Ask 5 people to define threat intelligence and you'll get 5 different answers, and that's exactly where this episode starts. Will Elchert (Senior CTI Analyst, Hunter Strategy) and Jake Williams (VP of R&D, Hunter Strategy) join host Matt Triner alongside two clients living this from the buyer's side: Keith McCartney, SVP of Security and IT at DNA Nexus, and Billy Martin, CTSO at Vigor. Together, they break down what separates a threat intel program that actually drives decisions from one that's just, as Jake puts it, "cyber story time with the CTI team." The conversation covers where AI genuinely helps in CTI workflows and where it falls flat, how red and blue teams each get value out of the same intelligence, and what metrics actually prove a security program's worth to leadership.
Episode Chapters:
00:00 Introduction to Cyber Threat Intelligence
02:51 Defining Threat Intelligence
05:41 Stakeholder Engagement in Cybersecurity
08:34 Risk Management and Cyber Threat Intelligence
11:36 Industry-Specific Approaches to Threat Intelligence
14:25 The Importance of Context in Threat Intelligence
17:07 Integrating Cybersecurity Functions
19:51 Actionability of Threat Intelligence
25:24 The Evolution of Cyber Threat Intelligence
28:58 AI's Role in Cybersecurity
32:19 Data Analysis and AI Integration
37:14 Challenges and Opportunities with AI
41:27 Human Element in Cyber Threat Intelligence
49:57 Red Team vs Blue Team Dynamics
52:28 Red Team vs Blue Team: Who Leverages CTI Better?
55:02 Funding and Capability Development in Cybersecurity
58:11 The Importance of Communication and Collaboration
01:01:14 Metrics for Measuring Threat Intelligence Effectiveness
01:09:45 Building a Cybersecurity Program from Scratch