How to Build an Intelligence-Led Security Program

TL;DR
Build security around intelligence that reduces uncertainty and supports operational risk decisions, rather than relying only on compliance requirements or threat feeds. Combine human judgment with machine processing to turn large volumes of structured and unstructured data from adversary, defender, and shared digital environments into smaller, actionable information that enables proactive and persistent risk mitigation across the enterprise.
Transcript
Well, good morning, everybody. I appreciate it. Some friendly faces in the audience. I like to see that. Um, for those who don't know me, I'm a super informal presenter. I think it's far more important just to kind of engage, and especially, uh, given the, uh, the audience today, we have an opportunity to absolutely do so. So I'm going to leave a f... Read More
Key Insights
- Intelligence-informed security is a transition from programs driven primarily by compliance toward programs that use threat knowledge to manage operational risk. The intended result is a stronger connection between security activities, day-to-day operations, and decisions about where mitigating and detective controls should be applied.
- Humanity is effectively a sensor in the digital environment because people willingly contribute information about their identities, interests, transactions, movements, activities, intellectual property, and business behavior. This continuous participation expands the available data while also increasing the scale of the information-processing challenge.
- The digital boundary is moving beyond traditional brick-and-mortar security controls as work, personal activity, information, and transactions spread across distributed environments. This movement makes the attack surface difficult to contain and increases the importance of intelligence that can operate across physical and logical boundaries.
- Physical presence, logical presence, and artificially created perceived presence form a triangulation of data that can support analysis. Connecting these dimensions can help security teams understand how real-world actions, digital footprints, infrastructure, and influence operations relate to one another.
- The purpose of intelligence is to remove uncertainty quickly enough to support effective action. Organizations need systematic, thoughtful, legal, and ethical processes that find relevant data, transform it into useful knowledge, and produce outcomes that humans or machines can act upon.
- Human and machine capabilities work together by shrinking big data into small data and then into focused pieces of information that support action. Machines can correlate disparate data at scale, while people contribute judgment and direct actions where analysis requires human involvement.
- Commercial intelligence can use broadly accessible information because intelligence is not restricted to government organizations. Classified status often concerns the sources and methods used to gather information, while the underlying intelligence mission remains focused on finding, collecting, articulating, and using data from multiple sources.
- Red, blue, and gray spaces provide a framework for intelligence collection. Red space covers adversary behavior, blue space covers defended assets and controls, and gray space covers the shared digital infrastructure through which adversaries connect with organizational attack surfaces.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: How do you build an intelligence-led security program?
Build the program around the goal of reducing operational risk, then connect intelligence directly to daily security and business decisions. Collect relevant structured and unstructured data from adversary activity, the organizationβs own attack surface, and shared internet infrastructure. Use machines to process and correlate information at scale, while preserving human judgment for interpretation and action. The process should remain systematic, thoughtful, legal, and ethical.
Q: Why should security programs move beyond compliance-based approaches?
Compliance-based security does not by itself provide the threat context needed to address changing adversary behavior across a distributed digital environment. A threat-informed and intelligence-informed approach connects security work to operational risk, helping teams decide how to use detective and mitigating controls. The objective is to reduce uncertainty, prioritize meaningful actions, and disrupt adversaries before they can successfully act against the organization.
Q: What is the main purpose of security intelligence?
The main purpose of security intelligence is to identify and quickly remove uncertainty so people or machines can take effective action. Intelligence should transform large volumes of disparate data into focused information that supports operational risk decisions. It is more than a threat feed because its value comes from finding, correlating, interpreting, and applying information across the enterprise to enable proactive and persistent risk mitigation.
Q: How do humans and machines work together in intelligence analysis?
Humans and machines form a combined analytical capability that can handle both data scale and decision complexity. Machine processing helps shrink large datasets into smaller, relevant information and correlate disparate elements that would be difficult to examine manually. Human practitioners then contribute context, judgment, dialogue, and action. Depending on the outcome, the resulting response may be performed by a person, a machine, or both.
Q: What are red, blue, and gray spaces in threat intelligence?
Red space represents the adversaryβs environment, including who adversaries work with, what they plan, where they act, and which tools or campaigns they use. Blue space represents the organizationβs attack surface and the ways threats appear within its environment. Gray space is the shared digital infrastructure connecting both sides, including hosted infrastructure, network traffic, command-and-control connections, registration data, and publicly available domain information.
Q: Why is gray-space intelligence useful for security teams?
Gray-space intelligence reveals the infrastructure an adversary may use to reach an organizationβs attack surface. Although this shared digital environment is not fully owned by either attacker or defender, it can expose network traffic, connections to command-and-control nodes, registration details, and public domain information. Correlating those elements improves knowledge of adversary infrastructure and can help teams reduce uncertainty before malicious activity reaches defended systems.
Q: How does digital activity expand the enterprise attack surface?
People and organizations continually place identities, interests, transactions, movements, intellectual property, business activity, and other information into the digital environment. Work and personal activities also move data beyond traditional brick-and-mortar security controls. Adversaries use the same environment to prepare and execute malicious intent. Together, expanding digital boundaries and growing human participation create more data, connections, and potential exposure for security programs to address.
Q: Is intelligence limited to governments and classified sources?
Intelligence is not limited to governments because military, government, civilian, and intelligence-community participants operate within the same general digital environment. Information may become classified because of the sources and methods used to gather it, not necessarily because the underlying information must always remain inaccessible. Commercial organizations can build intelligence capabilities by finding, collecting, articulating, and using data from multiple legally and ethically available sources.
Summary & Key Takeaways
-
Security programs should transition from compliance-based practices toward threat-informed and intelligence-informed operations. The purpose is to manage operational risk more effectively by connecting security decisions with daily business activities. Intelligence can help organizations prioritize actions, address expanding attack surfaces, and use available information to reduce uncertainty before adversaries execute malicious plans.
-
The digital environment contains extensive information produced by human activity, business operations, transactions, movement, infrastructure, and adversary behavior. Physical actions, digital footprints, and influence operations create interconnected sources of evidence. Organizations need systematic, thoughtful, legal, and ethical methods for finding, processing, correlating, and applying this information to security decisions.
-
An intelligence-led program can examine red space, blue space, and gray space. Red space concerns adversaries, plans, associates, tools, and campaigns. Blue space covers the organizationβs attack surface and defensive controls. Gray space includes the shared infrastructure connecting attackers with targets, such as network connections, command-and-control nodes, registrations, and public domain information.
Read in Other Languages (beta)
Share This Summary π
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from RSAC Cybersecurity π






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator