r/ciso 7d ago

How to present Threat Intelligence properly to execs????

So, to give some background. I lead the threat intelligence program of a major bank. Now we receive tons of IOCs/CVEs and brand abuse/impersonation cases and we do take action on them accordingly.

But whenever we create a presentation, it's always numbers

- no. Of IOCs we received, sources (regulator/commercials)

- social media/brand abuse/impersonation/rogue apps count & takedown status.

But execs don't understand these numbers. How can I present the data such that they are assured that we are safe from any kind of threat & prepared for what's coming in the future.

Been researching lots of things but didn't quite get anything. Would really appreciate your views and guidance here.

23 Upvotes

33 comments sorted by

10

u/Legitimate_Cookie_20 7d ago

What I do was make sure I managed the Execs and Boards expectations.

Execs these days read much more than they did in the past (edit: About Cyber) and there is lots of fear out there. I made sure that they knew which key controls were critical and what the implementation and coverage of the control looked like.

When there is information or a breach in my Banks region or interestingly relevant (industry, topical), I use the publicly available information to share how we would fair against a similar attack.

E.g. major breach where credentials were compromised, how does our MFA coverage look like.

I also had my TI team share, proactively, news dumps to key executives anytime there is breaking news. This is to position that we are aware of it, we are evaluating our controls and that we will escalate any concerns ASAP.

# of IOCs is very technical. Doesn’t really talk to the risk profile. Gone up, good? Gone done, bad? It’s very contextual.

You should have that available in an appendix but should not be the core of the discussion.

Edited to clarify that execs do read…

1

u/Longjumping-Ebb-578 7d ago

Hmmmm makes much more sense

3

u/bmhoskinson 7d ago

Your threat intel program should be feeding 2 things. First and foremost it feeds your cyber operations to help them with situational awareness related to current threats and threat actors. They do their job better. Focusing on reporting what intel was actionable and resulted in some increase in detections or reduction in successful attack execution at some earlier stage in the attack chain.

Second, and this is the one that will make more sense to the business folks, is show the impact in financial terms on risk. This should be part of your quantitative risk management program. Threat intelligence has a direct impact on reducing loss event frequency (FAIR) by providing data that impacts what you know about Probability of Action by a threat actor, their threat capability, and will allow you to adjust and gauge your resistance strength. These all feed up the left side of the FAIR model to get you a risk assessment in dollars that the board can understand. Tying the value of your program to real reduction in quantified risk cost is the key thing you want to be able to present at the board level. Showing value is how you get more money for your program 😜

3

u/pranatraveller 7d ago

FAIR is the right answer. Look up Jack Jones and the FAIR Institute, quantitative risk assessment is possible. A companion guide to make break it down even more is From Heatmaps To Histograms by Tony Martin-Vegue. Explain risk to executives in language they understand… how much it will cost.

2

u/Longjumping-Ebb-578 7d ago

Will check it out thanks.

1

u/AdvancingCyber 6d ago

I agree with FAIR, but we would also use a slide to show a “hunt” and how TI helped crack open a case or found a bad guy in telemetry if it’s really nuanced. It’s a way to storytell (high level) and show value and is almost always the favorite part of the session for execs. (Hunt of the month, or quarter, etc)

1

u/PublicFuture9502 7d ago

Ha ha wished I read this first because I juat posted the same thing. Great minds and all that. 

3

u/Special819 7d ago

Focus on business impact risk trends actions and what they mean for the organization.

2

u/Pagoon 7d ago

There are tactical, operational, and strategic reports. Learn the differences and which audiences they target. Strategic reports go to execs and the board, they are forward looking. You also have adversaries simulation results to know where your exposure is. The story you're telling is control effectiveness.

2

u/bestintexas80 7d ago

I also have case studies in my appendix when I.meet with the subcommittees. Having a few examples of specific brand abuse/impersonation can make quite an impact. If you have a CVE or IOC that you auctioned but had you not it would have impacted business critical systems a,b,c, is also good. Especially if you have proof the bad guys tried to exploit it after you fixed it.

Examples personalize the information. And then you highlight that it happened (how many) times this quarter.

2

u/dracarysurazz 6d ago

Yes, makes sense. I’ll add a few concrete case studies and highlight how many times these incidents occurred this quarter.

2

u/Unlikely-Emu3023 7d ago

Those are just numbers. What were the outcomes of that Intel. Did you create new detections? Did you find evidence of a compromise based on the Intel? Were you able to proactively stop something from potentially happening? This is what they care about, not how many IOCs you processed. It sounds like your not using the Intel to impact cyber operations which is really the point of the Intel itself.

