Moving from threat intelligence to understanding business risk

By
Follow google news

AI is forcing security teams to rethink how they prioritise and respond to threats.

The dam wall has burst. The volume of threats and vulnerabilities today’s organisations face exceeds their ability to react in a timely way by orders of magnitude. AI agents, that are either maliciously or accidentally executed, can compromise defences and cause damage to corporate data and applications.

Moving from threat intelligence to understanding business risk

“With the new frontier AI models, we’re seeing a five‑fold increase in CVE [Common Vulnerabilities and Exposures] volume. After the Mythos release and the Glasswing test cases, organisations like Mozilla rolled out patches en masse and Palo Alto reported a 5x jump in discovered vulnerabilities,” says Dan Elliott, the Field CISO for APJ at Recorded Future.

That has led to a massive increase in the number of potential threats that need to be addressed at a time when budgets are constrained and there is a global shortage of cybersecurity experts.

In parallel, motivated actors will have access to models that can run on lower cost hardware, making it easier and cheaper for adversaries to launch attacks at a volume that was inconceivable just a year ago.

(Dan Elliott, the Field CISO for APJ at Recorded Future)

CISOs and other security leaders need to cut through the noise so they can be more strategic about where they deploy their resources. By deploying resources for better detection, rather than waiting to react after a breach, they can be one step ahead instead of two steps behind

The National Vulnerability Database maintained by NIST disclosed approximately 50,000 CVEs in 2025. Recorded Future Intelligence observed that fewer than 1% were exploited in the wild.

Elliott says, “Budget pressure and staffing realities creates a prioritisation challenge where cyber teams must decide how they address vulnerabilities and risks. That requires the use of tools and data that can keep up with the volume of newly disclosed vulnerabilities and focus only on vulnerabilities being exploited in the wild rather than CVE scores. It’s no longer just about finding potential weaknesses. It’s prioritising and acting on the ones most relevant to threat actors in your space before they do.”

The increase in complexity, coupled with the exponential growth in the volume of potential threats, has created a perfect storm that can’t be weathered by people alone.

The sheer scale of that five‑fold rise means teams can’t manually triage everything. And while AI has boosted the number of vulnerabilities being detected, it can also be used for autonomous threat hunting which is increasingly important with the shortage of cybersecurity professionals, explains Elliott.

For example, a large enterprise in the financial services sector recently partnered with Recorded Future to transform their vulnerability management workflow. Following a major patching effort across the organisation, the team built out automation between their vulnerability scanning and IT service management tools, extending visibility across their full attack surface. The result was a streamlined, repeatable process and an estimated weekly time savings of over 20 hours for the team.

Threat Intelligence is mostly tactical and used mainly for detection, hunting and vulnerability triage. But Elliott argues that there are strategic uses once the signal-to-noise ratio is managed. Executive reporting, investment justification and risk-based decision making are areas where there can be significant benefits. But many threat intelligence feeds sit in silos and are presented on dashboards or SOC consoles that are not connected to risk teams or enterprise registers, procurement activities, or operations planning.

Even within the SOC and cyber teams, AI has progressed to a point where it's useful for identifying the methodologies of threat actors and autonomously simulating an attack. This enables teams to test how their triaged list and patched assets would hold up against real threat groups today.

“A complete intelligence lifecycle loop could offer organisations significant benefit.  Threat intelligence often stops at the security operations centre or CISO. If security intelligence is shared with executives and used to inform broader corporate strategy there is significant return on investment available,” says Elliott.

Moving from the tactical goals of detection to the strategic objectives of enterprise      risk management means moving from collecting data from internal telemetry and external sources to prioritising what matters most for the business. That relies on using tools like generative AI and natural language processing while preserving human judgement.

In Elliott’s view, moving to this more strategic operating model starts with completing the integration of threat intelligence into existing security workflows such as detection, response, exposure management and executive risk reporting. By using AI, that data can be leveraged to enhance operational efficiency.

“AI doesn’t replace people,” says Elliott. “It enhances their capacity to filter through the data to focus on threats that put organisational assets at risk. It adds clarity as teams shift from filtering data and information to providing insight and meaningful, actionable advice to the C-suite and boards.”

Moving to this operating model requires an understanding of what is possible and what tools and techniques are available. This is why working with experienced and trusted partners is critical. A reliable partner will not bombard you with a list of features. They will help focus accuracy and coverage to ensure risks are recognised and mitigated.

“The landscape is shifting quickly. We have threats both detected and created at machine speed. Threat actors aren’t somehow smarter, but AI is allowing them to move faster than ever before. It's now about figuring out what needs to be prioritised and working with the tools or a partner that can pinpoint what to do next to protect your business,” says Elliott.

You can reach out to Recorded Future to book a demo to see how intelligence-driven prioritisation can free up your teams’ time and sharpen risk reporting

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

AI Without Governance Is Just Expensive Risk

AI Without Governance Is Just Expensive Risk

Australia’s use of AI is growing faster than its foundations

Australia’s use of AI is growing faster than its foundations

Why traditional cyber risk assessment in cybersecurity is broken

Why traditional cyber risk assessment in cybersecurity is broken

Scaling innovation safely: innovating through rapid prototyping with the mission in mind

Scaling innovation safely: innovating through rapid prototyping with the mission in mind

Log In

  |  Forgot your password?