<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CTI - RiskInsight</title>
	<atom:link href="https://www.riskinsight-wavestone.com/en/tag/cti-en/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.riskinsight-wavestone.com/en/tag/cti-en/</link>
	<description>The cybersecurity &#38; digital trust blog by Wavestone&#039;s consultants</description>
	<lastBuildDate>Wed, 27 May 2026 08:07:42 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/Blogs-2024_RI-39x39.png</url>
	<title>CTI - RiskInsight</title>
	<link>https://www.riskinsight-wavestone.com/en/tag/cti-en/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Amplifying Cyber Threat Intelligence with AI: A Pragmatic, Maturity Driven Approach</title>
		<link>https://www.riskinsight-wavestone.com/en/2026/05/amplifying-cyber-threat-intelligence-with-ai-a-pragmatic-maturity-driven-approach/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2026/05/amplifying-cyber-threat-intelligence-with-ai-a-pragmatic-maturity-driven-approach/#respond</comments>
		
		<dc:creator><![CDATA[Pauline Hendi]]></dc:creator>
		<pubDate>Wed, 27 May 2026 08:07:40 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Ethical Hacking & Incident Response]]></category>
		<category><![CDATA[Focus]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[AI in Cybersecurity]]></category>
		<category><![CDATA[AI4CTI]]></category>
		<category><![CDATA[Automatisation CTI]]></category>
		<category><![CDATA[CTI]]></category>
		<category><![CDATA[CTI automation]]></category>
		<category><![CDATA[Cyber Threat Intelligence]]></category>
		<category><![CDATA[cybersécurité]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[IA]]></category>
		<category><![CDATA[Natural Language Processing]]></category>
		<category><![CDATA[NLP]]></category>
		<category><![CDATA[offensive security]]></category>
		<category><![CDATA[RAG]]></category>
		<category><![CDATA[Threat Detection & Hunting]]></category>
		<category><![CDATA[vulnerability management]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=29986</guid>

					<description><![CDATA[<p>Against a backdrop of heightened geopolitical tensions, recent years have been marked by an upsurge in cyber threats, illustrated by the strengthening of attackers’ capabilities, the diversification of their tactics and even the enhancement of their operations thanks to artificial...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2026/05/amplifying-cyber-threat-intelligence-with-ai-a-pragmatic-maturity-driven-approach/">Amplifying Cyber Threat Intelligence with AI: A Pragmatic, Maturity Driven Approach</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p style="text-align: justify;">Against a backdrop of heightened geopolitical tensions, recent years have been marked by an upsurge in cyber threats, illustrated by the strengthening of attackers’ capabilities, the diversification of their tactics and even the enhancement of their operations thanks to artificial intelligence (ANSSI, Cyberthreat Landscape Overview 2025).</p>
<p style="text-align: justify;">In this context, integrating Cyber Threat Intelligence (CTI) into organizations’ cybersecurity strategy and overall posture has become a key asset to anticipating increasingly sophisticated and innovative attacks and their potential operational impacts. Indeed, CTI provides early insight into potential threats and supports proactive posture by strengthening detection, reinforcing defenses, and enhancing incident responses. More than just collecting raw indicators, it constitutes a decision-driven process, aimed at improving the understanding of adversaries by turning data into actionable intelligence capable of answering precise cybersecurity questions.</p>
<p style="text-align: justify;">In general, we distinguish three complementary forms of intelligence to reinforce an organization’s cybersecurity posture:</p>
<ul style="text-align: justify;">
<li>Strategic, guiding long‑term decisions and investment priorities,</li>
<li>Tactical, analyzing attackers’ tools and Tactics, Technics and Procedures (TTPs) to shape defensive posture,</li>
<li>Operational and technical, providing actionable details such as Indicators of Compromise (IoCs) and Indicators of Attack (IoAs) to counter specific, recent threats.</li>
</ul>
<p style="text-align: justify;">As CTI spans multiple levels of decision‑making, its effectiveness depends on an organization’s ability to process growing volumes of heterogeneous data, detect weak signals, and produce actionable intelligence across all layers. These capabilities remain highly challenging for traditional CTI tools given data volume and heterogeneity. Throughout this article, we will present several use cases in which the use of enterprise-internal AI acts as a powerful lever to truly enhance CTI. To do so, our analysis is grounded in the CTI‑CMM model, which provides stakeholders with a structured framework for strengthening their CTI maturity. Designed to assess a program’s maturity and capability growth, the CTI‑CMM proposes a comprehensive mapping of CTI use cases across eleven domains, providing a clear and systematic foundation for evaluating where AI can most effectively enhance CTI activities.</p>
<p style="text-align: justify;">Not all AI use cases in CTI deliver the same value or should be approached in the same way. Building on its experience across CTI engagements, Wavestone has developed a three-tier model – Safe Wins, Accelerators, and Frontier Bets – designed to structure use cases based on their AI maturity, impact on decision-making, and alignment with an organization’s CTI maturity.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><img fetchpriority="high" decoding="async" class="aligncenter size-full wp-image-29964" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/05/A-Maturity-Based-3-Tier-Model-for-AI-Enhanced-CTI-Use-Cases.png" alt="A Maturity-Based 3-Tier Model for AI-Enhanced CTI Use Cases" width="1088" height="658" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/05/A-Maturity-Based-3-Tier-Model-for-AI-Enhanced-CTI-Use-Cases.png 1088w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/05/A-Maturity-Based-3-Tier-Model-for-AI-Enhanced-CTI-Use-Cases-316x191.png 316w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/05/A-Maturity-Based-3-Tier-Model-for-AI-Enhanced-CTI-Use-Cases-64x39.png 64w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/05/A-Maturity-Based-3-Tier-Model-for-AI-Enhanced-CTI-Use-Cases-768x464.png 768w" sizes="(max-width: 1088px) 100vw, 1088px" /></p>
<p style="text-align: justify;"> </p>
<h2 style="text-align: justify;">Safe Wins</h2>
<p style="text-align: justify;"><strong>“Safe Wins” are use cases where AI can already improve CTI performance with minor changes to a “traditional” CTI governance model</strong> (i.e., analyst accountability, validation and dissemination workflows, and control over what is automated versus what remains expert judgment). They are low-regret and easy to implement, delivering fast ROI by automating high-volume tasks such as filtering, enrichment, and correlation. Outputs are reversible, errors are easy to detect, and AI is typically used for triage or processing, making them ideal entry points.</p>
<p> </p>
<h3 style="text-align: justify;">AI to enhance threat detection and preparedness (1a.)</h3>
<p style="text-align: justify;">AI has become a powerful ally in processing and correlating unstructured data collected through Threat Intelligence Platforms (TIP) to be transformed into actionable intelligence. While organizations should rely on TIP for data collection on IOCs and IOAs from human-selected qualitative feeds and OSINT sources, the true added value of enterprise-controlled AI for attack prevention and preparedness lies in its capacity to improve the quality of incoming data through confidence scoring. Given its capacity to process vast amount of data quickly (IP, domain, hash, behavior, etc.), AI can be used to correlate features (e.g., similarities to past malware, links to threat actors, unusual behavior) and verify false positives in incoming IOCs to assign a confidence score and avoid blocking relevant information on the Blue Team side.</p>
<p> </p>
<h3 style="text-align: justify;">AI to structure and standardize CTI data analysis and report (1b.)</h3>
<p style="text-align: justify;">AI can support CTI teams by assisting in the analysis of raw intelligence data from multiple sources using large language models. It helps restructure reports according to standardized models such as STIX, ensuring that the right information is placed in the appropriate fields. Attacker procedures, techniques, and contextual elements can be extracted and transformed into structured data in a consistent manner. This improves overall data quality, readability, and interoperability with TIPs and downstream security tools. As a relatively simple and low risk use case, it primarily acts as an analyst productivity booster for structuring reports in a standardized format.</p>
<p> </p>
<h3 style="text-align: justify;">AI to operationalize CTI for offensive security operations (1c.)</h3>
<p style="text-align: justify;">When it comes to red and purple team activities, AI acts as a strong enabler by helping CTI teams identify recurring TTPs across reports, cluster similar procedures, and consolidate duplicates into exploitable building blocks. AI can support analysts in extracting the most relevant information from threat reports and OSINT to maintain a consistent and actionable threat-driven knowledge base. AI can also help generate macro scenarios based on threat reports and publicly available intelligence, including actor selection and attack patterns. However, to be considered a safe win it must remain a decision-support tool, as end-to-end technical scenario generation would require sensitive data, the adequate responsibility model, and data confidentiality safeguards to avoid improper exposition and misuse.</p>
<p> </p>
<h3 style="text-align: justify;">AI to support strategic alignment of intelligence requirements (1d.)</h3>
<p style="text-align: justify;">AI can also support the definition and refinement of priorities and objectives within the threat intelligence function. More specifically, AI participates in accelerating analytical processes by assisting in the drafting and continuous refinement of priority intelligence requirements (PIRs) and proposing stakeholder-tailored reporting frameworks. It also helps distill complex program signals into intermediate insights, enabling analysts to focus on interpretation and decision‑making. Human validation remains essential to ensure alignment with the organization’s broader cyber strategy and performance frameworks. However, failing to account for AI’s inherent limitations, particularly in terms of accuracy, reliability, and explainability, may introduce significant risks, including the generation of misleading insights that could misalign intelligence outputs with enterprise cybersecurity objectives.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">These &#8220;Safe Wins&#8221; illustrate how AI can already strengthen CTI across several operational dimensions: improving the quality and exploitation of intelligence data for defensive activities (a), accelerating the structuring and usability of CTI reporting (b), supporting threat-informed offensive security operations through better TTP extraction and scenario preparation (c), and assisting in the drafting of intelligence requirements and designing of reporting. By enhancing efficiency, consistency, and scalability across these activities, these use cases establish a strong foundation for the next tier of applications, where AI supports more analytical and decision-driven processes requiring greater maturity and governance.</p>
<p style="text-align: justify;"> </p>
<p><img decoding="async" class="aligncenter size-full wp-image-29970" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/05/Safe-Wins-Use-Cases-Across-the-CTI-Lifecycle.png" alt="Safe Wins Use Cases Across the CTI Lifecycle" width="1200" height="482" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/05/Safe-Wins-Use-Cases-Across-the-CTI-Lifecycle.png 1200w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/05/Safe-Wins-Use-Cases-Across-the-CTI-Lifecycle-437x176.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/05/Safe-Wins-Use-Cases-Across-the-CTI-Lifecycle-71x29.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/05/Safe-Wins-Use-Cases-Across-the-CTI-Lifecycle-768x308.png 768w" sizes="(max-width: 1200px) 100vw, 1200px" /></p>
