{"id":9177,"date":"2025-12-18T03:02:24","date_gmt":"2025-12-18T03:02:24","guid":{"rendered":"https:\/\/mailitics.com\/index.php\/2025\/12\/18\/four-ways-ai-can-finally-make-threat-intelligence-useful-and-not-just-noisy-1603545943\/"},"modified":"2025-12-18T03:02:24","modified_gmt":"2025-12-18T03:02:24","slug":"four-ways-ai-can-finally-make-threat-intelligence-useful-and-not-just-noisy-1603545943","status":"publish","type":"post","link":"https:\/\/mailitics.com\/index.php\/2025\/12\/18\/four-ways-ai-can-finally-make-threat-intelligence-useful-and-not-just-noisy-1603545943\/","title":{"rendered":"Four ways AI can finally make threat intelligence useful and not just noisy"},"content":{"rendered":"<p>    Four ways AI can finally make threat intelligence useful and not just noisy<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<img data-recalc-dims=\"1\" decoding=\"async\" class=\"img-responsive\" src=\"https:\/\/i0.wp.com\/d1v1e13ebw3o15.cloudfront.net\/data\/91641\/pool_and_spa_logo\/..jpg?ssl=1\"> <\/p>\n<p>For years, many CISOs have been told that threat intelligence is the missing piece in their security program. In other words, the glue that would finally tie risk, controls and decision-making together. Yet inside most organisations the reality is very different. Threat intelligence feeds are noisy. Reports often arrive out of context or too late to make a difference, and the sheer volume of data makes it difficult for already-stretched security teams to turn intelligence into action.<\/p>\n<p>That experience isn\u2019t unique. According to Google Cloud research cited in ISACA\u2019s recent white paper, <a href=\"https:\/\/www.isaca.org\/resources\/white-papers\/2025\/building-a-threat-led-cybersecurity-program\" target=\"_blank\" rel=\"noopener\">Building a Threat-Led Cybersecurity Program with Cyberthreat Intelligence<\/a>, 61% of cybersecurity professionals say they\u2019re overwhelmed by the number of intelligence feeds coming in, and nearly the same number say they can\u2019t make the intelligence actionable. The outcome is predictable: millions are spent, minimal operational value is gained and threats continue to slip through the cracks.<\/p>\n<p>But the threat environment isn\u2019t standing still: attackers are stealing credentials at scale, buying and selling access to networks, and using generative AI to speed up their operations. To keep up and stay ahead, defenders need to rethink how they use threat intelligence. The ISACA white paper shows that a modern, threat-led approach, supported by AI and automation, can finally turn intelligence into real operational value.<\/p>\n<p>Below are four practical ways AI can do exactly that.<\/p>\n<h4>1. Using LLMs to analyse initial access broker activity at scale<\/h4>\n<p>The cybercrime ecosystem increasingly resembles a mature market, complete with supply chains, brokers and marketplaces. Initial access brokers (IABs) are central players, selling entry points into enterprise networks. But their posts are often cryptic, inconsistent and buried across dozens of dark-web forums and encrypted channels.<\/p>\n<p>Historically, manually analysing IAB chatter has been slow, labour-intensive work. A human analyst might review a few dozen posts a day; meanwhile, thousands more are published.<\/p>\n<p>Large language models change that equation.<\/p>\n<p>LLMs can be used to automatically identify IAB listings, extract structured information from unstructured posts, and flag listings relevant to a specific organisation or sector. This significantly reduces manual triage time and helps analysts focus on the highest-risk access for sale, the kind that precedes ransomware incidents.<\/p>\n<h4>2. Prioritising breached identities using automated classification<\/h4>\n<p>Infostealer malware has become one of the most damaging and underestimated drivers of enterprise compromise. The white paper notes that millions of \u2018stealer logs\u2019 are sold annually, and nearly a third originate from enterprise-licensed environments. This means corporate credentials, session cookies, browser-stored passwords and sensitive tokens are ending up in criminal markets at unprecedented rates.<\/p>\n<p>The challenge? No human team can meaningfully triage that volume of exposure.<\/p>\n<p>AI-assisted prioritisation is now essential. By automatically classifying breached identities based on factors such as domain sensitivity, privileged access, critical system relevance, active sessions and MFA posture, security teams can immediately escalate the exposures that really matter.<\/p>\n<p>This flips the model in that instead of drowning in alerts, teams receive a structured, risk-ranked queue of high-priority exposures. For organisations running hybrid identity environments, this is one of the most impactful steps they can take.<\/p>\n<h4>3. Automating credential verification and remediation<\/h4>\n<p>Most Australian enterprises still grapple with credential-based intrusions. Attackers know it: they continue to target the easiest path of reusing stolen credentials purchased from stealer logs or phishing kits.<\/p>\n<p>ISACA\u2019s guidance emphasises the value of establishing automated workflows that:<\/p>\n<ul>\n<li>verify whether exposed credentials are active<\/li>\n<li>force immediate resets or token revocations<\/li>\n<li>track patterns to identify systemic gaps in authentication controls.<br \/>\n\t\u00a0<\/li>\n<\/ul>\n<p>When integrated into identity governance or SOAR systems, this automation dramatically reduces mean time to response (MTTR). The alternative, manually resetting accounts after threat intelligence reports surface, is no longer viable.<\/p>\n<p>This is an area where AI can help prevent intrusions outright.<\/p>\n<h4>4. Refining IoC feeds so analysts aren\u2019t overwhelmed<\/h4>\n<p>Technical threat intelligence like indicators of compromise (IoCs) remains one of the most established forms of intelligence and one of the most problematic. Organisations often ingest too many feeds, don\u2019t deprecate stale indicators, and inadvertently flood security tools with false positives.<\/p>\n<p>AI-driven curation solves much of that.<\/p>\n<p>ISACA recommends using automation to score, age, cluster and prioritise indicators based on:<\/p>\n<ul>\n<li>the organisation\u2019s threat model<\/li>\n<li>the reliability and historical accuracy of the source<\/li>\n<li>indicator age and relevance<\/li>\n<li>alignment with known active threat groups targeting the sector.<br \/>\n\t\u00a0<\/li>\n<\/ul>\n<p>Instead of overwhelming SOC analysts, curated IoC feeds improve signal-to-noise ratios and sharpen threat-hunting activities.<\/p>\n<h4>Why traditional threat intelligence programs fail and how to fix them<\/h4>\n<p>During my career I\u2019ve seen some of the same themes repeated:<\/p>\n<ul>\n<li>Too many feeds, not enough context.<\/li>\n<li>Intelligence that isn\u2019t tied to risk.<\/li>\n<li>Manual processes that can\u2019t scale.<\/li>\n<li>Stakeholders who aren\u2019t aligned on priorities.<br \/>\n\t\u00a0<\/li>\n<\/ul>\n<p>ISACA\u2019s white paper addresses these systemic issues and helps guide tech professionals with a practical blueprint for building or strengthening a modern threat intelligence program. It emphasises building priority intelligence requirements (PIRs) tied to the organisation\u2019s unique threat model and risk appetite. When PIRs are structured well \u2014\u00a0specific, actionable, measurable and time-bound \u2014\u00a0intelligence stops being generic and becomes directly tied to business outcomes.<\/p>\n<p>The result is a threat-led approach where:<\/p>\n<ul>\n<li>controls are adjusted based on real attacker behaviour<\/li>\n<li>SOC teams receive intelligence that is relevant and timely<\/li>\n<li>executives can tie intelligence to risk-reduction, not report-volume.<br \/>\n\t\u00a0<\/li>\n<\/ul>\n<p>Done poorly, threat intelligence is noise. But done well, it becomes one of the most powerful accelerators of cyber resilience.<\/p>\n<p><h8><em>*Jamie Norton is Vice Chair of the ISACA Board and Chief Information Security Officer at the Australian Securities and Investments Commission (ASIC). With more than 25 years of experience across government, commercial and international sectors, he specialises in cybersecurity, resilience and strategic risk management. <\/em><\/h8><\/p>\n<p><h9>Image credit: iStock.com\/ArtemisDiana<\/h9><\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><\/p>\n<p> \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/www.technologydecisions.com.au\/content\/it-management\/article\/four-ways-ai-can-finally-make-threat-intelligence-useful-and-not-just-noisy-1603545943?utm_source=rss\">Go to Technology Decisions<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Four ways AI can finally make threat intelligence useful and not just noisy For years, many CISOs have been told that threat intelligence is the missing piece in their security program. In other words, the glue that would finally tie risk, controls and decision-making together. Yet inside most organisations the reality is very different. Threat [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[44],"tags":[48],"class_list":["post-9177","post","type-post","status-publish","format-standard","hentry","category-technology-decisions","tag-technology-decisions"],"_links":{"self":[{"href":"https:\/\/mailitics.com\/index.php\/wp-json\/wp\/v2\/posts\/9177"}],"collection":[{"href":"https:\/\/mailitics.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mailitics.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mailitics.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/mailitics.com\/index.php\/wp-json\/wp\/v2\/comments?post=9177"}],"version-history":[{"count":0,"href":"https:\/\/mailitics.com\/index.php\/wp-json\/wp\/v2\/posts\/9177\/revisions"}],"wp:attachment":[{"href":"https:\/\/mailitics.com\/index.php\/wp-json\/wp\/v2\/media?parent=9177"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mailitics.com\/index.php\/wp-json\/wp\/v2\/categories?post=9177"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mailitics.com\/index.php\/wp-json\/wp\/v2\/tags?post=9177"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}