Skip to main content
Guidance

How to prepare for and plan your organisation's response to severe cyber threat: a guide for CNI

Act now to be ready to withstand and recover from severe cyber attacks.

Page 12 of 26

2.4 Establish frameworks for sharing threat information

It is important to embed effective threat intelligence sharing now –  before a severe cyber incident occurs. Organisations should establish clear governance, legal alignment, and operational workflows. This includes:

  • defining classification rules for what TTPs and IoCs can be shared
  • assigning accountability to a dedicated role which decides what information can be shared
  • creating pre-approved guidance for rapid decisions

Engage your legal teams early to develop frameworks that balance risk and compliance, and are supported by regulatory references to, for example, the NIS regulations on securing network and information systems. Operationally, organisations need streamlined clearance processes, standardised machine-readable formats for IoCs, TTPs, and hunt queries, and contingency plans for sharing partial intelligence. Together, these measures will ensure collaborative, timely, and actionable information exchange during crisis. 

Cyber threat intelligence in government: A guide for decision makers and analysts provides practical guidance for government departments on how to create, mature, and operate a Cyber Threat Intelligence (CTI) capability. The focus is on enabling a threat-led approach to cyber security.

Published

Reviewed

Version

1.0