<p> </p>
<h2 style="text-align: justify;">High-Potential Accelerators</h2>
<p style="text-align: justify;"><strong>“High-potential Accelerators” target more mature CTI teams, where AI acts as a force multiplier rather than a substitute for expertise. </strong>They significantly amplify analyst productivity by scaling detection, supporting hypothesis generation, and translating intelligence into actionable outputs. However, these use cases require high-quality contextual data, structured processes, and robust governance (e.g., human-in-the-loop, explainability, feedback loops) to ensure reliable and controlled outcomes.</p>
<p> </p>
<h3 style="text-align: justify;">AI to scale financial fraud and brand impersonation detection (2a.)</h3>
<p style="text-align: justify;">AI can enhance CTI by scaling the identification of fraud and brand impersonation assets across large data streams and monitored perimeters. It enables the detection of newly created lookalike domains and cloned websites/logos across domains using NLP<sup>[1]</sup>, computer vision, and behavioral analytics. These assets can be enriched with technical indicators (DNS, hosting infrastructure, registration patterns) and contextual signals (content similarity, redirection flows), then correlated into coherent attack campaigns and ingested into TIPs. The resulting intelligence can be disseminated to blue teams to support detection, blocking, and take-down actions. While the automation of large-scale discovery and triage allows CTI teams to focus on validation, prioritization, and business impact, it requires strong governance and coordination between CTI, fraud/brand protection, legal, and security operations teams to minimize false positives and ensure effective response.</p>
<p> </p>
<h3 style="text-align: justify;">AI to prioritize vulnerability patching (2b.)</h3>
<p style="text-align: justify;">AI can support vulnerability management by dynamically prioritizing patching efforts based on threat intelligence, underlying technologies, and the exposure and criticality of business applications. By combining threat context, exploit activity, asset environment, and enterprise-specific constraints, AI can estimate a risk score for each vulnerability. This score is used to raise targeted alerts and guide patching teams toward the most critical remediation actions. The approach embeds all threat-related elements within the organization’s context, allowing AI to act as an intelligent decision-support layer rather than a generic scoring mechanism. This use case complexity arises from the need for AI to access and correlate large volumes of sensitive and critical data across security, IT, and asset management systems.</p>
<p> </p>
<h3 style="text-align: justify;">AI to support threat hunting and penetration testing (2c.)</h3>
<p style="text-align: justify;">When it comes to guiding proactive hunt hypotheses and prioritizing them using threat‑actor TTPs, campaigns, and priority intelligence requirements, AI adds real momentum. It can help generating hunting hypotheses from observed TTPs, turning them into queries or playbooks, highlighting which hunts should come first based on PIRs, vulnerabilities, or asset signals, and summarizing the results of ongoing investigations. Paired with an internal knowledge base or RAG<sup>[2]</sup>‑enhanced context, AI supports hunters move through their environment with greater clarity and focus. Additionally, AI can assist the teams in the execution of penetration testing and adversary simulation activities. By automating offensive workflows and simulating complex, real-world attack scenarios, it enables more scalable, efficient, and realistic testing, helping teams better keep pace with increasingly AI-enabled threats. However, this does not imply that AI can replace CTI and offensive security teams. Success in AI-supported penetration testing relies on expert control, business awareness, and rigorous risk management. Human expertise remains essential for interpreting results and making informed decisions.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">Taken together, these High-potential Accelerator cases show how AI amplifies CTI across three core functions: detecting financial fraud and brand impersonation threats (a), prioritizing vulnerability patching (b), and enhancing proactive threat hunting and validation of adversary behaviors (c). Acting as a force multiplier rather than a substitute, AI accelerates intelligence exploitation, improves prioritization, and strengthens decision-making.</p>
<p> </p>
<p><img decoding="async" class="aligncenter size-full wp-image-29968" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/05/High-Potential-Accelerators-Use-Cases-Across-the-CTI-Lifecycle.png" alt="" width="1177" height="473" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/05/High-Potential-Accelerators-Use-Cases-Across-the-CTI-Lifecycle.png 1177w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/05/High-Potential-Accelerators-Use-Cases-Across-the-CTI-Lifecycle-437x176.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/05/High-Potential-Accelerators-Use-Cases-Across-the-CTI-Lifecycle-71x29.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/05/High-Potential-Accelerators-Use-Cases-Across-the-CTI-Lifecycle-768x309.png 768w" sizes="(max-width: 1177px) 100vw, 1177px" /></p>
<p> </p>
<h2 style="text-align: justify;">Frontiers Bets</h2>
<p style="text-align: justify;"><strong>“Frontier Bets” represent more complex and experimental AI applications in CTI, requiring significant transformation of operating models and strong governance frameworks. </strong>Compared to the two other tiers, they involve higher uncertainty, stronger dependency on data quality, and risks that are harder to detect or control (e.g., bias, hallucination, strategic misalignment). As such, they should be approached through controlled experimentation, with strict guardrails, human oversight, and iterative validation before scaling.</p>
<p> </p>
