Topic: Traditional Risk Assessments Fall Short; Three Things to Look for in Threat Intelligence
Notes
• Why traditional risk assessments fall short
o Static snapshots: Often performed annually or quarterly, missing fast-moving
threats and shifting vendor/asset landscapes.
o Siloed data: Risk scores come from isolated sources (IT, security, OT) with little
cross-domain correlation, leading to inconsistent priorities.
o Lacking context: Aggregated scores without explainable reasoning or actionable
remediation steps, reducing usefulness for decision-making.
o Slow adaptation: Do not account for new threat chatter, zero-days, or changes in
adversary tactics, techniques, and procedures (TTPs).
o Incomplete third-party view: Vendor risk often focuses on compliance checklists
rather than dynamic, real-world exposure.
• Three things to look for in threat intelligence (as a supplement to risk assessments)
o Automation and machine learning
▪ Capabilities: automated enrichment of indicators, correlation of events
across datasets, anomaly detection, and predictive risk scoring.
▪ Benefits: faster signal-to-noise ratio, scalable triage, adaptive risk models
that reflect evolving threat landscapes.
▪ Practical signals: ML-based risk scoring, automated playbooks, dynamic
alerting thresholds, and evidence-backed remediation guidance.
o Real-time updates to risk scores
▪ Capabilities: continuous ingestion of threat feeds, vulnerability advisories,
exploit activity, and exposure changes (e.g., new CVEs, new indicator
relationships).
▪ Benefits: timely prioritization of incidents, reduction of alert fatigue, near-
term containment actions aligned with current risk posture.
▪ Practical signals: live risk dashboards, per-asset risk deltas, alerting on
sudden score jumps, and time-stamped rationale for changes.
o Transparent risk assessments
▪ Capabilities: explainable scoring with clear methodology, data
provenance, and traceability from signals to risk.
▪ Benefits: trust and accountability, ability to challenge or adjust weighting,
audit-ready reporting for governance.
▪ Practical signals: documented scoring model, data sources catalog,
sensitivity analyses, and actionable remediation steps linked to each risk
finding.
• How to operationalize these three elements
o Integrate diverse feeds
▪ Threat intel feeds (TTPs, IOC/IP, malware hashes)
▪ Vulnerability data (CVEs, exploit activity, exploit kits)
▪ Vendor/third-party risk signals (security posture, incident history)
▪ Internal telemetry (EDR, SIEM, vulnerability scanners, asset inventory)
o Build or adopt an adaptive risk scoring framework
▪ Use continuous scoring with delta tracking for assets over time.
▪ Weight signals by relevance to critical assets and business impact (e.g.,
crown jewels, data sensitivity).
▪ Include confidence levels for each signal; factor remediation status into
scores.
o Automate decision aids and runbooks
▪ Create automated containment and remediation playbooks triggered by
specific risk thresholds.
▪ Provide prioritized, evidence-based guidance (e.g., patch this CVE on
asset X within Y hours; rotate credentials; isolate segment).
o Enhance transparency and governance
▪ Publish data provenance for risk factors (source, timestamp, confidence).
▪ Document the scoring model and any adjustments; provide an auditable
trail.
▪ Include risk appetite alignment (what scores trigger executive alerts vs.
operational remediation).
o Ensure feedback loops
▪ Analysts can annotate and challenge scores, with outcomes feeding back
into the model.
▪ Post-incident reviews update models to reflect lessons learned.
Topic: Responding to High Third-Party Risk Scores
Notes
• Recognize the spectrum of third-party risk
o Data confidentiality, integrity, and availability impacts from supplier systems.
o Access provided to networks (SaaS, IDS/PS, API integrations).
o Geography, regulatory compliance exposure (GDPR, HIPAA, industry-specific
standards).
o Supply chain dependencies (critical components, single points of failure).
• Immediate response steps for high third-party risk scores
o Validate the signal
▪ Cross-check with vendor’s own disclosures, third-party assessments, and
recent incidents.
▪ Verify the scope: which systems, data sets, and interfaces are affected.
o Containment and minimization
▪ Limit access to the minimum required scope; apply network segmentation
where feasible.
