary users of threat intelligence, and I'll toss the first question over to our panel. Can you pick out 1 or more of these roles and let us know what you've how you've seen them operationalize threat intelligence or if there are roles that are higher than you would expect or lower down here than you would expect. Yeah. I'll pick that one up, Sam. In looking in taking a look at this, and reflecting, it it's really interesting to see this and reflect on is it the observations that I've had? I've been at Recorded Future for almost 15 years now. So the the the opportunity to reflect, I think, on the on the practice of threat intelligence and how has how it's changed over the last 12, 13, 14 years. And I think one of the the notable things about the results here from the survey that matches what I think we've observed in the field with our with our many clients is the is the remarkable diversity of roles who take advantage of threat intelligence and actually practice threat intelligence in some regard as compared to a decade ago. And like, I'm over generalizing, but it used it felt like it used to be a group in a select number of companies, usually a small group or a person that was tasked with, like, the job of threat intelligence. And and now when you look at this, it's actually starting to be sort of dispersed nearly everywhere across enterprise security in some way. And if I could give one specific example of something I've noticed recently, is that a facet of threat intelligence that was almost always handled by one of these small teams, is like the detection of external threats. So external to the environment. So, like, you observe something in the criminal community about a business or registration of a domain or a fraudulent app gets advertised or listed on in a some sort of app ecosystem. And a trend that that we've seen that's notable is that a shift of those, like, detection and response type activities to the security operations function where, like, you would commonly see detection and response type runbooks for internal incidents. It's quite interesting to see how they've like, the process of those, like, threat detection type activities that are commonly seen as a component of a threat intel function have been shifting into a part of the security organization that is very familiar with threat detection type activities. And I could talk about this this topic for a really long time, but I won't because we have a short time and there are other people. But I think it's it's something that's become threat intelligence has become part of a design decision for security organizations. Like, really, whether you know it or not. And it's about, like, where do you fit intelligence into different aspects of dedicated TI work, of fitting, like, slivers of it into security operations work, into dedicating certain workflows there. You know, security engineering decisions on where to put this in, in the larger context of, I guess, security architecture and the work that goes around planning and executing that. So I think that's a good insight. I was gonna hit a little bit on the architecture team being listed here, and I think, you know, being listed quite high as well, which one of my takeaways was, again, if we look at intelligence, I I would say, you know, oftentimes was a report that was being produced. People were consuming that to understand, you know, what is the threat? What does the landscape look like? But the prevalence of the architecture and engineering team here shows that, you know, that shift is well underway to say not just how can we get the intelligence, but how can we put it to work and get it integrated into the right systems, whether it's, you know, to the SOC analyst to auto enrich alerts to save time, whether it's to auto close alerts that are irrelevant and benign to save time, you know, to enrich that information, but really getting it integrated into the different tools across the ecosystem to drive the business outcome that, you know, was was probably conceived of when the intelligence program was, you know, stood up or when the strategic priorities were set. So, I was happy to see that one coming in so high, and I think it's a a really important one. Yeah. And, you know, I have been at record leader for only a couple of years. But 2 years ago, I remember talking about that how, you know, we, as a group, talked about that how we can democratize threat intelligence and use it across different teams, and it's great to see as a leader we are really driving that and seeing, you know, as Holden mentioned, seeing that adoption across our customers. The other thing, it's great to see the usage of threat intelligence by the risk and compliance team. We know that CIOs and CISOs are shifting their focus to build resilience, which are all about reducing risk. And I think we will continue to see more usage of threat intelligence to inform risk assessment, priorities, and enable teams to be more proactive. So really, you know, awesome to see that, you know, ranking, you know, ranking so high because, ultimately, the, you know, the goal of threat intelligence is for to enable teams to be proactive and reduce their risk to the business. Perfect. And before we move on, I know there's a a question in the chat. For for those of us who have read actually read the full, 26 page document, the graph is not linked in the report PDF, because there's only so much space to answer or show kinda showcase all the data within the report. Some of the content that we'll be going through is kind of, auxiliary to to what is included in the full report PDF. I hope that helps, but we can also make these slides available as it is research from the report. I think we would be happy to share any of the any of the content that you see here with the audience and follow-up with you. I see it in the questionnaire to to you, Ashley. We'll get these to you. So perfect. So moving on to how organizations are using threat intelligence to take action, let's take a look at some of the top tactical use cases. So I'll pose the question to the panel. Which response here do you think organizations should focus on if they're looking to build out their threat intelligence program? If organizations looking to mature their program, where should they be focusing? So I'll I'll maybe kick us off here since Chris started the the last one. You know, this was a hard one for me to kind of pick because they're all such good use cases, and, I think we kind of see that it's evenly the results here are kind of, you know, split as well. But I'm gonna kinda pick the the second one around vulnerabilities. And one of the trends that we've certainly seen this year has been the number of, you know, 0 days that are coming in being