How to prepare for and plan your organisation's response to severe cyber threat: a guide for CNI
Pages
Page 10 of 26
2.2 Increase quality of threat intelligence: focus on attacker tactics, techniques and procedures
Threat intelligence (TI) refers to knowledge of an attacker’s activities. This can range from a simple narrative around a threat actor's motivations, through to in-depth technical descriptions of an attacker's tactics, techniques and procedures (TTPs).
As outlined in NCSC’s Threat Intelligence guidance, the pyramid of pain is a useful tool for thinking about TI. It refers to the amount of extra work – or pain – an attacker will be subjected to if you can detect part of their attack.
2.2.1 The pyramid of pain

TI comes in many formats, as depicted in the pyramid of pain. At the lower levels, open source TI feeds provide details of known bad IP addresses, domains, hashes and strings which can be compared with your logs. Getting a match indicates the system is interacting with a known bad IoC.
At the highest level are Tactics Techniques and Procedures (TTPs) which can be invaluable in creating behavioural analytics. For example, a certain threat actor that is relevant to your organisation has been taking advantage of specific system tools to perform privilege escalation. This kind of information, when used correctly, can be turned into detection use cases.
The bottom of the pyramid is the level where most organisations' cyber defenders focus activity. It is the easiest defence mechanism in terms of implementation and speed, but is not always effective against sophisticated attackers. This is because when you block an IP or hash, attackers can simply rotate infrastructure. TTPs on the other hand, describe how attackers operate – their behaviours, methods, and patterns. Understanding TTPs allows defenders to build a more strategic detection and response function, which is vital in the context of a severe cyber threat environment.
Why TTPs are a better method of defence from sophisticated cyber attacks
| TTPs | IOCs (such as file hashes, domains and IP addresses) |
|---|---|
| Much harder to change quickly because they reflect attackers' underlying capabilities and objectives. | Easy for attackers to change. |
| Proactive: by understanding attacker behaviours, defenders can spot new campaigns even if the specific IOCs are different. | Reactive: you only catch what you already know. |
| TTPs provide higher-level, actionable intelligence that informs architecture hardening, detection engineering, and incident response playbooks. | IOCs can number in the millions and expire quickly, creating vast volumes of unnecessary alerts that distract defenders. |
IOC-based defence may be easy and fast to deploy, but it’s fragile and reactive. TTP-based defence is harder to implement but far more resilient against sophisticated, evolving threats.
2.2.2 Use global knowledge bases to mitigate threats from TTPs
Knowledge bases of TTPs like MITRE ATT&CK enable structured analysis and mapping of adversary behaviour. This helps defenders prioritise controls and mitigations that address the most critical techniques used by threat actors targeting CNI. For ICS, use the Matrix for ICS.