<h3 style="text-align: justify;">AI to improve situational awareness of the cyber threat landscape (3a.)</h3>
<p style="text-align: justify;">AI could help maintain a comprehensive understanding of the cyber threat landscape by serving as a preliminary layer of analysis before CTI experts validate and expand it. More broadly, it could enable the continuous synthesis of the threat landscape from OSINT sources, partners, and vendors, and the detection of emerging trends and correlations for informed strategic decision-making. While the autonomous drafting of CTI reports by large language models raises the risk of biased outputs and AI hallucinations, AI should initially be used to support analysts in drafting activities to help them gain time in the analysis of cyber threats, serving as a pragmatic first step toward broader AI integration in this use case.  The market maturity for use cases supporting the full intelligence lifecycle remains limited, with few industrialized and proven solutions available.</p>
<p> </p>
<h3 style="text-align: justify;">AI to enhance identity-based threat detection and response (3b.)</h3>
<p style="text-align: justify;">AI could strengthen CTI for identity‑driven use cases by enabling earlier detection of attacker behaviors and supporting deception techniques such as honey accounts<sup>[3]</sup> or canary tokens<sup>[4]</sup> to expose and divert adversaries. By treating identities as active sensors, organizations can surface stealthy attacker activity before full compromise. AI could help scale these mechanisms by automating deployment, continuously tuning detection signals, and correlating weak indicators. It could also reduce analyst workload through intelligent alert triage, prioritizing high‑confidence identity‑related threats over noise. Despite its high potential for CTI and IAM teams, this use case remains at an experimental stage due to the limited maturity of identity‑centric deception techniques, integration complexity with IAM and SOC processes, and the need for strong governance to avoid false positives, operational overhead, or unintended exposure of deception assets.</p>
<p> </p>
<p><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-29966" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/05/Frontier-Bets-Use-Cases-Across-the-CTI-Lifecycle.png" alt="" width="1199" height="475" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/05/Frontier-Bets-Use-Cases-Across-the-CTI-Lifecycle.png 1199w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/05/Frontier-Bets-Use-Cases-Across-the-CTI-Lifecycle-437x173.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/05/Frontier-Bets-Use-Cases-Across-the-CTI-Lifecycle-71x28.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/05/Frontier-Bets-Use-Cases-Across-the-CTI-Lifecycle-768x304.png 768w" sizes="auto, (max-width: 1199px) 100vw, 1199px" /></p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">AI is already transforming how organizations produce and use cyber threat intelligence, not by replacing analysts, but by amplifying their ability to process information and enhance decision-making at scale. This article highlights where enterprise-internal AI can deliver value to CTI by focusing on the use cases most relevant in practice. To structure this approach, we introduced a pragmatic three-tier model to help prioritize efforts and adopt AI progressively based on the organization’s maturity, from low-risk &#8220;Safe Wins&#8221; to more advanced use cases dependent on high-quality data, robust governance as well as human oversight and AI model explainability.</p>
<p style="text-align: justify;">Organizations should therefore focus on applying AI where it creates measurable value and aligns with their level of maturity, reinforcing a key reality: AI does not create CTI maturity, it amplifies it. Recent developments such as Anthropic’s Mythos also illustrate a broader shift in the cyber landscape: AI is beginning to compress the gap between vulnerability discovery and operational exploitation, while significantly reducing the cost and complexity of large-scale offensive operations. While the exact pace and scale of this evolution remain uncertain, it highlights the need for organizations to become “Mythos-ready” by enabling teams to leverage AI for defense while ensuring robust cybersecurity fundamentals.</p>
<p style="text-align: justify;">At Wavestone, we support organizations in navigating this transformation, from identifying high-potential use cases to implementing AI in a controlled, scalable, and value-driven manner across their CTI capabilities.</p>
<p> </p>
<hr />
<p style="text-align: justify;"><sup>[1]</sup><span style="text-decoration: underline;"><strong>NLP (Natural Language Processing) :</strong></span> AI techniques used to analyze and understand human language in text or speech</p>
<p style="text-align: justify;"><sup>[2]</sup><span style="text-decoration: underline;"><strong>RAG (Retrieval‑Augmented Generation) :</strong></span> AI approach in which a generative model is systematically enriched with relevant contextual information retrieved from curated knowledge sources at query time, allowing it to produce outputs that are better aligned with a given operational or analytical context</p>
<p style="text-align: justify;"><sup>[3]</sup><strong><span style="text-decoration: underline;">Honey account :</span></strong> A decoy user account created to mimic a legitimate identity, used to detect unauthorized access when an attacker attempts to use it</p>
<p style="text-align: justify;"><sup>[4]</sup><span style="text-decoration: underline;"><strong>Canary token :</strong></span> A planted digital artifact (e.g., credential, file, or link) that triggers an alert when accessed or used, revealing potential malicious activity</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2026/05/amplifying-cyber-threat-intelligence-with-ai-a-pragmatic-maturity-driven-approach/">Amplifying Cyber Threat Intelligence with AI: A Pragmatic, Maturity Driven Approach</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2026/05/amplifying-cyber-threat-intelligence-with-ai-a-pragmatic-maturity-driven-approach/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Citalid &#124; Shake Up &#8211; Cyber Threat Intelligence for optimizing cyber budgets</title>
		<link>https://www.riskinsight-wavestone.com/en/2020/11/cyber-threat-intelligence-for-optimizing-cyber-budgets/</link>
		
		<dc:creator><![CDATA[Maxime Cartan]]></dc:creator>
		<pubDate>Tue, 03 Nov 2020 17:48:01 +0000</pubDate>
				<category><![CDATA[Cyberrisk Management & Strategy]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[budget]]></category>
		<category><![CDATA[citalid]]></category>
		<category><![CDATA[CTI]]></category>
		<category><![CDATA[FAIR]]></category>
		<category><![CDATA[finance]]></category>
		<category><![CDATA[investment]]></category>
		<category><![CDATA[optimization]]></category>
		<category><![CDATA[quantification]]></category>
		<category><![CDATA[shake'up]]></category>
		<category><![CDATA[startups]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=14585</guid>

					<description><![CDATA[<p>Citalid is a French tech startup founded in 2017 that provides CISOs and Risk Managers with a software for quantifying and managing cyber risk. Citalid&#8216;s highly innovative technology enables its clients to benefit from simulations, metrics and recommendations that are...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/11/cyber-threat-intelligence-for-optimizing-cyber-budgets/">Citalid | Shake Up &#8211; Cyber Threat Intelligence for optimizing cyber budgets</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><strong><em>Citalid</em></strong><em> is a French tech startup founded in 2017 that provides CISOs and Risk Managers with a software for quantifying and managing cyber risk. <strong>Citalid</strong>&#8216;s highly innovative technology enables its clients to benefit from simulations, metrics and recommendations that are directly operational to optimize their ROSI (Return On Security Investments) thanks to its unique ability to cross-reference technical, contextual and financial data. <strong>Citalid</strong> is part of Wavestone&#8217;s startup acceleration programme, Shake&#8217;Up.</em></p>
<p>&nbsp;</p>
<p><img loading="lazy" decoding="async" class="size-full wp-image-14516 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/citalid-2.png" alt="" width="1082" height="378" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/citalid-2.png 1082w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/citalid-2-437x153.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/citalid-2-71x25.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/citalid-2-768x268.png 768w" sizes="auto, (max-width: 1082px) 100vw, 1082px" /></p>
<p><strong><em> </em></strong></p>
<p>For the time being less well known and less widespread in Europe than its sisters <strong>EBIOS RM &amp; Mehari</strong> (among others), the FAIR risk analysis method nevertheless fills the gaps left by other approaches. Already highlighted by <strong>Wavestone</strong> in a <a href="https://www.riskinsight-wavestone.com/en/2020/10/cyber-risk-quantification-understanding-the-fair-methodology/">previous article</a>, its main assets lie in the perspective of data usually ignored by traditional risk analysis on the one hand, and on the other hand in its ability to generate metrics dedicated to strategic decision support and adapted to the language of decision-makers, such as <em>Value at Risk</em>.</p>
<p>Nevertheless, as this same article points out, this approach is a priori undermined by time, human resources and the multiplicity of knowledge required to carry it out. Therefore, although the concept is attractive, is it realistic to deploy the <strong>FAIR</strong> method? How can its nomenclature be translated operationally? What about its automation? More generally, does it provide enough added value to justify its use?</p>
<p>Despite its undeniable effectiveness in quantifying risks, such an approach requires both an appropriate technical system and functional support, which is essential in the collection of data. Quantifying its potential financial losses in the event of a cyber incident is not enough: it is also necessary to have the capacity to put them into perspective in an ecosystem of polymorphous and evolving threats. This is <strong>Citalid</strong>&#8216;s innovation: to be able to carry out a dynamic quantification of cyber risk for decision-makers, by automatically crossing the reality of the threat that weighs on a company, its business context and its defensive maturity. And, above all, not to stop at analysis alone: to generate an action plan that reflects the optimal balance between efficiency and profitability.</p>
<p>&nbsp;</p>
<h2>Empiricism as FAIR&#8217;s automation framework</h2>
<h3>Contextualizing the external environment</h3>
<p>As in any analysis, the objectivity of the observation increases with the number of parameters considered. If it is frequent, even usual, that the internal context of an information system is studied, it is rarer for the analyst to be interested in all the external dynamics that can influence the analysis. These dynamics, which can take on a variety of realities as we shall see, can however strongly influence the frequency and intensity of cyber threats. However, it is difficult to draw up an exhaustive typology of these data, and taking them into account is almost systematically a mixture of two ingredients:</p>
<ul>
<li>Curiosity and the logical mind of the analyst (<em>in fine</em>, his capacity to project himself into / adapt to a context);</li>
<li>The good visibility of the person(s) responsible for the system and the activities within their perimeters;</li>
</ul>
<p>Among the exogenous criteria that can influence the risk analysis are: the competitive environment, the company&#8217;s position on its market, its geographical locations, geopolitical dynamics, internal policies, the normative framework, the socio-economic climate, the diversity of its activities, etc.</p>
<p>However, it would be easy to get lost in this labyrinth of criteria. It is therefore necessary to support the decision-maker in the creation of a cartography of its environment in the most comprehensive sense of the term. It is therefore through exchange and collective intelligence that a first level of filter is created, by drawing up a perimeter of analysis that is both structured and flexible.</p>
<p>While defining the perimeter of the analysis makes it possible to establish a coherent framework, a multitude of risks can nevertheless be inserted into it. It should also be noted that the defined perimeter can itself be a component of a broader scope of analysis. In this sense, the various perimeters determined can be articulated in the form of a hierarchical tree, often tracing the internal organisation of the company (see diagram below).</p>
<p>&nbsp;</p>
<p><img loading="lazy" decoding="async" class="size-full wp-image-14452 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-1.png" alt="" width="601" height="433" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-1.png 601w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-1-265x191.png 265w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-1-54x39.png 54w" sizes="auto, (max-width: 601px) 100vw, 601px" /></p>
<p>&nbsp;</p>
<p>Thus, in the example opposite, the group level is represented by the &#8220;<em>Energy Company</em>&#8221; perimeter, which aggregates the risk of all its &#8220;children&#8221; perimeters (here its &#8220;<em>business units</em>&#8220;). However, each perimeter has its own context and risks. This tree structure plays a predominant role in the construction of a relevant library of related risk scenarios. One could easily be tempted to go back up to the group level to globalize its scenarios, but this often <em>de facto</em> deteriorates the granularity, and therefore the quality, of the analysis due to the particularities of each perimeter.</p>
<p>&nbsp;</p>
<h3>Build a relevant library of scenarios</h3>
<p>This framing work therefore conditions the choice and parameterisation of risk scenarios. This parameterisation and the resulting calculation is made complex by the number of criteria to be taken into account and the uncertainty inherent in cyber risk. Without going back over the FAIR methodology already discussed on this blog, it can therefore be long and tedious to build a large number of scenarios of risk while considering the specificities of each perimeter. A solution to this problem therefore lies in the construction of a library of scenarios that can be adapted to each business context and encompass several types of threats. Based on operators&#8217; experience and accumulated data, Citalid now has several libraries of scenarios and losses, listed in &#8216;Business&#8217; directories. These are easily exportable on the platform, while retaining a degree of flexibility that allows the scenarios indicated to adapt very precisely to the business context. Following on from the use-case used above, the image below illustrates a &#8216;fictitious&#8217; library of scenarios related to the Energy sector. As this is a &#8216;Demo&#8217; version, this panel is however not exhaustive.</p>
<p>&nbsp;</p>
<p><img loading="lazy" decoding="async" class="size-full wp-image-14454 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-2.png" alt="" width="1862" height="629" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-2.png 1862w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-2-437x148.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-2-71x24.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-2-768x259.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-2-1536x519.png 1536w" sizes="auto, (max-width: 1862px) 100vw, 1862px" /></p>
<p>&nbsp;</p>
<p><strong>Citalid</strong>&#8216;s library of scenarios is thus part of a double dynamic that at first sight seems contradictory: capable of meeting the requirements of efficiency and automation of the analysis, it remains flexible enough to be implemented with precision and relevance in any context. Each typology of threat, combined with the characteristics of the perimeter analyzed, determines the frequency of occurrence and the financial losses, whether primary or secondary, inherent in the chosen scenario. In the case of an economic espionage scenario, for example, it is safe to say that there will systematically be a loss related to the remediation of the incident, a loss related to the exfiltration of data and a loss resulting from damage to the entity&#8217;s reputation if the attack were to become public.</p>
<p>In addition, for the quantitative parameters (frequency of the threat, IS resistance to the attack, frequency and magnitude of losses, targeted assets, etc.) of the scenario to remain relevant, they must be profiled on the characteristics of the target perimeter. Therefore, Citalid&#8217;s expertise lies in part in defining and keeping up to date &#8211; cyber threats and available abacus evolving rapidly &#8211; a library of <em>templates</em> from which the analyst must be able to draw to easily and automatically initiate his risk assessment.</p>
<p>Accumulating data on cyber threats and their impacts therefore makes it possible to calibrate scenario &#8220;templates&#8221; and thus gradually automate the <strong>FAIR</strong> analysis. By combining threat intelligence, technical models and abacuses from open source analysis and customer feedback to assist analysts, <strong>Citalid</strong>&#8216;s award-winning innovation platform leverages collective intelligence to ensure scientific rigor and unparalleled accuracy in quantifying financial losses.</p>
<p>&nbsp;</p>
<h2>Putting risks in perspective with the defense ecosystem</h2>
<h3>The CISO as pilot of his IS</h3>
<p>In terms of cybersecurity management, the CISO is, unsurprisingly, the focal point of the system. To do this, he must be able to quickly visualize the entire panorama of cyber risks weighing on his IS &#8211; a &#8220;cockpit&#8221; view, in order to then inflect orientations on a larger scale. He therefore needs a GPS to guide him in his decisions: how to take his IS from point A (current risk situation) to point B (desired risk exposure), taking care to optimize his trajectory (cyber investments) while avoiding obstacles (threats) that appear dynamically along the way.</p>
<p><strong> </strong></p>
