Managing Cyber Threat Intelligence

Move cyber threat intelligence from general awareness to a repeatable, reviewable practice.

📍 Abu Dhabi🗓️ 5 training days📚 4 modules🎓 Accredited certificate
5intensive training days
4scientific modules
8training sessions
32detailed points

Course Overview

The value of preparation for cyber threat intelligence is only visible on the day it is needed. Insider risk in this aspect of corporate security practice is uncomfortable to discuss and expensive to ignore. The programme takes participants through this area of corporate security practice end to end, from framing the problem to closing it out. Most organisations already have a policy on cyber threat intelligence; far fewer can show it working. Mature organisations treat this part of corporate security practice as a standing capability rather than a project that finishes. The course leaves participants able to diagnose weaknesses in this strand of corporate security practice before they become incidents. The programme works equally well for those formalising cyber threat intelligence for the first time and those improving an existing approach. The teaching approach is deliberately practical: participants build a security procedure for this aspect of corporate security practice as they go. The final module sets out how progress on this part of corporate security practice will be evidenced six months later.

Expected Learning Outcomes

01

Plan the handover of cyber threat intelligence so that capability is not lost when key staff move on.

02

Exercise and test arrangements for cyber threat intelligence under realistic conditions.

03

Build the security operating procedures governing cyber threat intelligence.

04

Sequence improvements to cyber threat intelligence so that each step makes the next one easier.

05

Coordinate with civil defence, police and external authorities on cyber threat intelligence.

06

Balance security requirements in cyber threat intelligence against operational practicality.

07

Identify the failure points in cyber threat intelligence most likely to cause loss, and control them first.

Who Should Attend

01

Members of committees that take decisions affecting cyber threat intelligence.

02

Business continuity and crisis managers covering cyber threat intelligence.

03

Analysts producing the data on which decisions about cyber threat intelligence rest.

04

Control room and monitoring staff operating cyber threat intelligence.

05

Information security staff whose remit overlaps cyber threat intelligence.

06

Investigation and loss prevention specialists working on cyber threat intelligence.

Course Modules

01

Cyber threat intelligence: threat assessment and intelligence

2 sessions · 8 points

Session 1Insider risk inside cyber threat intelligence

  • Confirm vetting standards applied to staff and contractors in cyber threat intelligence.
  • Assess insider risk in roles with privileged access to cyber threat intelligence.
  • Verify six months later that changes to cyber threat intelligence have held.
  • Build the threat picture for cyber threat intelligence from sources relevant to this site and sector.

Session 2Supervising the guard force on cyber threat intelligence

  • Write down the assumptions underpinning the approach to cyber threat intelligence.
  • Confirm access control on cyber threat intelligence cannot be routinely bypassed.
  • Confirm that reporting on cyber threat intelligence reaches the people who can act.
  • Confirm that contractual obligations around cyber threat intelligence are understood.
02

Cyber threat intelligence: insider risk, vetting and personnel security

2 sessions · 8 points

Session 1Access control on cyber threat intelligence that people do not bypass

  • Assess contractor and third-party exposure within cyber threat intelligence.
  • Set escalation criteria and out-of-hours contacts for cyber threat intelligence.
  • Review cyber threat intelligence after every incident, exercise or change in threat.
  • Check that cyber threat intelligence still works when volumes rise unexpectedly.

Session 2Comparing cyber threat intelligence with recognised practice

  • Draft the minimum viable security procedure for cyber threat intelligence.
  • Report on cyber threat intelligence in terms that support an investment decision.
  • Define the first response actions for an incident involving cyber threat intelligence.
  • Rank the weaknesses in cyber threat intelligence by consequence rather than by ease of fixing.
03

Cyber threat intelligence: investigation, evidence and reporting

2 sessions · 8 points

Session 1Reading the current state of cyber threat intelligence honestly

  • Establish what evidence demonstrates cyber threat intelligence is under control.
  • Rehearse the briefing on cyber threat intelligence that would follow an incident.
  • Supervise and spot-check performance on cyber threat intelligence rather than relying on reports.
  • Check guard force instructions for cyber threat intelligence are current and understood.

Session 2Surveillance on cyber threat intelligence that supports an investigation later

  • Record what was learned when cyber threat intelligence did not go as planned.
  • Identify vulnerabilities in cyber threat intelligence and rank them by consequence, not ease of fix.
  • Identify single points of dependency in cyber threat intelligence and reduce them.
  • Set the review interval for cyber threat intelligence and who attends.
04

Cyber threat intelligence: surveillance, monitoring and control rooms

2 sessions · 8 points

Session 1The decisions in cyber threat intelligence that cannot be delegated

  • Coordinate arrangements for cyber threat intelligence with civil defence and police in advance.
  • Close out actions on cyber threat intelligence rather than leaving them open indefinitely.
  • Agree what will be standardised in cyber threat intelligence and what will not.
  • Exercise the plan for cyber threat intelligence under realistic conditions and record failures.

Session 2Exercising the plan for cyber threat intelligence realistically

  • Test the procedure for cyber threat intelligence against a realistic scenario.
  • Build the internal briefing that explains cyber threat intelligence to those affected.
  • Establish evidence handling and chain of custody for cyber threat intelligence.
  • Verify identity checks applied at entry points relevant to cyber threat intelligence.

Choose the package that suits you

Silver Package

At least 3 people

USD1,250
  • Workshop or Program Participation
  • Airport Transfers
  • Customized Badge
  • Expert Mentorship (Private Sessions)
  • Supervision & Secretarial Services
  • Accredited Certificate of Participation
  • Complete Training Kit
  • Coffee Break
  • Closing Ceremony

Gold Package

At least 3 people

USD1,850
  • 5-night stay in a 5-star hotel
  • Workshop or Program Participation
  • Airport Transfers
  • Customized Badge
  • Expert Mentorship (Private Sessions)
  • Supervision & Secretarial Services
  • Accredited Certificate of Participation
  • Complete Training Kit
  • Coffee Break
  • Closing Ceremony

Complete your registration

We will contact you within one business day to confirm.