Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

CTI is going cross-functional: what does that change for security teams?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: The SANS 2023 CTI Survey shows that current events, geopolitics, and external news sources continue to shape analyst priorities, while threat intelligence is becoming more cross-functional across organisations, according to Anomali’s summary of the survey. That shift matters because CTI now has to support faster operational decisions, not just reporting.

NHIMG editorial — based on content published by Anomali: SANS 2023 CTI Survey Results, Keeping Up with a Changing Threat Landscape

Questions worth separating out

Q: How should security teams turn CTI into practical control changes?

A: They should map intelligence inputs to specific control owners and response thresholds before incidents happen.

Q: Why do external intelligence sources matter so much for CTI programs?

A: External sources often surface emerging threats before local telemetry shows abuse.

Q: What breaks when CTI is not shared across security functions?

A: The main failure is delayed action.

Practitioner guidance

  • Define CTI-to-control escalation paths Document exactly which threat signals trigger action in IAM, PAM, cloud, and SOC workflows.
  • Integrate external intelligence with identity telemetry Correlate news, vendor reporting, and community indicators with logins, token use, secret exposure, and privileged access events.
  • Assign one owner for identity-related threat intake Establish a clear handoff model for alerts tied to accounts, service identities, and access paths.

What's in the full report

Anomali's full white paper covers the survey detail this post intentionally leaves for the source:

  • The survey methodology and respondent mix behind the CTI findings.
  • The full set of trend observations on how CTI priorities changed over time.
  • Additional context on how vendors and customers collaborate in CTI operations.
  • Expanded discussion of where the field can mature next.

👉 Read Anomali's white paper on the SANS 2023 CTI survey results →

CTI is going cross-functional: what does that change for security teams?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

CTI is shifting from insight production to decision support. The survey’s core signal is that intelligence teams are being judged less on volume and more on whether they help the organisation act faster. That raises the bar for collection, enrichment, and dissemination because intelligence that cannot change a control outcome is just reporting. For identity security teams, this is the same shift seen in NHI governance and privileged access management. The practical conclusion is that CTI must be measured by operational effect, not publication cadence.

A question worth separating out:

Q: Who should own threat intelligence inside customer identity workflows?

A: Ownership should sit with the identity and security functions together, because the control affects both access policy and threat response. Identity teams need to define when a login is challenged or blocked, while security teams need to maintain the signals and escalation logic. That shared ownership prevents the connector from becoming a disconnected security add-on.

👉 Read our full editorial: SANS CTI survey shows intelligence work is becoming cross-functional



   
ReplyQuote
Share: