Attackers share information with each other. Tools, vulnerabilities and access change hands on a functioning market, and what one actor learns about Swedish organisations quickly becomes available to more. The defending side has historically been worse at this, for reasons of confidentiality, competition and fear of exposing weakness. This chapter is about why that arrangement has started to change and what an individual organisation gains from it.
It opens with the argument for sharing, what an organisation actually gets out of knowing what others in the same sector are seeing right now. Then comes MISP-SE as the national platform. How it works, who can connect, what connecting means in practical work and what it costs, which for most organisations is nothing. After that comes the cycle from data to action, the steps from collection through processing and analysis to dissemination and measures. That is where most initiatives fail. The information comes in, but it is never related to the organisation's own environment and therefore never reaches anyone who can do something with it. Without that step, threat intelligence is noise with high credibility. A maturity ladder shows how the work can start small and grow gradually, which is the most useful part of the chapter for anyone without an analysis function and with no plans to build one. The chapter closes with the practical pitfalls. The actors doing the sharing are covered in chapter 5 on the cybersecurity ecosystem, and control A.5.7 in chapter 15.
The question is current because threat intelligence is now an explicit control in ISO 27001:2022 and because cooperation has been built out at national level. The opportunity exists and it is open, but it is taken up by considerably fewer organisations than it could be. For anyone unsure where to begin, the answer is almost always to start by receiving, not by analysing.
This page shows what the chapter covers and why sharing gives an advantage. The platform, the cycle and the maturity ladder are in chapter 22 of the book.
Cybersecurity is a team sport. Alone, you lose.
Key insights
- What attackers know about you is shared knowledge on their side. Threat intelligence sharing is how the defence evens that out.
- MISP-SE provides Sweden specific indicators and is free of charge for connected organisations.
- Raw data becomes intelligence only when related to your own environment. Without that step it is noise.
- The maturity ladder matters. Most organisations should start by receiving, not by analysing.
- Sharing rests on reciprocity. Whoever only consumes gets less back over time.
Tools that belong to this chapter
The templates and interactive tools are in the Toolbox, free of charge.
System tools
Platforms and connections for threat intelligence sharing.
Glossary and resource catalogue
The terms used in threat intelligence and the routes to CERT-SE.
Read on
Next step
Where does your organisation stand?
The self-assessment gives you a maturity profile against the ten requirement areas of the Cybersecurity Act in a few minutes, right on screen.