By Josue LedesmaThreat intelligence has transformed the information security world for the better but it’s not always leveraged in the best way possible by organizations and departments. The sheer amount of information, providers, platforms, and types of threat intelligence and data available, make it difficult to confidently ensure an organization is making the most of their threat intelligence.For this article, we spoke to Karl Sigler, threat intelligence manager at Trustwave, to get a sense of how organizations can maximize threat intelligence for their organization.Threat intelligence is a relatively new area in the information security world brought by a shift in security philosophy and mindset among companies, and due to major changes in technological capabilities.Sigler describes a previous world where companies held tight to their security research and information, seeing it as an advantage they had over their competitors. However, it was soon discovered that information-sharing vastly benefitted all companies, mitigated potential risk, and weakened attackers who preyed on a lack of knowledge.These data and information partnerships have led to an exponential growth in available data and only somewhat recently has the technology been widely available to access and leverage this amount of data and information. Now, infosec should look towards leveraging threat intelligence as a key part of their department and function.How threat intelligence benefits an organization varies wildly and should vary by that organization’s objectives and priorities. For example, threat intelligence can enhance a company’s auditing capabilities, it may help in defining, identifying and filtering incoming firewall data, or it may support your current Intrusion Detection Systems (IDS) or Intrusion Prevention Systems (IPS).However, using threat intelligence effectively is where the challenge lies.Sigler stresses that without the right training, no amount of threat intelligence data or platform would make an effective impact in an organization. He outlines that the right individual and team should have the following areas of expertise.We should stress that it would be difficult finding the right team, let alone individual, with high degrees of expertise in all of these areas. Which brings us to the next area.
Why Threat Intelligence is Important for Information Security Departments
“Threat intelligence has only started to mature over the past 5-7 years because just recently, we’ve been able to collect, handle, analyze, and store massive amounts of data.” - Karl Sigler
Making the most of threat intelligence
Using threat intelligence effectively is largely about using data effectively. This means your company needs to have the right organizational and departmental set up before being able to properly leverage any threat intelligence for its benefit. According to Sigler, there are three major areas of consideration - infrastructure, team skill-sets, and training.Having the Right Infrastructure
Simply put, if an organization doesn’t have the right infrastructure to handle the amount of data coming from a new threat intel feed, then the threat intelligence information is of no use to the company. Or worse, it may even slow an organization down, making it less capable of preventing potential attacks or mitigating damage in the case of a compromise.As Sigler puts it, “When dealing with threat intel data, you could be looking at PBs (petabytes) of data. To be able to handle, query, clean, analyze, and sort that data, your company needs a lot of processing and storage power.”Your organization’s data infrastructure should weigh into your decision-making when considering adopting a new threat intel source or figuring out how you will leverage threat intel in your organization.If you don’t feel like your organization has the right infrastructure (yet), don’t worry. Sigler has some suggestions for smaller or newer companies later in this article.Looking for the Right Team
“You need invest in people before you invest in a threat intel provider.”
- Information Security Knowledge
This is key to understanding how to apply and use threat intelligence data. This is important, for example, when trying to improve processes based on updated malicious IP data or when detecting intrusive signals from exploit kits. Without infosec knowledge, your organization can be at a loss on how to take advantage of new threat intel. - Data Science and Analytics
The skill set of using and applying algorithms, advanced statistics, and general data science principles are necessary when dealing with such a large amount of data. Hundreds of billions of records need to be analyzed, cleaned and processed to discover trends and identify what’s important and what can be used as part of your current organization’s processes. - Programming and Database knowledge
Hard skills related to knowing and understanding databases (back-end and front-end), implementation, and more advanced subjects around machine learning are also critical. This is in addition to using querying and programming languages (such as SQL and R, which Karl notes is a popularly used language in statistical analysis and threat intelligence).