exploited, especially in the enterprise software, you know, as opposed to the the kind of individual consumer or on some of the externally facing assets. It seems to be the, you know, a bad year to be a firewall vendor, because you're highly targeted, you know, on on those types of appliances and and software. And I think intelligence really can help there because the old school way was, you know, is there a vulnerability? What's the CVSS score? Do I need to patch it? But it kind of missed actually the context of, you know, of the environment of what's going on, you know, there, how critical is it, how can I actually kind of reduce this, like getting to a more granular level? Because, you know, just having the long list of vulnerabilities we all know isn't necessarily the most helpful security control because you actually need to prioritize what you actually have time for. So seeing the increased use in vulnerability intelligence there makes sense based on the the landscape of what we're seeing as well as the effect it can have to actually, you know, pick the 5% of vulnerabilities that if you patch them are gonna have the biggest impact on the organization and the biggest kind of impact on reducing risk based on the threats targeted at you, your environment, things like that. So I was pretty happy to to see that one there. Yeah. And just, I wanna add, well, one more thing around so to communicate risk to business leaders. So we recently had had our user conference predict in both DC and London, and I was talking to a couple of the CISOs there. And it's so interesting to see that how, you know, before, you know, how the questions about the threat landscape are being asked from business leaders across the board. So, you know, one of the CISOs mentioned that, you know, when they pass by, they are chief legal officer. They have questions about a certain ransomware group or something they have read in the news, and it is great to see how people are able to use threat intelligence to really inform, business leaders about risk to the business, both at the tactical level, but, you know, we're gonna cover that at the strategic level as well. I might piggyback on a little bit of the what both what Jamie and Kolpin has said, which is, actually, I think, of course, sort of dead on from the experience that we have with our thousands of clients around the world. I think on this, in the results, I think one of the areas that probably doesn't get enough appreciation, because well, maybe I'll go into this. My my feelings on why it doesn't get this, in a minute, is the is the category of informing organizational investments. And I'll, like, I'll take the liberty of expanding the word investments to include what Jamie mentioned, which is, like, an investment of organizational resources to choose what to patch. Like, a a lot of these things are like the the the outcomes from a lot of this is a choice of where to apply resourcing of some kind. You consider the finite amounts of of time of skill that you might have in your teams, in your enterprise security programs. There's finite budget. There's finite technologies that you can buy and apply. And so, like, however you want to, like, lean on that word, investments. And and the threat intelligence is it it can be a really incredible tool to to use when in terms of supporting, like, the enterprise's decision and inform where to invest in security ranging from, like, what Jamie said, what do we choose to patch on this pile? You know, prioritizing in the SIM, if you're like, hey. What do I look at? What do I have my teams look at here over one thing or another? There's a finite time. You know, prioritizing what controls to implement. You only have so much to choose on, you know, what technology to flex, where to like, what skills do you have to invest in. And then you have your people skills, and where, you know, might you choose to have a hiring decision based on intelligence and the kinds of things that your organization is trying to protect, what controls you're trying to implement, what technology you're trying to stand up to mitigate risk. I think a lot of those things can be informed, by threat intelligence, generally. And I I think that's an area that tends to get hard because the, like, the result of that requires this, like, communication internally in organizations. And as many of you might feel like, the people part can be the hard part more so than the technical part. And I, I I feel like there's a really interesting opportunity for those of you that are practicing threat intelligence or your senior leaders in security organizations to start to flex that where that might, like, rise higher in this list if we look at it several years from now. So There's a question from Ashley on saying that how do teams use CTI to retain talent? That's a unique use case I've never seen. Actually, one of the, you know, one of the challenges that security teams face is they're, you know, always inundated with alerts. They have, you know, thousands of alerts to sift through. A lot of them are relevant. A lot of them are not. And, you know, that leads to burnout of teams. And one of the things that threat intelligence does is actually give you context to be able to prioritize what matters so then you can actually focus on things that are really critical rather than sifting through a mountain alerts to focus on that. So we have some great insights on this on, you know, our website on how much time we save, how much effort we save for, for security teams across the board. So one of the examples that Jamie was saying, people can have up to 10,000 vulnerabilities generated through a scanner. They're not gonna fix those, and all of them should not be are not priority. So how do we focus on the 10 that really matter? And that's what, you know, threat intelligence helps teams do, which means the security teams can really operate, you know, efficiently and effectively rather than feeling the burnout. I know, Holden and Jamie, if you guys wanna add anything on that. I think it's a good point, especially because Holden kind of, I think, did a good job of talking about sometimes it's the people part, not the technical part that's the hardest. And, you know, I think one of the things I always think about that that helps motivate people and keep people engaged is, like, seeing how, you know, their how their job gets better each day, you know, that there's a path for you know, I see the organizations investing and resolving some of these challenges that we have and repetitive things on being able to tackle new, more complex problems and and learn and grow my own personal skill set and career. And so I think, you know, kind of helping you know, being a part of moving your