▪ Enforce stronger authentication, rotate credentials, and review API keys or
tokens.
o Mitigate and remediate
▪ Request or ensure timely remediation plans from the vendor.
▪ Implement compensating controls (additional monitoring, data loss
prevention, stricter data handling).
o Contractual and governance actions
▪ Escalate to procurement and legal if risk exceeds tolerance; review and
tighten SLAs, security addenda, and termination rights.
▪ Require evidence of ongoing monitoring, vulnerability remediation, and
incident response testing.
o Communication and escalation
▪ Notify internal stakeholders (CISO, risk management, legal, business
units) with clear impact.
▪ Prepare external communications if data is exposed or regulated data is at
risk.
o Sustained monitoring and reassessment
▪ Increase monitoring of the vendor’s security posture and any changes to
their controls.
▪ Re-evaluate risk score after remediation or governance actions; set a clear
timeline for reassessment.
• Best practices for ongoing third-party risk management
o Vendor risk taxonomy and baseline expectations
▪ Define what constitutes acceptable risk, required controls, and response
timelines upfront.
o Continuous monitoring and automation
▪ Integrate vendor risk signals with your internal risk posture in real time.
o Regular reassessment cadence
▪ Schedule periodic re-assessments (e.g., quarterly) and trigger urgent
reviews for material changes.
o Collaboration and transparency
▪ Establish a shared security improvement plan with critical vendors.
o Incident preparedness
▪ Ensure your incident response plan includes third-party compromise
scenarios and the steps to coordinate with vendors.
Optional enhancements and discussion prompts
• If you’re presenting to leadership, prepare a one-page executive summary with:
o The gaps in traditional risk assessments
o The three capabilities to adopt (automation/ML, real-time risk, transparent
assessments)
o A high-level implementation roadmap and required investment
• For a technical audience, provide sample data models:
o Asset-centric risk score schema with incoming signals, confidence, delta, and
remediation steps
o Third-party risk dashboard layout ideas showing current risk, trend, and SLA
statuses
• Metrics to track success
o Time-to-detect and time-to-remediate for third-party incidents
o Percentage of assets with real-time risk scores vs. static scores
o Reduction in alert fatigue and mean time to containment after vendor-related
alerts
1. Threat Intelligence for Digital Risk Protection: Being Online Is Being at Risk
In a connected era, every online presence (website, app, social profile, domain,
marketplace listing) can introduce risk. Threat intelligence helps detect, understand, and
mitigate these online exposures before they translate into real-world impact.
• Why online presence matters:
o Brand exposure across the web creates attack surfaces (phishing sites,
impersonation, data leakage).
o Adversaries target customer touchpoints (logins, payments, support channels) to
commit fraud or steal credentials.
o Digital channels enable data collection, credential reuse, and reputational damage.
• Threat intelligence role:
o Proactive discovery: identify external risks that could affect customers, partners,
or operations.
o Contextual alerts: map external risks to assets, stakeholders, and business
processes.
o Rapid response enablement: guide takedown, remediation, and communications.
• Practical actions:
o Monitor a broad set of online domains: official sites, typosquats, subdomains,
marketplaces, social platforms, app stores.
o Track brand-related indicators: brand names, logos, domain registrations,
impersonation activity.
o Correlate external indicators with internal exposure (e.g., compromised
credentials, leaked data tied to your brand).
o Develop and practice playbooks for impersonation, data leakage, and credential
stuffing incidents.
o Align with legal, communications, and IT security for coordinated response.
2. Types of Digital Risk
Digital risk refers to potential negative outcomes arising from the online environment that
can affect assets, operations, and reputation. It spans multiple domains.
• Major risk types:
o Brand risk
▪ Impersonation, counterfeit domains, logo/name misuse, misleading
advertising.
o Cyber risk
▪ Phishing campaigns, malware distribution, credential stuffing, account
takeover via online channels.
o Data risk
▪ Leakage or exposure of sensitive information through misconfigurations,
insecure apps, or data sharing.
o Supply chain risk
▪ Dependencies on exposed third parties, vendor compromises, and third-
party services integrated online.
o Regulatory/compliance risk
▪ Violations related to data handling, cross-border transfers, and platform
policies.
o Operational risk
▪ DDoS, platform outages, or service disruptions affecting digital
experiences.
