Survey
SANS2022Cyber
ThreatIntelligence
Survey
WrittenbyRebekahBrownandPasqualeStirparo
February2022
?2022SANS?Institute
ExecutiveSummary
Twomajorcybersecurityeventsthatshowcasedtheroleofcyberthreatintelligence(CTI)
innetworksecurityoperationsbookendedthisyear’ssurvey.TheSolarWindssoftware
1
supplychainattackbrokeaswefinishedupthe2021survey,andtheLog4jvulnerability
2
responseprocesswasinfullswingasweworkedtowrapupthe2022survey.Bothevents
highlightedtheneedtorapidlygainsituationalawareness,contextualizevastamountsof
sharedinformation,andprioritizeremediationofsignificantthreats.The2022SANSCTI
surveyshowsthatmanyCTIprogramscanmeetthechallenge.Whilesomeprogramsare
justgettingstartedduetoincreasedcybersecurityneedsandagrowing,complexthreat
environmentbroughtonbytherapidshifttoremotework,organizationscanrelyonCTI
providersandinformation-sharinggroupstofillingapsastheirprogramsmature.
Keytakeaways:
?MoreorganizationsarebeginningtodeveloptheirCTIcapabilities,withan
increasingnumberofrespondentsreportingthattheyareearlyontheirCTI
journeyandstilldevelopingprocessesandgoingthroughthesamegrowingpains
thatmanyrobustCTIprogramspreviouslyfaced.
?Severalpromisingtrendsfrompastyears,suchascollaborationbetweenCTIteams
andbusinessoperationsgroups,havebeenindeclinesincetheshifttoremote
workinresponsetotheCOVID-19pandemic.Ittakesefforttobuildbridges,and
organizationsmayfindcoordinationthatwasalreadynotasintuitiveoringrained
whenorganizationswereprimarilyinpersonevenmoredifficultnow.
?Quiteanimportantpercentageofrespondents,21%,saidthatthey