organization along the maturity journey of using intelligence, I I think actually can be a very motivating, position for for many many people. Yeah. I would I would just add I'll add on. I've think we've observed that too with some, folks in, like, in our I'll call it our customer base over the years where, it also provides, like, I think, some in some interesting, career career growth opportunities there where if someone's doing the maybe they're doing, a security engineering function in the SOC and, like, the intelligence piece allows, like, a may have progression or or just something different, but it also then sort of, like, ties back. It allows you to tie together the pieces of the organization. And, you know, Sam, as part of this question, had asked about, like, where would you start? You know, I think some of the things here speak to a broader like, the applications of threat intelligence speak to the broader opportunity of, like, if you're of how intelligence can sort of advance the capability of maybe, like, a vulnerability function or a a sec ops function or an incident response function or you'd like name your name your vertical there. And sometimes you think of it like, I don't know, you've got your your standard, you've got your standard red teaming activities, and sort of like, I don't know, the the growth of a Pokemon. You're like, you've got a simple version, You add an intelligence and then it advances it in capability, and then you fit together the, like, the other parts of the security function. And now you have, like, the 3rd stage of the Pokemon that's the strongest. And, like, you sort of use intelligence as a way to, like, advance the capability of the other surrounding enterprise security, like, organizations. So I can't say I expected can't say I expected to, have the evolution of a Pokemon kind of be translated to a maturity of a threat intelligence program, but I think, you can take a bow, mister Chris Holden. You can use that if you're trying to demonstrate the advancement of capability to your organizations and and, further investment. And I noticed there there's also a question about, you know, there's there's business unit specific and manual content in these bar graphs. What about automation? I think that's these are something we didn't include in the in the research, but I think it's it's an incredibly important tactical use case and kind of something that Colton and I talked to. So, and I think if we look at the full research and all all 31 questions we asked, which we don't have time to cover through today, you'll see that automation plays a huge part in in how people are using Fed Intelligence. But for the sake of time, I'll, I'll keep us moving on to the to the next question, and that's where we shift from tactical to strategic. So let's take a look at how organizations are using threat intelligence at that strategic level. And according to our respondents, many of them find threat intelligence to be important or very important for justifying business investments to our leadership. I think of our our own CISO, Jason Steer, who talks about, you know, you you wanna be an enabler of business initiatives, not an inhibitor. So I'll pose the question for our panel. I imagine some of our audience are looking for some actual advice on how they can use their intelligence for this purpose. How would you be advising them? So I like to think about intelligence as a way to, like, both enable your security controls, but then also to validate where controls are being effective and where controls aren't. So if we take, for example, a a threat landscape, here are all the threats that are, you know, targeted at at my company or my my industry or kind of irrelevant to me in some way, you've probably deployed a series of controls that mitigate a lot of those threats, you know you know, basic things, firewalls, EDRs, and such. But there might also be a series of, of risks, you know, maybe MITRE TTPs or such that you don't have a specific control for, or maybe you have a very generic control and you're not sure, like, is that control actually going to detect that threat if it comes at you? Am I actually protected? And so I think having the intelligence to be able to say, hey. Here are the threats that we're worried about and why they're relevant to us. Here's the controls we have deployed and and such. Here's the gaps that we have. That kind of helps start to justify the investment, again, whether it's in buying a new tool, whether it's in people and resources and attack emulation to try to get more refined. There's many ways you could go about it, but that kind of gives a clear picture of, you know, we have a problem, you know, we we have this much solution, these are the gaps we have, this is what we need to do to go solve them, and it starts to become a very simple framework, to explain. Maybe it's not as simple as explaining a Pokemon, evolution, but, you know, a simple framework there to be able to, you know, quant kind of show the risk in a way that people can understand and and be able to justify the the action or investment around that. I think I think in in terms of, like, justifying you know, one of the I'll use one of the examples that, again, you know, based on a recent discussion we were having with couple of the CISOs is, you know, when you think about expanding let's say somebody you know, a business or a bank is trying to expand in a new geography. And, you know, instead of you know, there are obviously, you know, things like, oh, where are we gonna have a location? What's the TAM? You know, how are we gonna target, you know, the customers there? But from a security perspective, there are other things that you need to think through. What's the fraud landscape there? What kind of unique attacks that they might face? What's the geopolitical risk, if there are any? What are the physical risks that may employees, may face? And all of these things are a huge part of bringing security to the table early on to actually make a holistic business assessment of what investments would really need to make that business successful, which is very different from security coming in later and say, oh, well, we have this fraud thing, and now we have to deal with it. And that's when one of the CISOs, was talking about that having that seat early on in on the table to really think of how how you're gonna make the investments the right way. It is not just about security anymore. It's about, you know, reducing risk and enabling business, and that's what we believe that threat intelligence is really can be hugely important in justifying business investments, but also making the business successful in whatever endeavors the business is going towards. And, again, you don't have to be a unicorn to use, you know, threat intelligence. It's just, you know, you you have you have a platform that helps you get that right insight and right level of information that you need. I think just to add on to that, yeah, I think anything to orient the anything to when like, I guess, deploying threat intelligence at a strategic level, anything that oriented around the, you know, the the business risk, like, Kolpana said. And I think whether if you extend that out to, like, what is the investment organizations are making? What are the bets they're making? And what are the existential threats to those bets that you're making? And now it becomes sort of part of the business conversation. And it's not to be, like, it's not to be scary, but it's to help it's to help orient the rest of the organization. It may or may not be. I the like, technical is kind of a sometimes not the best word to use here. Maybe that, like, the technical aptitude or the understanding of how security fits into the larger sort of risk and or, like, enterprise goals. Like, let's assume it's a business and you're talking about growth of the business, and how the security teams organizing and operating based on threat intelligence can actually advance, like, the the business intent or the agency if you're in government or securing personnel or citizens if you happen to be here from, like, a from a government of some kind. Right? So I think organizing the communication, like, from the security organization, informed by intelligence and attached to the the threats that exist related to business or enterprise or agency or or national level government goals. Right? Great points. Sake of time. Moving on to taking a look at the top reasons our respondents gave for working with a threat intelligence vendor. So taking a look at these, I'll I'll start, start back with Holden. You know, at the top of this list is access to experts. You know, why do you think this might be the case? Yeah. When I so when I when we looked at this together and was kind of reviewing the results, I I thought about this for a long time in advance of the conversation today. And the just again, like, this feels like another topic you talk about for a really long time. My punch lines here are, like, I feel like this is, an outcome of just the game changing so fast. Like, what threat intelligence specifically, but then also the the threat environment, the the nature of, like, the the technology ecosystem, and just like the diversity of applications of intelligence has evolved so fast that there's, like, there's little in the way of structured institutional driven education on how to deploy threat intelligence in a business setting. I think that's a really important consideration in what might result in someone, leaning on the sort of expertise that exists in the and it's called the vendor or the technology ecosystem. Obviously, intelligence as a discipline is, like, ingrained, highly regimented, formalized in governments and militaries for decades or 100 of years, maybe longer. But, if I reflect that back on the enterprise, like enterprise security or or IT security space, like having to deal with adversaries, like unrestrained criminals operating in a space where you actually can't put people in jail, having to contend with governments if you're a business, like, you know, nation state adversaries, all of that is really still very new to many organizations. And, I think that the that organizations trying to build out their enterprise security practices and intelligence practices can still benefit a lot from the collective expertise and experience that vendors, whether it be Recorded Future or other, that they that we've aggregated it like quickly because that's our day to day, that's our existence, while those organizations, our customers, and others, like, build those muscles, the market matures, just the whole ecosystem learns a little bit more over over as the years go by. And for Jamie and Kolpina, you know, what are your thoughts on the top reasons here? Is is there anything sticking out to you? One thing that came to mind for me was, you know, it feels like the threat landscape is, like, always shifting like a a lava lamp going back and forth and, you know, different sizes. And I think the fact that, again, these categories came out so, you know, almost equally dispersed, you know, I think shows that it's like, you can implement some sort of, you know, process. So you're trying to do intelligence yourself. You can implement some sort of collection or analysis or such, but then just as soon as you get there, that approach goes away and a new one comes up. And then just when you're done with that one, the old one comes back in a slightly, you know, new form. You know, and the landscape is constantly shifting. And so I think being able to have, you know, a vendor or a partner that you're working with that is actually motivated in staying on top of that and, you know, working through developing techniques when there are new techniques and bringing them in and normalizing them and, like, their job is to make sure that it's easy to operationalize and put the work and drive the outcomes. I I think, you know, it's a good reason to do this because one day dark web is the most important monitoring for you, the next day it's Telegram, the next day it's all about, you know, advanced malware being targeted at you, and then then it's back to something new on the dark web. So it's it's a kinda constant, you know, shifting game. I just wanna put since I just said thinking about that. Like, I I agree. And just as a, like, a discreet example that came up recently when we were when I was at our when I was at RSA in the spring and meeting with customers, it was it was, like, it was almost shocking how many times, like, as a sort of a current modern business challenge, the concept of check fraud was. I was like, I thought we were done with this. Like, I thought this had like, this was not like a non and it was it was shocking to hear it come up. So as such a, like, a resonating relevant issue right now. And, like, that's not the that's not, like, the the high end exciting, like, use case that you would think of for a threat intelligence team to solve. And it's like that sounds like so boring, like some flat, like, club soda stuff. And it's like and yet, because the how the ecosystem has changed and the technology, has changed and the distribution mechanics for, like, criminals has changed, it's become very relevant again. And so working with partners who keep tabs on that and understand the trends and the the technical capabilities to contend with shifting adversary behaviors, I think, has become, I think that's yeah. I think that that just