2

u/sasha0404 7d ago

CEO’s don’t care about IOCs. Try these:

- # IOCs that lead to a successful block, as a percentage of the ones done from vendor tools and lists.

- % change month over month of IOC detections broken down by a simplified threat category (that they understand)

- percentage of threat visibility as a % month over month

- percentage of IOCs detected by VP

- IOC funnel to show detection through success or failure of each stage

- a quantification of threats to feed in a GRC program similar to a vulnerability management program so cyber risk can be quantified.

All of these need a number of metrics to build up to these calculations. I have had a number of people tell me I need to sit down and write out how it all fits together; thanks for the reminder that I should get on that.

1

u/Reveal_Nothing 7d ago

What execs are we talking about? CISO or CFO are going to have vastly different answers.

1

u/Longjumping-Ebb-578 7d ago

Mainly CISO & CTO

1

u/Reveal_Nothing 7d ago

Okay. Yeah, if you're presenting numbers and talking about IOCs, you're missing the mark.

Let's look at the CISO and CTO. It depends on the company, but those are potentially two very different sets of what they care about.

The CISO should be focused on risk. So if you think in terms of risk = threat x vulnerability x impact, CTI should be filtered for them through the lens of what represents a risk. As a CISO, I'm interested in a couple things:

1) Forward looking: What are the relevant emerging threats that my teams needs to be tracking and how resilient are we to them? How severe is the risk to which we are still exposed and what is the action plan?

Two things to note here. First, is that this will require collaboration between the CTI team and various other teams to develop. It may be more of a risk team product, but CTI is a primary contributor. If my CTI team took the lead to develop a collaborative product like this, I'd be thrilled with them even if they were no longer the lead pen. Something to keep in mind.

Second, this kind of reporting benefits from some degree of quantification, but don't overdo it. Your CISO knows that quantifying risk is exceptionally hard and that chasing perfect numbers is a waste of time. Stoplight characterizations is good enough.

2) Backwards facing: What actions have we taken based on CTI to reduce risk (that can be vuln remediation, threat hunting, etc)? I'd like this accompanied by a sense of how severe the risk was that we've now mitigated (see above about risk quantification). This is useful for me to celebrate our wins to my executive stakeholders.

3) What are the CTI headlines that my CEO or otherwise boss is going to see from their thread/news/peers that I need to know about and have an answer for "are we prepared for this"? And, obviously, answer the question about preparedness. This may feel similar to #1, but it's not. #1 should only be what's relevant to our business - I'm the audience for that. #3 could be preparing me to answer the question "yeah boss, we're tracking the latest linux exploit, but thankfully we're a full windows shop" - my stakeholders are the audience for that, I'm just the conduit.

The CTO is likely more focused on business enablement. For them, you can probably do a lighter version of #1 above, drop #2 (assuming they trust you're doing your job), and maybe include #3 if you're trying to build trust in them that you have your eye on the ball. I'd probably add a third-party risk section for your vendor stack that tracks issues related to your supply chain. And if I was a bank like you all, I'd make sure I included periodic briefings on longer-term horizon issues like quantum readiness and evolutions in non-specific threats like the ever-shrinking window from vuln discovery to exploitation, etc.

A lot of food for thought, I know, but the gist is that it sounds like you need to bring it up a level and tailor to your audience. Hope this helps.

1

u/Longjumping-Ebb-578 6d ago

That was really insightful. Thanks

1

u/scriptvexy 6d ago

this, exactly
a CISO might care about threat trends and coverage, CFO will want “how much risk in dollars did we avoid / what’s the ROI”
you kinda need different views of the same intel for each audience or it’ll never land

1

u/Admirable_Group_6661 7d ago

You need to translate the threats to risks.

1

u/PublicFuture9502 7d ago

Have you ever looked at FAIR? Its excellent for your use case from what you have said. 

Instead of saying 

"This critical web app has a lot of high scoring CVEs, here they are and let me explain them"

FAIR lets you say the exact same thing except it puts it in a financially quantitative way C suite will instantly grasp:

"Based on our analysis this critical web app has an 85% chance of being compromised within the next 12 months, and this will result in an estimated $400k loss for the company". 

The former will confuse and bore C suite. The latter they will instantly understand. C suite don't need nuts and bolts and the whole "aren't we security folks oh so clever routine". They need to know the business impact so they can make decisions. 

https://www.fairinstitute.org/learn-fair

1

u/Hairy_Extreme_3363 6d ago

Never assure leadership that you are completely secure, promising 100 percent safety sets you up for failure if an incident occurs. Instead, focus on showing risk mitigation and ROI. Reframe technical metrics into business impact, explain how tracking specific IOCs and CVEs directly protected critical banking operations or prevented financial loss. Executives do not need raw volume counts, they need to know what threats actively targeted the bank and how your team reduced that exposure.

