Intelligent security tools
Assessing intelligent tools for cyber security
Page 4 of 6
Dealing with data
Discover some guiding principles that will give your intelligent tool the best chance of working effectively, using the right data and handling it correctly.
Many intelligent tools require data about your organisation in order to function. This data is processed by the tool to either determine an action, or provide information to the user. It may also be used to further train the tool, allowing it to adapt to new situations.
Having the right data, and ensuring it's handled correctly, is a very important consideration for intelligent tools generally, because the quality and quantity of this data will determine how effectively your tool functions.
Principles
Following the principles in this section will give your intelligent tool the best chance of learning its task well.
The function and value of many intelligent tools will be completely dependent on the data you provide.
Initially, you will need to understand what specific data will be used by the tool, why it is needed, and what format it needs to be presented in.
Following this, you need to find out what parts of this data are currently being collected and ensure they can be made available to the tool. If the data is not currently available, then the method by which that data can be collected needs to be made clear.
Before you purchase any tool, you should have a defined method for obtaining all the data it requires.
Quality and quantity
While you may have access to the right type of data, you should also check that you have access to data of sufficient quality and in sufficient quantity, for the tool to work.
Rules and regulations
Care needs to be taken in verifying that you are able to use the data required by the tool.
Check that the use of any sensitive data complies with your organisation's data handling processes and associated regulations. For those unclear wanting further support, the Information Commissioners Office (ICO) have provided some insights and advice for how to approach this.
You should consider whether you can anonymise the data, such that it is no longer sensitive. If this isn't possible, then look to minimise the number of data fields needed for the tool to operate, especially those involving sensitive data. You should verify with the vendor that the tool can still provide the desired functionality without using some or all sensitive data.
Priorities
There may be some data that is absolutely essential to the operation of the tool, while other data may simply enhance its accuracy, or enable additional features.
For essential data, it is important to know why it is needed, and what will not operate correctly without it.
For non-essential data, you should understand what extra performance is enabled.
Establishing data requirements
- What data does the tool need to function correctly/effectively?
- Are you able to use this data in this way? Are there any legal (or ethical) restrictions on how you can use the data?
- Discuss how resilient the tool is to poor quality data with the vendor. Ensure your data is available in sufficient quantities, and at a suitable quality, to get good performance from the tool.
- What data could you use to gain additional functionality? What functionality does that data get you?
For some tools, your systems will already be producing the data you need. For others, it may need to be specially collected. This could entail additional expense.
You should determine the costs associated with collecting and storing the data, as these might not be included in the cost of the tool itself.
You should also understand how you will collect and store the data your tool requires before purchase. This way you can be sure you'll be able to use it as planned.
Note that the stored data itself may be a target for attackers. If you can gain valuable insights from it, so can your attackers. In addition to data theft, there is also a concern with data tampering. If an attacker can tamper with the data that's being collected, it's possible that the data could be manipulated to influence the decisions being made by the tool.
Determining data availability
- New tools may be required to collect the data - if it's not already available on your system. This cost should be factored into your purchase
- For additional data sets, decide if the added functionality is worth the additional collection, storage and protection costs
- For more information on collecting, storing, and protecting data, see our logging guidance
Once collected, the data needs to be passed to the tool for processing. Some tools run within your system and the data does not leave your estate, whether this is on site or in the cloud. But in some cases, your data may be sent to and stored by the vendor for processing.
Here, your data may be combined with other's to build a much broader picture of threats. This could potentially create a much more powerful tool, but, since AI and machine learning are still new technologies, there are still unanswered questions about how much might be revealed about your data to those with access to the trained tool. This could include other customers of that vendor.
Depending on your data, and your business sector, there may also be important considerations about where and how this data is sent.
It's important that potentially sensitive data you send to a third party is treated in a way that complies with any regulations surrounding data privacy or protection. This might involve knowing how to work with training data that includes Personal Identifiable Information. This includes usage or destruction of data after the end of a tools life or data relating to an individual that has left the organisation.
Many of these issues are consistent with other Software as a Service (SaaS) concerns, more details of which can be found in the current NCSC guidance on the topic.
Correct handling of data
- Will the processing be done within your existing system, in the vendor's system, or on a third party platform? If your data is sent out, where will it be hosted? Is the processing secure?
- What security is applied to data in transit?
- Will the data be stored by the vendor? How will it be stored?
- Does this comply with all the data handling requirements for your sector and data type?


