Using threat information in industrial environments
Threat intelligence, when properly integrated into a security program, reduces the time to discovery of infiltration as well as the time to recovery after a cybersecurity incident. Early discovery of malicious activity is important because that can reduce the potential impact and damage of an incident, and quick recovery is beneficial to get the environment and the process restored as quickly as possible so production can be restarted. If performed properly, threat intelligence can even help organizations prepare for an attack. As an example, let's say threat intelligence processes have identified that a particular threat actor is sending out phishing emails where the attacker is trying to have the receiver open a Microsoft Word document that supposedly has the negative results for an NCEES exam the receiver supposedly took. The Word document is booby-trapped and installs malware once it is opened: