How to Make Threat Intelligence Sharing Work

TL;DR
Threat intelligence creates value only when it leads to countermeasures that protect users. Effective sharing starts with a focused campaign, rewards organizations for contributing useful information, and uses an operational platform to convert intelligence into defenses. The cybersecurity industry must also act urgently on its talent shortage instead of continuing to describe the problem without solving it.
Transcript
Vice President Intel Security, Chris Young. Good morning, everyone. Hey, before I get started, let's give another round of applause to those award winners. Inspirational people for us in our industry. You know what? Every year at the beginning of the year, I'm often intrigued by the headlines, those top 10 cybersecurity predictions for the coming y... Read More
Key Insights
- Threat intelligence is valuable only when it informs countermeasures that can be deployed. Accumulating raw malware samples or indicators does not automatically improve security, because participating organizations still need a clear process for translating shared information into protections for endpoints, networks, and users.
- Focused investigation produces more actionable results than indiscriminate data collection. The Cyber Threat Alliance gained little from broadly sharing malware samples, then generated useful findings by starting with a specific campaign, asking a defined question, and working from that objective toward the relevant evidence.
- Diverse participants contribute complementary visibility into the same threat. Organizations may serve different customers, operate in different countries, or collect information through different business activities, allowing their combined intelligence to reveal details and support countermeasures that no participant could develop as effectively alone.
- Threat intelligence sharing needs a sustainable competitive model rather than dependence on charity. Companies can continue to compete and differentiate through the speed, quality, and effectiveness with which they apply shared intelligence, instead of treating the underlying threat data as the primary source of differentiation.
- An operational platform is necessary to manage participation and convert information into action. Simply assembling companies and publishing data can create free riders, inconsistent contributions, and complaints, while a structured exchange can measure value, coordinate participants, and support automated defensive responses.
- A scoring mechanism can balance contributions from organizations of different sizes. A smaller participant may provide deep expertise on a focused subject, while a larger participant may contribute broader coverage, allowing the platform to recognize distinct but useful forms of intelligence fairly.
- The CryptoWall 3 investigation showed how collective intelligence can become practical protection. Alliance members combined malware samples and indicators of compromise, then converted their findings into blocked IP addresses and security update signatures deployed across the endpoints and networks of their customer bases.
- The cybersecurity talent shortage requires immediate industry action rather than continued discussion. Young argues that organizations have spent too long admiring or complaining about the problem, and that delaying action will leave the industry poorly prepared to meet future security demands.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: How can threat intelligence sharing become actionable?
Threat intelligence sharing becomes actionable when participants begin with a defined threat campaign or security question instead of collecting every available data point. They can then combine relevant malware samples, indicators of compromise, account activity, and other observations, analyze their complementary findings, and translate the resulting intelligence into deployable countermeasures such as blocked IP addresses and security update signatures.
Q: Why does sharing large amounts of raw threat data fail?
Sharing large amounts of raw threat data can fail because more information does not necessarily answer a useful question or improve customer protection. The Cyber Threat Alliance initially committed to exchanging many malware samples, but the pooled data produced little practical value. Progress began only after the group selected a specific campaign and organized its analysis around a focused objective.
Q: What are the core principles of effective threat intelligence sharing?
Effective threat intelligence sharing rests on focus, a sustainable competitive model, and an operational platform. Focus connects information to a specific problem. A revised competitive model encourages companies to share intelligence while differentiating through execution. An operational platform scores contributions, accommodates different participants, discourages free riding, and helps automate the conversion of intelligence into countermeasures.
Q: How did the Cyber Threat Alliance study CryptoWall 3?
The Cyber Threat Alliance selected CryptoWall 3 as a focused campaign and pooled the members' relevant resources. Participants combined malware samples, indicators of compromise, account tracking, and observations of Bitcoin movements between cybercriminals and victims. Because the members had different customers, businesses, and geographic visibility, each contributed distinct evidence that strengthened the collective analysis and resulting countermeasures.
Q: How can cybersecurity companies share intelligence and still compete?
Cybersecurity companies can share the underlying threat intelligence while competing on how effectively they use it. Their differentiation can come from turning common intelligence into timely products, detection capabilities, endpoint updates, network protections, and other practical responses. This model gives every contributor a reason to participate because shared visibility improves security without eliminating differences in execution.
Q: Why does threat intelligence sharing need a scoring platform?
A scoring platform helps measure the value exchanged by participants and address the problem of free riders. It can recognize that contributions do not all have the same form. A small organization might provide deep knowledge of a narrow subject, while a larger organization might supply broader coverage. Scoring allows both contributions to be valued within a structured exchange.
Q: How can shared threat intelligence protect users?
Shared threat intelligence protects users when findings are converted into controls that organizations can deploy across customer environments. In the Cyber Threat Alliance example, collective analysis produced blocked IP addresses and DAT file update signatures for endpoints and networks. Those countermeasures extended the benefit of a small collaborative group across the customer bases of all participating organizations.
Q: Why must the cybersecurity industry address its talent shortage now?
The cybersecurity industry must act now because the talent shortage is already leaving many positions unfilled, while the threat environment continues to become more complex, targeted, customized, and voluminous. Young argues that repeatedly describing or complaining about the shortage is insufficient. The industry needs to begin making changes immediately if it expects to improve its future capacity.
Summary & Key Takeaways
-
Cybersecurity threats have grown more complex, targeted, customized, and numerous, but repeated warnings can make the industry less sensitive to their urgency. Chris Young argues that organizations must cooperate on challenges exceeding the reach of any single company, particularly useful threat intelligence sharing and the persistent shortage of cybersecurity professionals.
-
The Cyber Threat Alliance initially pooled large quantities of malware data, but the information did not improve customer protection because it lacked a focused question. The alliance changed its approach by examining the CryptoWall 3 campaign, combining complementary observations, identifying indicators of compromise, and developing countermeasures stronger than those available to individual members.
-
Successful intelligence sharing requires focus, sustainable incentives, and an operational platform. Companies can share underlying intelligence while competing through how effectively they apply it. A scoring mechanism can recognize different forms of contribution, while automation can transform shared findings into blocked addresses, detection signatures, endpoint updates, and network protections.
Read in Other Languages (beta)
Share This Summary 📚
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from RSAC Cybersecurity 📚






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator