Skip to content
Notifications
Clear all

Best way to share specific threat intel with our non-technical board?

1 Posts
1 Users
0 Reactions
22 Views
(@billyj)
Honorable Member
Joined: 3 months ago
Posts: 473
Topic starter   [#19588]

Having recently implemented Recorded Future across our organization’s security operations, I've reached a point where the platform's depth of intelligence is both its greatest strength and a significant communication challenge. The executive leadership and board members are requesting regular, digestible updates on the threat landscape relevant to our business, but they lack the technical context to parse raw threat feeds, risk scores, or IOCs. My current dilemma is structuring this intelligence sharing in a way that is both accurate and actionable for a non-technical audience.

My preliminary approach has involved attempting to translate Recorded Future data into a more conventional business format, with mixed results. For instance, I've experimented with:
- Generating weekly summary reports that filter global threat data down to only our identified critical assets and primary industries.
- Converting the Risk Score into a simple "Elevated," "Stable," or "Reduced" status indicator for our key digital properties.
- Extracting narrative summaries from Recorded Future's "Analyst Insights" to provide context on why a particular threat actor or campaign is relevant to us.

However, I am concerned this oversimplification may strip out necessary nuance or, conversely, still be too opaque. I am particularly interested in how others have balanced fidelity with clarity.

Specifically, I would appreciate detailed community feedback on the following workflow components:
- **Report Format & Cadence:** Are you using automated PDF exports from the Recorded Future platform, or are you manually curating intelligence into slide decks for board meetings? What is the optimal frequency for these updates—monthly, quarterly, or triggered by specific risk thresholds?
- **Metric Selection:** Which high-level metrics from Recorded Future have proven most resonant? Is it more effective to focus on trends in attempted phishing attacks against our domain, the volume of leaked credentials discovered, or the monitoring of dark web mentions of our company?
- **Visualization Tools:** Do you find the built-in Recorded Future dashboards sufficient for executive viewing, or do you pipe key risk indicators into a separate business intelligence tool like Grafana or even a simple shared dashboard for broader visibility?
- **Narrative Framing:** How do you effectively link external threat intelligence to internal business outcomes? For example, drawing a direct line between a reported vulnerability in a SaaS platform we use and the potential for operational disruption or financial loss.

The goal is to move beyond simply stating "threats exist" to providing a clear, prioritized picture of exposure that informs strategic resource allocation and risk acceptance decisions at the highest level. Any insights from your own implementations, including pitfalls to avoid, would be invaluable.

— Billy



   
Quote