speaks to the the utility of working with working closely with partners based on that expertise. Yeah. I think the the other thing that, you know, came up here is integration with security tools. You know, one of the things we have been talking about is, you know, intelligence needs to be actionable. You know, seeing that integration with security tools is talked to kind of reinforces how we see intelligence being used by our clients. You know, intelligence sitting in a silo is not actionable. You know, it's not it's not something, you know, people can use across the board. And Jamie mentioned earlier, it's not just like, you know, a report somebody leads can take action. So having that, you know, intelligence integrated into workflows and tools is what supercharges security tools and what actually make, you know, security teams that we saw earlier, all of them use it because they can use it in the tool that they are already using, in the workflow they are already using, and seeing that as, you know, as as definitely, you know, reinforces how we think about, you know, integrating threat intelligence into every security tool. That's why we have over a 100 integrations across every part of the stack. So that's really good to see that continuing to be one of the top two requirements. Perfect. And so thinking about the reasons for working with threat intelligence vendors and then transitioning to now I have a threat intelligence vendor, how do I really measure the effectiveness of my program? And it's a very popular topic we often get from our community. So I'll I'll pose the question to the panel. You know, should we be looking at detection rates, response rates, reduction in number of incidents? Like, where do you think organizations should start when they are measuring the effectiveness? Yeah. I'll jump on this one first. Yeah. The these are yeah. I think some of this some of the responses are born a little bit out of, like, what is what is measurable, right, and what historically has been measurable in security operations. And, and we certainly see lots of our clients using these types of things. Broadly, when my team and our organization is working out in the field when and we've we we work with customers to to to think about the output from their CTI programs. We've broadly organized, like, the outcomes that, that you can look to as measurement or or value representation of intelligence programs in a couple of categories. The sort of cut that you see most represented here is, like, this detection and prevention category. I think there's detection that is useful in turn you can actually measure, like, is it trending over time? I think from a preventative standpoint, one of the best opportunities is if you can use intelligence to, to sort of categorize and contextualize the nature of what you detected and prevented, then it allows you to do some interesting things to tie that to, like, if this incident had happened, what would the potential costs have been to that? And then you can both count the the things you detected and the things you you prevented, and you can also associate that with, like, hey. The nature of this threat that we prevented, it would have manifest if it if something had gone through and we hadn't prevented it, it could it would have manifested in a ransomware incident that the and the blast radius of that would have been whatever. And the the likely business impact would have been x y number of dollars. The another area that we've looked at that Jamie mentioned earlier, which is really common, is prioritization. And if you're able to tell a story that, you know, we are we are able to fast track a vulnerability that was critical, informed by intelligence over things that had been kind of parked in the queue for a long time. That's a nice, it's a good value storytelling. There's efficiency metrics. If it used to take, you know, x amount of time for our l one and l two to get through these types of alerts, like, it now takes y amount of time because it's sort of being supercharged, as Kolpina mentioned, by, like, intelligence. And then maybe a little more on the boring side, but also very important is, like, just, you know, compliance. Like, just straight up compliance. Are we able to meet the requirements that are expected of us as a business in a particular geography, from particular regulatory requirements? Like, are we able to meet those requirements either outright because it demands intelligence or, like, we're able to meet them because we're so they're sort of facilitated by intelligence. So I thought it'd offer some of the broad ways that the broad categories that we see Mhmm. Clients, accomplishing metrics and also how we we might go and work with them to recommend they, they measure the outcomes from intelligence programs. Yeah. I think, you know, all all amazing ways to think about it. And, you know, by the way, it's not you know, every team, you know, if you are struggling to measure the impact of fraud intelligence, you're not you're not alone out there. We have talked to a lot of customers and everybody is kind of figuring out the right way. And I think in a lot of terms, you know, in simple terms, I think it's also about risk reduction. And I think a lot of times, teams struggle with the concept of what does risk reduction mean because, you know, technically, if you think about, calculating risk it's actually assigned. But, you know, I was reading an article recently about the impact of, you know, impact on organization's business as a result of the breach, and we have obviously heard about the big ones like Equifax and SolarWinds, where the breach cost cost them, like, 1,000,000 and 1,000,000,000 of dollars directly, but also much more indirectly. And I think it's simple terms when you're the question you have to ask is what are you willing to risk, and what does the breach mean for your business? That's always a good way to start a conversation when you don't know which all of the metrics and knobs to turn around. And I think that's, you know, we were again, you know, as we were having some discussion with our clients, they mentioned, like, some some folks have zero tolerance policy where they just say they have such critical infrastructure that they have, you know, 0 tolerance for breach, and they know how critical it is, for threat intelligence to get get them achieve those outcomes. So all the things that Holman mentioned feeds into that of ultimate objective of, you know, not not having any tolerance for risk. And then, obviously, risk tolerance would change from organization to organization, but that's also a good way, especially when you are talking to the c suite or even, you know, even a board and audit committees. And I think, you