<p><img loading="lazy" decoding="async" class="size-full wp-image-14456 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-3.png" alt="" width="1877" height="818" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-3.png 1877w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-3-437x191.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-3-71x31.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-3-768x335.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-3-1536x669.png 1536w" sizes="auto, (max-width: 1877px) 100vw, 1877px" /></p>
<p style="text-align: center;">Example of a <em>risk dashboard</em>, illustrating the ISSM&#8217;s cockpit vision<strong>. </strong></p>
<p>&nbsp;</p>
<p>Once the various scenarios have been established and the quantification carried out, the difficulty lies in the possibility of translating these &#8220;raw&#8221; risks into a strategic roadmap. The first step is to put these risks into perspective by comparing them with the current defensive infrastructure of the IS. Knowledge of its environment is a prerequisite for the CISO&#8217;s analysis. All the more so as, in terms of defensive infrastructure, two major options exist and sometimes complement each other: opting for a logic of defensive maturity based on compliance with one or more reference systems (ISO 27k, NIST, CIS, etc.) or carrying out &#8211; and then comparing with peers &#8211; an inventory and evaluation of all the security solutions deployed on the perimeter.</p>
<p>&#8220;A permanent confrontation between theory and experience is a necessary condition for the expression of creativity&#8221; [1]. 1] The aphorism could not be more revealing of the method described here: that of the confrontation between theory (raw risks) and experience (evaluation of defensive maturity based on a multitude of feedback and incidents) as a necessary condition for the creation of a roadmap. The confrontation makes it possible to obtain the &#8220;net&#8221; risk with which the company is really confronted, lower than the gross risk since it considers the defenses of the IS.</p>
<p>Fueled by &#8220;actionable&#8221; metrics, the decision-maker will now be able to have visibility on his real risk in his own language, and consequently be able to arbitrate and determine its destination &#8211; his B point &#8211; according to his appetite for risk and the company&#8217;s policy. Which scenarios should be dealt with by investing to reduce the associated risk? Which ones should be maintained, given their low economic impact? Which ones to share with a cyber insurer? However, as we will see, the modelling of net risk described in the previous paragraph requires a consequent knowledge of the threat ecosystem in which it is embedded.</p>
<p>&nbsp;</p>
<h3>Cyber Threat Intelligence, a catalyst for optimal risk management</h3>
<p>One of the main shortcomings of risk management in cybersecurity is the difficulty in deploying an approach that reflects the reality of the risk &#8220;on the ground&#8221;. The CISO or Risk Manager must therefore also have a radar to dynamically detect obstacles in his path (threats) and, as far as possible, anticipate and prevent impediments.</p>
<p>Thus, just as a rock slide on a road is the result of a conjunction of multiple factors (weather conditions, geological characteristics, human activity, etc.), an attacker&#8217;s action depends on many elements. These elements should, as far as possible, be observed and included in the risk analysis. Consequently, Cyber Threat Intelligence (CTI), a discipline dedicated to the study and contextualization of attackers&#8217; operating modes, enriches and energizes traditional risk analyses. The mastery and inclusion of this discipline in cyber risk management is one of Citalid&#8217;s major differentiators and permeates its entire corporate culture.</p>
<p>How can CTI data be operationally and sustainably combined with the risk calculations announced in the previous paragraph? We can get an intuition of this by noting the following three facts:</p>
<ul>
<li>The company&#8217;s market segment helps to determine the operating methods most likely to be of interest to the company;</li>
<li>The attack techniques used by these operating methods and their centers of interest within the targeted information systems make it possible to identify the most critical assets and to know how to improve their protection;</li>
<li>By comparing again the CTI data defined in the two previous points with its defensive infrastructure, the entity can identify which scope (in the sense of a security repository) or which defense solution is not cost-effective enough (reduction of the risk in relation to the cost).</li>
</ul>
<p>&nbsp;</p>
<p><img loading="lazy" decoding="async" class="size-full wp-image-14458 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-4.png" alt="" width="1190" height="519" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-4.png 1190w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-4-437x191.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-4-71x31.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-4-768x335.png 768w" sizes="auto, (max-width: 1190px) 100vw, 1190px" /></p>
<p>&nbsp;</p>
<p>The diagram above represents a concrete example of the application of CTI to risk analysis, acting as a real catalyst for drawing up guidelines. A modus operandi is technically expressed through its &#8220;Kill Chain&#8221;, i.e. the sequence of attack techniques it uses to achieve its objective. Citalid has mapped the links between these TTPs (Tactics-Techniques-Procedures) and specific points of different security reference systems (here the CIS20), the latter being the defensive measures best adapted to the TTPs defined in the diagram. On the first line, for example, the CIS 16.3 measure (among others) is sufficiently deployed at the target entity to limit the impact of the TTPs indicated at this stage of the Kill Chain. On the second line, on the other hand, the opposite occurs: the CIS 11.1 measure is not mature enough to provide effective protection against the sophistication of the attacker.  It is therefore on this line that the defender potentially needs to concentrate.</p>
