Skip to content
Review

Demystifying cyber threat intelligence: A first-principles approach to capability development and vendor evaluation

Aug 2026 · International Conference on Cyber Security And Protection Of Digital Services · 0 citations

TL;DR

The case is made for a first-principles approach that CTI teams can adopt as an unbiased anchor to guide their decisions around establishing an adequate CTI capability, and pragmatic recommendations to assist CTI teams with qualifying their prospective vendors to ensure good fit are offered.

Abstract

Cyber threat intelligence (CTI) is considered an essential element of a robust cyber security programme. Given the relative nascency of the discipline, however, there is a degree of ambiguity among the community around what it takes to establish a credible CTI capability in support of the cyber security mission. At the same time, there is now a thriving industry offering commercial CTI products and services in support of the customer’s capability development efforts, with many instances of opportunistic vendors poised to exploit this fledgling market. This has spurred the growth of research and advisory companies that attempt to present an objective review and offer guidance around CTI vendor selection. Their perspective, however, is often heavily influenced by a small group of select vendors and the evaluation criteria is often incomplete and skewed towards the participating vendors. This paper makes the case for a first-principles approach that CTI teams can adopt as an unbiased anchor to guide their decisions around establishing an adequate CTI capability, and offers pragmatic recommendations to assist CTI teams with qualifying their prospective vendors to ensure good fit. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.

View source

Similar papers

Review Open access 2026

Evolving Cyber Threat Intelligence: A Systematic Review and Comparative Analysis

To improve cybersecurity across industries, Cyber Threat Intelligence (CTI) is becoming increasingly crucial. This systematic review explores how CTI practices are evolving in response to advancements in Artificial Intelligence (AI), particularly in the context of Large Language Models (LLMs). We examined 61 peer-reviewed studies using the PRISMA methodology, which demonstrates a strict selection procedure founded on specified inclusion, exclusion, and quality standards. This approach aligns with the scope of similar systematic reviews in the field of cyber threat intelligence. The review provides a comparative synthesis of CTI research capabilities across threat detection and prediction, attribution, forecasting, and automated reporting. We classify these approaches into three categories: conventional methods, those enhanced by AI and Machine Learning, and those based on LLMs. Our findings indicate that LLMs offer significant advantages in contextual reasoning, processing unstructured threat intelligence, and generating actionable mitigation plans. However, challenges such as model explainability, data privacy, system interoperability, and standardization impede their integration into operational environments. In addition to highlighting the potential and practical limitations of LLMs in CTI, this study identifies research gaps and proposes methods to create scalable, secure, and flexible CTI systems that support real-time cyber defense.

Hilalah Alturkistani, Abdul Ghafar Jaafar, S. Chuprat et al. · 0 citations
Aug 2026

ARAMIS: A unified and scalable methodology for industrial cyber security risk assessment

The rapid digitisation of critical infrastructure has made traditional fragmented risk assessment practices increasingly challenging to scale. For global industrial leaders managing hundreds of diverse projects, there is a real need for a unified methodology that ensures technical rigour, cross-project reproducibility, and scalability. This paper introduces the Advanced Risk Assessment Methodology for Industrial Systems (ARAMIS), an innovative framework developed through a strategic partnership between Airbus Protect and Alstom. ARAMIS merges the structured, requirement-driven security levels of ISA/IEC 62443 with the scenario-based approach of Expression des Besoins et Identification des Objectifs de Sécurité Risk Manager (EBIOS RM). The paper details the five-module structure of ARAMIS, its unique multilayered modelling of operational scenarios and its algorithmic approach to calculating security levels target (SL-T). Finally, it discusses the implementation of the methodology within the Fence risk management tool to ensure seamless reproducibility and knowledge capitalisation across global project portfolios. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.

Serge Benoliel, Florence Foudrain · 0 citations
Review Open access Aug 2026

AI-Supported Dynamic Cyber Risk Assessment for Cyber Situational Awareness: A Cross-Sectional Survey

Small and medium-sized enterprises (SMEs) have limited resources and governance that might restrict their ability to conduct dynamic cyber risk assessment (DCRA) and maintain effective cyber situational awareness (CSA). This study investigates stakeholders’ perceptions of CSA, DCRA, and AI-enabled cybersecurity to develop a conceptual framework targeted for SMEs. The online survey was cross-sectional, and 302 completed responses were gathered. The valid sample size for the items ranged from 288 to 299. Out of 293 respondents, 54 (18.4%) indicated prior usage of CSA techniques, 21 (7.2%) reported prior use of DCRA tools, and 226 (77.1%) backed AI in the cybersecurity field. The highest rated DCRA requirements were continuous threat updates, identification of attacks and vulnerabilities, and prioritization of alerts based on risk. The highest rated implementation challenges were accuracy, relevance, and integration with current infrastructure. Four multi-item measures had good-to-outstanding internal consistency (α = 0.868–0.926; ω = 0.870–0.929), and parallel analysis supported a single factor for each. Exploratory findings suggested that Information Technology (IT) and cybersecurity professionals had greater familiarity with CSA and DCRA than did leaders and managers. There was a moderate-to-strong positive association between familiarity with CSA and DCRA (ρ = 54). The framework defines AI as a layer of analytical decision support, DCRA as the process of translating changing evidence into updated and prioritized risk information, and CSA as decision-relevant interpretation and use of that information. This framework will help SMEs to improve CSA and will help their leaders to make the right decisions when dealing with cyber threats.

Mansour Almalki, L. Nawaf, Fiona Carroll · 0 citations
Review Open access Jul 2026

Cybersecurity Challenges and Centralized Monitoring Solutions for e-Governance in Zambia: A Literature Review

Some operational and technical challenges that affect the adoption of effective cybersecurity prac-tices within e-government infrastructures are identified and the importance of scalable, cost-effective, and integrated monitoring infrastructures to manage cybersecurity proactively in developing countries are highlighted.

Lukumba Phiri, Steve Muwowo · 0 citations
Review Open access Jul 2026

Technological Evolution of Strategic Security Infrastructure: Transitioning from Reactive Models to Predictive Intelligence

A global transition toward intelligent security infrastructures is demonstrated, with measurable improvements in performance, accuracy, and response times in the generation of actionable intelligence to support strategic decision-making.

Omar Flor-Unda, David Puga, Hugo Alomoto et al. · 0 citations