• Addressing digital risk:
o Build a layered threat intel program that detects, contextualizes, and mitigates
each risk type.
o Establish ownership, accountability, and measurable remediation plans.
o Integrate risk findings into governance, risk, and compliance (GRC) workflows.
o Continuously monitor and adapt to evolving online threats and regulatory
requirements.
3. Uncovering Evidence of Breaches on the Web
Detect breach-related footprints outside the organization’s internal environment to enable
rapid containment and response.
• Sources to monitor:
o Paste sites, forums, hacker marketplaces, and dark web chatter.
o Data breach repositories and leaked data dumps.
o Social media posts and discussions mentioning compromised credentials or
targeted products.
o Public search results revealing exposed data or exposed credentials.
• Indicators of compromise (IoCs) to look for:
o Leaked credentials with organization-specific formats (e.g., employee emails,
domain names, internal endpoints).
o Exposed PII, passwords, API keys, or internal tokens tied to your organization.
o Mentions of targeted exploits against your products or services.
• Validation and response workflow:
o Validate signals by cross-referencing multiple sources for authenticity.
o Assess potential impact and determine affected assets, users, or processes.
o Notify stakeholders, initiate containment actions (credential resets, access
revocation), and coordinate incident response.
o Update risk registers, remediation plans, and regulatory notifications as required.
• Prevention and readiness:
o Strengthen credential hygiene (MFA, unique passwords, credential stuffing
defenses).
o Maintain a rapid breach response playbook and regular tabletop exercises.
o Continuously monitor new data exposures and adjust monitoring scope.
4. Uncovering Evidence of Brand Impersonation and Abuse
Detect and mitigate attempts to impersonate your brand that could mislead customers, erode
trust, or cause financial loss.
• Common impersonation patterns:
o Brand impersonation domains (typosquatting, homoglyphs, lookalike URLs).
o Fake social media accounts or profiles claiming affiliation with your brand.
o Misleading apps, browser extensions, or counterfeit product listings.
o Unauthorized use of logos, trademarks, or product names in content and ads.
• Detection methods:
o Brand monitoring across domains, social platforms, app stores, marketplaces, and
advertising networks.
o Visual and logo recognition to identify lookalikes and fake branding.
o Automated takedown workflows with registrars, platforms, and law enforcement
where appropriate.
• Response actions:
o Initiate rapid takedown requests, domain seizures, or platform removals where
permissible.
o Communicate clearly with customers to prevent confusion and manage trust.
o Coordinate with legal, IP, PR, and security teams to pursue enforcement and
strengthen defenses.
o Enhance brand protection: adjust detection thresholds, expand monitoring to new
channels, and educate customers.
• Metrics to track:
o Time-to-detection, time-to-takedown, reach and impact of impersonation assets,
customer impact, and incident cost.
5. Critical Qualities for Threat Intelligence Solutions
• Core capabilities to evaluate when selecting or evaluating solutions:
o Coverage and breadth
▪ Access to diverse data sources (open web, dark web, technical feeds,
internal telemetry, third-party data).
▪ Global reach across regions, languages, and threat actors.
o Timeliness and velocity
▪ Real-time or near-real-time data ingestion, processing, and alerting.
▪ Low latency from data collection to actionable insights.
o Context and enrichment
▪ Rich contextual mapping of IoCs to campaigns, actors, and business
impact.
▪ Asset-centric view: mapping to domains, IPs, employees, products, and
supply chain elements.
o Accuracy and signal quality
▪ Low false positives, clear scoring, explainability of indicators.
▪ Proven methods to validate indicators and reduce noise.
o Automation and integration
▪ Playbooks, automation capabilities, and native or seamless integration
with SIEM, SOAR, ticketing, and risk platforms.
o Risk scoring and prioritization
▪ Transparent scoring models with explainable drivers.
▪ Prioritization aligned with asset criticality and business impact.
o Actionability and workflows
▪ Concrete remediation steps, playbooks, and cross-functional collaboration
between security, legal, brand, PR, and IT.
o Governance and trust
▪ Data provenance, source credibility, and change history.
▪ Compliance with privacy and data protection laws and ethical standards.