Skip to main content
Guidance

How to prepare for and plan your organisation's response to severe cyber threat: a guide for CNI

Act now to be ready to withstand and recover from severe cyber attacks.

Page 10 of 26

2.2 Increase quality of threat intelligence: focus on attacker tactics, techniques and procedures

Threat intelligence (TI) refers to knowledge of an attacker’s activities. This can range from a simple narrative around a threat actor's motivations, through to in-depth technical descriptions of an attacker's tactics, techniques and procedures (TTPs).

As outlined in NCSC’s Threat Intelligence guidance, the pyramid of pain is a useful tool for thinking about TI. It refers to the amount of extra work – or pain – an attacker will be subjected to if you can detect part of their attack.


IOC-based defence may be easy and fast to deploy, but it’s fragile and reactive. TTP-based defence is harder to implement but far more resilient against sophisticated, evolving threats.


Published

Reviewed

Version

1.0