<p>The last line crystallizes the interests of the enrichment of the analysis by the CTI. The yellow square determines the maturity progression due to the implementation of security solutions relevant to the CIS 11.1 measure (e.g. a network device management system), which are automatically determined and recommended to the user in the case of the Citalid calculation engine. In other words, this differential indirectly expresses a path towards optimal maturity and resilience for this specific scenario, the starting point for the definition of a tailor-made cyber investment strategy.</p>
<p>&nbsp;</p>
<h2>Turning analysis into strategy</h2>
<h3>Formulate a cyber strategy aligned with group objectives</h3>
<p>A successful and relevant risk analysis is characterized by the ease with which the observer can immediately visualize how to translate data into action. It must therefore be intelligible and coherent for the recipient, whatever his or her technical level and position in the organization chart. In other words, risk analysis alone is insufficient: it can only be truly useful if it gives rise to a long-term strategy.</p>
<p>This vision, strongly oriented towards the most strategic levels, marks the very DNA of Citalid. Behind the calculation of the risks (raw and real) and the most effective recommendations (referential as solutions) thanks to CTI, the objective is to be able to propose an indicator of the return on investment (ROI) of the security solutions. By visualizing his initial position (A), his desired position (B) and the different possible paths (defense investments), the final decision-maker must be able to compare the ROI of the different options and draw up a cyber investment strategy in line with his budget and real objectives.</p>
<p>Moreover, the objective behind this singular approach is twofold. Firstly, it is a question of accompanying our clients in the definition of their cyber security strategies and in the application of a co-constructed action plan, aimed at compensating for the flaws made visible by the analysis. However, in order to keep this strategy realistic, it is essential to ensure that it can be part of a global dynamic and therefore quickly assimilated by a higher hierarchical body (COMEX). To meet this need, Citalid has refined its service so that it is in line with the realities of the CISO:</p>
<ul>
<li>By adapting the platform in terms of ergonomics, level of technicality and language, so that the dashboards are transparent and easy to interpret;</li>
<li>By assisting our clients in defining budgets and in their legitimization and justification (advocacy) in view of the reality of the threat.</li>
</ul>
<p>By aligning cybersecurity strategies with broader investment strategies, in line with the objectives set by the group, Citalid intends to guarantee and reinforce the predominant role of the CISO in steering cyber resilience.</p>
<p>&nbsp;</p>
<h3>Capitalizing on the approach through the deployment of a risk index</h3>
<p>The major advantage in choosing to take a global approach to security lies in its potential for aggregating risk at any level (group, business unit, application, project, etc.) and for standardization (comparison between perimeters and peers). Like rating agencies, this &#8220;scoring&#8221; of the entity, which takes into account not only its level of maturity on its exposed assets but also its risk management strategy, internal organization, the reality of the threat, its own business context, etc., can be transformed into a global risk index, symbol of the entity&#8217;s resilience and monitored by its management. This is truer since a scientific approach based on many heterogeneous parameters presents a desirable objectivity, for the entity as well as for its partners and collaborators.</p>
<p>This time, it is no longer just a question of positioning oneself in one&#8217;s environment, but of positioning oneself in relation to possible peers (comparison) and partners (guarantees). A risk index reflecting high resilience and sound risk management will ensure that its suppliers or end customers have optimal security and respect for their data, while reassuring investors that their funds are being used correctly.</p>
<p>&nbsp;</p>
<p><img loading="lazy" decoding="async" class="size-full wp-image-14460 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-5.png" alt="" width="1387" height="606" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-5.png 1387w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-5-437x191.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-5-71x31.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-5-768x336.png 768w" sizes="auto, (max-width: 1387px) 100vw, 1387px" /></p>
<p style="text-align: center;">Examples of risk indices produced by <strong>Citalid</strong>: in this case, a &#8216;Cyber Weather&#8217; that identifies variations in a client&#8217;s media exposure.</p>
<p>&nbsp;</p>
<p>Other players could also benefit from such an index: the insurance industry, and cyber-insurers. The quantification of cyber risk remains an obstacle for them, as traditional actuarial approaches are limited by the lack of historical cyber security data. Citalid&#8217;s model, presented here, combines threat expertise, advanced probabilistic models and innovative attack-defense simulations to overcome this lack of data. Our scoring and metrics, based on risks rather than on a simple level of defense, allow us to refine the insurance model to be as close as possible to the real needs of our clients.</p>
<p>Thus, quantifying cyber risk and the return on investment of security solutions is one of the biggest challenges facing today&#8217;s CISOs, Risk Managers and insurers. Through its innovative approach, Citalid responds to this need to reposition cyber security at the heart of corporate strategies and to optimize its action plans and investments.</p>
<p><sup>[1]</sup> Attributed to Pierre Joliot-Curie</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/11/cyber-threat-intelligence-for-optimizing-cyber-budgets/">Citalid | Shake Up &#8211; Cyber Threat Intelligence for optimizing cyber budgets</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
