Cyware President Jawahar Sivasankaran on the Challenges of Operationalizing Threat Intelligence
Cyware president Jawahar Sivasankaran explains why so many cybersecurity teams are still finding it a challenge to operationalize threat intelligence even as cyberattacks continue to increase in volume and sophistication.
Transcript
Hey guys, thanks for, we're here with Jawa, who's president for Ware and we're talking about a survey they did related to threat intelligence of the recent RSAC conference. And it's kind of surprising 'cause, well it turns out that not that many folks are getting a whole lot out of that threat intelligence, but I'm gonna let him explain. Jawa welcome to show.
Yeah, thank you Mike. It's a pleasure being here and I look forward to the discussion. So what is going on here with the usage of threat intelligence?
Because on the face of it, it almost seems like it's another one of those oxymorons. Yeah, so it's, it's two parts, right? If you look at it, hey, the top tier of the enterprise segment, the large government organizations, they're leveraging cyber threat intelligence.
You very sophisticated, but if I can put it that way, right? So we are seeing a lot of traction with large banks, you know, big fortune 500, fortune 1000 type of clients. But where we are seeing adoption, I wouldn't say lacking, but it is getting better as we speak.
You know, moving from legacy tools into full on cyber threat intelligence is as you go one, two tiers below. Uh, and that's a little bit reflective of what we heard in that survey feedback, right? Where they see, hey, cyber threat intelligence is absolutely critical for my overall security needs, but I'm still struggling to operationalize that cyber threat intelligence, which is where cyber we come into play.
Where our goal is to help customers of all sizes operationalize that cyber threat intelligence. For those organizations that are struggling with figuring out what to do with threat intelligence, what is the fundamental challenge that they're encountering? Is there just too much noise and not enough signal for them to do something that's actionable?
I mean, I get that the big guys understand it, but what are the folks who are just newbies to this encountering? Yeah. Beyond the, the large enterprises in the large government organization, the top challenges that we see is still, they're tethered with lots of legacy technologies that they're continuing to invest.
And I think of the SIM tools that have been around for 15 years, uh, where they've not seen the operationalizing part of threat intelligence something that they can go get started. Uh, that is one of the biggest challenges that we have heard from customers because I need to bring in three, four different tools to effectively operationalize the threat intelligence concept itself, which is what we want to simplify, again, bringing in multiple components into the threat intelligence concept, if you will. Not just the traditional threat intelligence platform, but also other things coming to it.
So that is where, you know, we we're pushing this market so that these customers can seamlessly turn on get started or mature their existing CTI program. And to your point, we hear a lot about how organizations might be centralizing the management of cybersecurity and part of the issue that drives that is the consumption of threat intelligence. But other folks will say that they don't want to consolidate 'cause they don't want to be overly dependent upon one tool and they like having that defense in depth.
So, can I have my cake and eat it too here? Can I find a way to operationalize threat intelligence across multiple tools or do I need to centralize my platforms? You don't have to put all your eggs in one basket.
Uh, in fact, again, as we are looking at different tiers, different segments, the upper end of the market, they have multiple thread and thousands feeds typically coming in three, four or five different feeds coming in. And they wanna aggregate that with one platform so that they can correlate that information, look at the high fidelity threats that they want to prioritize to take action. But once you go to this customer base, if you're talking today where these customers, they typically don't have the skillset to ramp up on a threat intelligence program.
So typically in this case, uh, they're looking for a way to get startup, you know, to be very honest. So maybe they have one feed, a threat intel feed that's coming in, maybe an open source feed that's coming in. They just wanna make more sense out of it and get more out of it.
Uh, and that's really where, you know, we're focused to make sure that we're getting the right ROI for that set of customers as they try to operationalize their intelligence. What role might AI play in this in the future? And I'm asking the question 'cause at least in my experience, the, the volume of the threats and the sophistication of the attacks is increasing beyond the ability of a human set of cybersecurity professionals to manage it themselves.
Absolutely. So we're already seeing the impact of AI in cyber threat intelligence. We're seeing it in the broader cybersecurity, but also within the context of SOC security operations center.
But even if you zoom in within the cyber threat a thousand space, we're starting to see AI being leveraged. I mean, the starting point is using NLPD for threat queries, uh, what threat type of threats I'm seeing, how should I prioritize my threats, what actions I should be taking? So that's kind of table stakes if you will.
But where we are seeing this heading towards, and I would say in the next 12, 15, 18 months is a true multi-agent agent AI approach where threats are important, but what do I do with these agents or the multi-agent approach that I'm taking to solve some of the specific problems that I might have been using a legacy tool in the past, and maybe I'm, I was just doing that response in a manual fashion AI and multi-agency approach is going to automate a lot of that in the context of cyber threat intelligence. Of course not all threats are equal and not all threats are equal to the same organizations. And so will we be able to get better at kind of identifying which threats actually have the greatest potential impact for a specific company?