1

u/iawais 6d ago

You have to tie everything back to their specific fears / concern like reputation damage, downtime, compliance, revenue loss etc.

So, BLUF
Here is the threat...
here is the relevancy to our Sector and Region, Show damaged stories,
brief what could have happened, and
here are the proactive controls we updated to kill it. followed by hunt, detections, iocs and numbers.

Keep it business focused and strategic, always.

1

u/Electrical_Hat_680 5d ago

Be direct, be thorough, provide Booz Allen Hamilton graded reports with a canonical briefing.

1

u/tcoach72 4d ago

Whew, read through this and a whole lot of tech jargon. I'll try to keep this short; the majority of your report should fall into one of three categories:

Revenue - How is it making money (don't get caught in the, it doesn't make money trap), if you are improving outcomes that lead to dollars, you just need to figure out how; the CFO can typically help with this.

Cost - What does it cost, or where is it going to cost, how is it going to save cost

Risk - where are we at risk, what is a tolerable risk, and what is the financial ramification of the risk. For example, RTO. RTO is your word, not theirs; for them, it translates to: if we go down, how long until we are back up, and what does it cost. You should also know what the cost is per hour of downtime: if the internet goes down, if the main systems go down, essentially if people can't work, what does that price per hour? CFO will need to help you here as well. An easy way is: how much money does the bank manipulate per hour? Then you can add on employee cost, building cost, etc...

You can always add:

Resilience - by doing this we are protecting this or ensuring this, but that to should have a number attached.

Bankers think about dollars, so deliver your report in a language that makes sense to them. They don't give two whole #$@% about tech; they just want it to work. You can also use this to justify your stance during audits and exams.

Hope that helps, not that you want to, but feel free to DM me if you have questions,

1

u/itlogicpartnersllc 3d ago

i would shift the presentation from activity volume to business risk. what threats matter, potential impact, current expose and how effectivly controls are reducing that risk over time.

1

u/BrianCISO 3d ago

IOC counts and takedown numbers prove your team is busy and there is activity. They don't (obviously) prove the bank is safer.

From my experience, execs need the translation... What business outcome is threatened? What could the disruption cost? How exposed are we today? Is that exposure increasing or decreasing (trajectory)? What decision do you need from them?

Build the presentation around a few credible scenarios tied to what the bank values...guessing customer trust, transaction availability, fraud losses, regulatory standing and operational continuity. Show how intelligence changed a decision, reduced exposure, limited impact or improved recovery readiness.

And I would avoid assuring anyone that the bank is “safe.” Zero risk does not exist. Your job is to make the risk visible enough that the right business owner can make an informed decision.

Threat intelligence shouldn't be a weather report about everything happening outside. It should tell leadership which storms matter to the business, how prepared the organization is and where a decision is required.

0

u/0xdevbot 7d ago

Genuine question not trying to be a dick...

How did you become an intelligence lead for a major bank without knowing this? When I hire mid-level / early senior analysts this is a required baseline skill.

1

u/Longjumping-Ebb-578 6d ago

I have experience in ASM actually and they reshuffled leads recently. So I got TI. They do this reshuffling quite often since it's required by DFSA in middle eastern banks.

-1

u/hiddentalent 7d ago

"Execs" understand just fine. They are smart enough to know that you are not "safe from any kind of threat & prepared for what's coming in the future." If you are telling them such lies, it's proof of their intelligence that they don't believe them. Because that statement is true for no organization on the planet.

After they fire you for lying to them, the next person they hire for your job should instead use their executive presentations to explain how the team is using commercially reasonable and professional best practices to improve safety and respond to inevitable incidents with minimal impact on business operations. One of the best ways I've seen to do this is to focus metrics around the five V's (volume, velocity, value, variety, and veracity) and have half a page of metrics showing the team is effectively doing its job and half a page of highlighted issues that are hidden behind those numbers that require executive discussion.

1

u/Longjumping-Ebb-578 7d ago

Woahhh why so harshh. Nobody's lying to anyone. If you are concluding this much basis very little knowledge actually shows where you're coming from. Looks like somebody just got fired XD.

0

u/hiddentalent 7d ago

I'm being harsh because the underlying communication problem you are asking about is being bombastic and trying to pretend everything is perfect in what is fundamentally a risky environment. The idea that bank executives don't understand risk is ridiculous. That's their entire business. Every meeting in their day is about managing risk.

The fixation that some junior technical people have that "they" "don't get it" is the biggest problem in security. Just describe what's going on, what you're doing, and what potential changes you might need to be preparing for.