know, and then one of the things we are actually doing, I would be remiss not to plug in one of our upcoming reports on ROI for threat intelligence. So stay tuned for that. Really excited about that, and, hopefully, that will give you insights from our own clients, how they have successfully, measured the return on investment for the Verizon Intelligence program. Jamie, any any measurements that you kinda think are are important to go through for teams? No. I think they I think, Holden and Colvin, covered it. I mean, I think you can look at detect, respond, you know, different rates. One other maybe just to consider would be shifting work to a lower level analyst because you've been able to kind of systematize it. So as opposed to having to, you know, escalate to a higher tier, especially in a SOC environment, you know, if you can get simple intelligence that answers the question to kind of the the lowest level person that you can, you know, it's gonna inherently, you know, drive faster responses. It's gonna, you know, allow you to scale, allow you to automate more, and so I think also looking at, you know, who's doing the work and and can you shift it, across those tiers is another good one. Just plus one that, I think that in the the category Jamie Jamie just nailed one of the areas that, like, you could consider in those broad buckets with one of the buckets being efficiency. That doesn't necessarily just mean processing power, like, of like, how many can you get through. It might be shifting, you know, the the cost of your efforts in the organization. You might be able to automate in different ways. Like, there's a lot of different ways to consider, like, the, the the measurable outcomes that you could, that you could put in that efficiency bucket. So I that was that was a great point, Jamie. Yeah. No. Great great points across the board. And we actually had, our champion one of our champions from Rivian on a webinar fairly recently where he talked about you know, I asked him the same question. He talked about how it's you know, to to Holden's point, it's it's kind of about storytelling and making sure that the incidents that you do prevent, that you're able to educate the broader organization on how important threat intelligence was to that. For example, understanding if there's a, a domain impersonating your benefits portal and being able to take that down before there's something that happens there that can really impact the business. So, yeah, it kinda shows there's a number of ways to cut it and that, you know, threat intelligence is is is pretty important across the board. But I'll, I'll move us along and and kinda go into the last section here, and look at look into the future here. So what are the things that organizations are planning on doing to improve their usage of threat intelligence? And I'll have a a personalized question for each of our panelists here, and I'll I'll start with Holden. But if you're an organization, again, looking to begin or grow their threat intelligence program, what should they be making sure that they do here over the next 1 to 2 years? Yeah. I've I thought about this question a lot and I'm I'm I I'm I'm gonna admit, like, I I give this I've given this advice in this kind of, commentary, I guess, in a lot of different ways. And for those of you that have been practicing intelligence for a while, you'll probably be like, yeah. I know. I probably. But it's like, I think one of the first things before I I don't think there's a straight. I don't think there's a straight and one, like, one common path here. And I think one of the in terms of where where organizations are gonna invest and where do they start, I think it's it's the the first place. If you're gonna be the like, if you're gonna be successful in building out capability or adding on capability is, to a lot of the commentary from from Damien Culpin earlier. Like, a lot of this is gonna be born out of looking internally and understanding what the business initiatives are, what is extreme what is gonna be perceived as investment and risk mitigation for what matters to the organization, the enterprise, the agency, versus, like, what's a fancy thing for the security org to do? Like, what's gonna what's going to advance the business across the board? What do you have in place today? What's critical to the enterprise? What are you trying to secure? Like, that internal, like, introspection around, like, what's important to the organization, I think will drive, a lot of where people place investments on threat intelligence, whether that be automation, whether it be personnel, whether it be trade craft, like learning and development for their people. And it's not intended to be a cop out, I swear. But I think looking internally and saying, like, hey. Are there things that we're trying to build out, our security operations function? Or if we already have a highly efficient, what an organization believes to be effective secure SecOps team, but we don't have a hunting capability. And, like, that's what we're gonna choose to invest in because we've like, that's where we have gaps. I think there will be investments placed in those different areas. Like, we saw the diversity of roles. And really quickly before I shut up, like, I think that they're in terms of the measurements and maturity, I think that it's not like a lump sum game. I think that we see organizations starting to understand that maybe they've advanced really quickly and successfully in using intelligence to drive vulnerability prioritization. But they're at the starting line basically for using threat intelligence led hunts. And so, like, you might invest over here, and this may advance a little bit. And then 3 years from now, you'd be like like, okay. Well, now I'm a little actually, like, lagged a little bit over here. So I think you're gonna I think that organizations are starting to find that it's not like a, hey. Threat intelligence is a thing, but we need to figure out what lanes we wanna invest in based on the business priorities. And, I I think that that is what we will see coming out of this a little bit more in terms of, investment and strategy for organizations. So Got it. And and one of the key insights we saw from their research is that organizations are saying that they are are maturing in their threat intelligence capabilities. So I'll I'll bring up for for Jamie for an organization looking to, you know, maybe further mature from intermediate to advanced or intermediate to more advanced. You know, what what do you think they should be looking to do over the next 1 to 2 years? So I think this slide kind of shows to me how many teams are involved in consuming and using intelligence to put to work. And so I'll use a a brief Starbucks analogy, which is like, why does Starbucks release a pumpkin spice latte every year? Because everyone drinks it like crazy. And so if you're producing intelligence, like, you want it to be that your end consumers, whether it's the vulnerability management team, whether it's your board at a higher level, you know, whether it's the SOC, like, for whatever type of intelligence you're producing, long form analysis, quick flash reports on a topic, high high quality, high confidence indicators that you're feeding. Who's on the other end of that, and, like, what do they need out of it? What makes them successful? What's gonna make them come back and keep drinking, you know, what what it is that that you're producing? That's gonna mean that it kind of forces you to do a few things. 1, it forces you to understand your end user, you know, your customer on the other side or your your other department. Understand, like, what are their challenges and problems? How can you, you know, help solve them? That inherently means that you're gonna be more, you know, closer to solving the problem with them, and that's gonna help you mature mature because it means you know that what you're producing isn't, you know, just being read and put aside. It's actually being implemented and actioned consistently, to the point that if you were to stop doing it, that team would feel the pain. They'd be like, I can't do my job anymore because I'm so reliant on it. Okay. Now you know you're at quite a mature state because you've, you know, understood the exact business needs or the exact requirements of that team, whether it's technical, whether it's strategic, you know, somewhere in between. You've produced a product, whether it's text imagery, you know, technical analysis, you know, etcetera that directly meets that need. That's kind of how I really look at at measuring maturity. And you don't have to start with every team in the company. You might start with just, hey. This is our closest stakeholder. How can we make them a little bit better? How can we then replicate this to the next team, to the next team, to the next team, and kind of build your your roadmap of execution in that way. But I think that's kind of to me, you know, it's maybe a very simple way versus a a metric to look at maturity of the of the program, but I think it's a a good way to say, like, we're critical. Okay. That means we've we've done quite a few things right now. Perfect. That's really cool. Real quick, I just wanna add, I think that Jamie used the word that's called the the word product, which I think is an interesting it's been like a like a it's a loaded word in the world of in like, in of intelligence. And then a product, a lot of people think is like the report. And I just wanted to really quickly touch on that because I think this the results of this reflect that, like, the products of intelligence teams, people the the respondents here are looking for it to be the products to be more than just reports. And for those of you on the line and think about it this way, like, I think the the products, the proceeds, or however you wanna however you wanna name it of your intelligence teams, it could be, it it could be detection signatures. It could be recommendations to the 3rd party risk team. It could like, there's all these different things that could come out and be products from the intelligence function that I, I hope out of this conversation some of you might take back and be like, oh, it doesn't have to be a report. Right? I think before we turn into all of us turn into a pumpkin here, there are some questions that I think would be great to answer. I know we only have 11 minutes left. So, Sam, do you wanna pick few? Perfect. Before before I get to that, one last question for you, Kolbana, there. Is there is there a response that's not here or that we think we'll see added in the next 1 or 2 years? Yeah. I think in at the risk of sounding just like, you know, using a buzzword, but I do think this is something that we'll see is the use of AI. I think one of the things that, we haven't seen is obviously, you know, there is some people are still adopting, building trust, and, you know, we released our own AI capabilities a year ago. We are constantly improving it. But, you know, one of the things we want people to do is really focus on what humans are good at so they can focus on things that are nuanced and figuring out hunting and all those things, and how does AI does all the grunt work of, you know, doing those things. We have been using AI in our platform for over a decade, but now we have bring brought it to the forefront. So I do think that there would be things, you know, in the next year or so, you will start to see how people are using different capabilities of AI to drive better outcomes from their threat intelligence program, as well as, you know, all all across the cybersecurity programs as well. Perfect. Yeah. With that, we can, get into our questions here. I appreciate everyone that has asked 1. It's also a new webinar platform, so trying to get used to how to pull them up here. But I think this is a great question for the team to answer, and and that's a little bit long one, but bear with me. A common perception of CTI I see in org is that CTI is a 100% external, I. E. Primarily consuming external sources. Do you see the orgs change its perception and look more closely at internal data? For instance, generating intelligence from what they see across their environment. Looking internally seems like a great opportunity for CTI growth. Can you all speak to this? I feel like this question is speaking my my love language, which I agree. I I I've kind of called out this problem for for quite some time, which is that for a long time, exactly as you said, intelligence was external, and then the SIEM was the source of truth internally. And what happened was, 1, the SIEM was never really the source of truth internally because the SIEM was one data point and the EDR logs weren't necessarily pulled in there, and then there was another SIM for the cloud environment, that had those, you know, what was seen there. And then a subsidiary or the the European office had a a different, you know, system and toolset. And so then you actually ended up with, like, what is actually the priority of the threats that we need to be focused on? And there wasn't a single answer because you had the external perspective and then in one or many internal perspectives. I think for sure the the the goal and the strategy needs to be to bring those together to say, well, actually, what we're seeing in our environment is incredibly unique. It's high confidence. It's it's clearly been seen, so we clearly have some weakness that's been