Because you know, a lot of the times they'll look at the threat and they'll say, oh, well I already got that protected. And other cases they'll won't be able to understand that this threat is particularly equal for them. Exactly, exactly.
Not all threats are the same, uh, or not all threats are equal. And even if you look at threats that, you know, what we call as high fidelity threats, high priority threats that you wanna focus on, it might vary by sector to sector. What's critical for financials might not be imported for manufacturing, might not be, might be slightly different for healthcare.
Uh, so we are seeing that evolve where sector specific threat intelligence, threat intelligence management is becoming a higher priority or a focus, uh, as we've seen in the last, you know, couple of years where it's not about CTI and cyber threat intelligence, A one size fits all approach. We gotta be prescriptive about cyber threat intelligence management and response, the action part, and it's based on the size, it's based on the sector, it's based on the geography that you're in. Uh, so again, you know, not all thats are equal.
It's not a one size fits all approach and this is where it becomes super critical. Again, I go back to that border around operationalizing cyber threat intelligence. You can get as many feeds as you want if you're not prioritizing, enriching, correlating the threats the right way, you're not gonna take action on the high priority threats that you should be focused.
What else leaps out in you in this survey that you guys did? I mean, besides the threat intelligence stuff, is there other things in here that you know, you think that, you know, should be top of mind for folks? Yeah, a couple of things that's definitely that, that was a standout for us with the RSA survey, but also we did a follow up survey at the InfoSec event in London, uh, which just happened a couple of weeks back here in June, 2025.
Uh, what came out for us was clearly customers or, or, or the industry itself are starting to prioritize cyber threat intelligence. Uh, what they've struggled in the past is to truly operationalize it, and they're looking for a platform that will help them get there. The second thing that we're also seeing is a, beyond cyber threat intelligence, there is an integration that we are seeing with other areas in cyber, you know, be it digital risk protection, exposure management.
Uh, and, and that's something that we are aligning ourselves. For example, we launched compromised credential management that's integrated into cyber threat intelligence like a month ago. So that integration, that alignment of architecture is happening as well.
And the third thing I'll really point out is compliance in the past used to be more of a checkbox thing as it relates to cyber threat intelligence. Now we're clearly seeing CTI as cyber threat intelligence as a requirement for some of the compliance needs like ISO 27,000 1, 20 22, the deadlines coming up October 31st, 2025. 7 a need to have a cyber threat intelligence program in place.
So we're, we're starting to see this maturity come in in different directions from compliance, from obviously security, but also the response piece that, uh, we've seen over the course of the last couple of years. Do you think there's a greater appreciation for the fact that it's now essentially a race against time? I mean, the minute that the breach happens, the longer it takes for me to fix it, the more damage there's gonna be.
And so has this whole thing moved into kind of a, a near real time battle? Absolutely. And how about flipping the script, not react, but be proactive looking at your threat intelligence information.
So it's not about managing your logs. We all did log management, event management, and we've been doing that for what, 20 years now on the market. Uh, and we still see all of these big breaches, and this is where when we talk to customers, they're clearly saying, yeah, I need to focus on threat and managing threat intelligence.
And that means yes, I want to be, you know, looking at things when there is a breach and looking at threats, you know, that I'm exposed to. But how about flipping the script and being a lot more proactive and connecting the dots, if you will, even before a breach happens? Because I'm able to look at my adversary, the adversarial behavior, the tools, the techniques that they're using, and that means I'm better prepared even before a breach happens.
So what's that one thing you see your organizations doing that still makes you shake your head a little bit and go, folks, we gotta be better than that, Continuing to, uh, sign up or renew their legacy tools? I'll put it that way, right? And I've been in this industry for almost three decades now in 27, 28 years.
Uh, and a lot of times, you know, what I see and I still shake my head, is, you know, something that they started using 10, 12, 15 years ago. Uh, and it served a purpose at that time, uh, but they continue to do the same, expecting a different result. So I, you know, I, I still shake my head, uh, with that.
And then given the market that we play in you, again, coming to cyber threat intelligence, sometimes when I see a game in that segment, which is, you know, below the top tier, uh, not giving enough attention to threats itself, All right folks, you heard it here. Hey, there's a world of difference between responding there a breach, and actually preventing one. And preventing one actually means you gotta lean forward and know what the bad guys are doing before they start launching that attack.
So you can thwart it before it even gets there. Hey, JOA, thanks for being on the show. Awesome life.
It was a pleasure. Thanks so much. All right.
And back to you guys in the studio.