exploited to to be there. We also have threats that we may or may not have seen externally. And so bringing those 2 together to one source gives you a view of both collectively, what is the priority and what is the focus and the risk and the threats that we're dealing with, but then also what are the gaps between what is is seen in others like me, in my industry, in my geography, just a trending prevalent threat today, and what I'm detecting, and those gaps also become incredibly key to understand and drive focus and priority. So I I agree. I think this has been a big problem in intelligence, and I think this bringing them together is, is important. And obviously, I'd be remiss even though this wasn't a a seeded question to say, like, this is exactly what we're doing in recorded future with with some of our collective insights capabilities is to say, actually, we need to build that one source of truth and just make that easy easy to have. Yeah. I might add on going back years. Like, if you think and it probably depends a little bit on the nature of your organization in terms of, like, the scope and scale of what you have access to and might be able to generate internally. But, if you think about, if you think about retailers or anybody who runs anybody who has access to, or runs or is responsible for an ecommerce platform, like, some of the telemetry that you can observe from people interacting with that platform, from actors who are trying to abuse that platform, like, all of that, like, all of the telemetry you could imagine getting, like, getting together, is just the is an is a invaluable resource. It, of course, takes, like you have to invest in, like, organizing it and analyzing it and processing it, which Jamie mentioned, there are some things that we're working on to assist and facilitate that kind of processing of, like, internal versus external and matching it up. But, I just I would, I I can't help but support the comment here that suggests that looking internally is a great opportunity. And I also think to the point of, like, where do you start? And I mentioned before, like, when I said the introspection, I think that directs requirements in terms of how you might want to direct what intelligence serves in the business. But looking internally at what you're already capturing, what you're able to see, and what, like, telemetry you have available from your systems is also part of that. Because if you're expecting to design and deliver on a use case that requires you have visibility to something internally, but you don't, then, like, that should not be where like, you shouldn't start by trying to deliver on the thing that requires you to have the internal visibility. And instead, maybe you want to actually implement so you get the visibility and then can build from there. So Perfect. Alright. Looking for one last one. So you had another question here around, my company uses many cloud ERP solutions, which are out of our view. The the question is how many cloud platforms are utilizing your threat intelligence platform, and whether you provide standard reporting formats, but, also, I guess, any information on how threat intelligence can be used to gain better visibility into cloud assets. So I think there's, like, a couple of ways to look at what are the threats to cloud and then, therefore, what are the intelligence, you know, components needed. I think if we look at cloud at large, one of the the first problems that usually comes up is understanding what cloud assets you have. You know, how many AWS accounts do you have? How many people are actually spinning stuff up in GCP or Azure despite perhaps a company policy or standard not to do that? So the first IC is, like, actually identifying your attack surface based on what's actually exposed. It's usually more than what you expected, and so that then gives you an immediate action to try to remediate that. I think looking at the particular threat vectors, you know, a lot of this comes down to, stolen credentials being reused even on top of, you know, exploits and, you know, sophisticated attacks. And so knowing what stolen credentials exist, whether it's for your own employee network or whether it's for your customers that are logging into your website is another kind of key way of of looking at that. And then just kind of like where are the the threats targeted? How are they going after other similar platforms? Is it supply chain attacks typically and you need to worry about the, you know, the 3rd, 4th, 5th party vendors that have access, you know, and and kinda walking that that chain as well. Anybody else wanna answer take an answer on that one? Yeah. I think the only last thing I would say, like, one of the big things around, you know, cloud providers is, you know, I'm sure these are hosted at big cloud providers. So one of the things we have this unique capability is our network intelligence that can give you very early detections on if any of these, you know, infrastructures that support those are, you know, under any sort of potential attack by just looking at the different different patterns and, you know, unusual patterns of network. So, you know, one of the things is it's not just about, you know, things that, you know, it could be stolen credentials. It could be the fact that somebody's running a DDoS attack. Somebody's trying to, you know, do, you know, malicious, you know, traffic attack. And all of those things impact your ability to use the the cloud service, but also with your data being there is also a potential concern. So you can proactively go and ask your provider, hey. We have seen this unusual activity. What are the things that you know, what are you doing to mitigate that and, take extra extra actions and precautions? So, that's that's another dimension that we help with those. And I know the question was, like, how many cloud providers do you that's right. And so that is obviously something you know, we we can, publicly share a lot of our customer names, but we do know that, you know, a lot of the things, you know, we enable a lot of the big cloud providers in terms of protecting their infrastructure. Perfect. Well, with 2 minutes left, I'll, I'll wrap this up. Thank you to everyone who joined. Thank you everyone who's downloaded the report. We'll make sure to send around the slides with the full research report. And just remember that, yes, stuffing is the dish of the holidays, and that if you're looking for a threat intelligence maturity curve, you can start by painting the picture of a Pokemon evolution. But I hope you found this helpful sorry. Go ahead. Make sure you enjoy your pumpkin dishes and pumpkin sized lattes, for the fall season. Thank you, everyone. Thanks, everyone. Thanks, everyone.