The Art of Cyber Threat Intelligence: A Comprehensive Understanding
暫譯: 網路威脅情報的藝術:全面理解

Thomas, Crawford

  • 出版商: Apress
  • 出版日期: 2026-01-03
  • 售價: $1,370
  • 貴賓價: 9.5$1,302
  • 語言: 英文
  • 頁數: 233
  • 裝訂: Quality Paper - also called trade paper
  • ISBN: 9798868817380
  • ISBN-13: 9798868817380
  • 相關分類: Penetration-test
  • 海外代購書籍(需單獨結帳)

相關主題

商品描述

In the ever-evolving world of cybersecurity, the need for robust and proactive threat intelligence has never been more critical. This book is designed to arm you with the essential knowledge and tools required to establish a world-class cyber threat intelligence (CTI) capability. Authored by Crawford Thomas, a seasoned expert with over two decades of frontline experience in military intelligence and cyber threat intelligence within the financial sector, this guide is not just theoretical--it's a distillation of hard-earned, practical wisdom.

This book is not a typical consultation manual filled with checkboxes and generic advice. Instead, it draws from the real-world experiences of a practitioner who has navigated the complexities of regulatory pressures and excelled in environments that demand nothing less than excellence. Notably, during a recent CBEST testing, Thomas's leadership and the performance of his CTI team were described as "formidable." This recognition underscores the level of expertise and effectiveness you can expect to learn from.

You are invited on a comprehensive journey through the critical stages of building a CTI function: from developing a strategic vision, formulating prioritized intelligence requirements, and selecting the right vendors, to mastering the nuances of intelligence reporting. This book is designed to guide you in creating a CTI capability that not only protects your business, but also enhances its efficacy and fosters an environment of reliability and trust--both internally and externally.

The necessity for this book stems from the current cybersecurity landscape where businesses face an increasing barrage of threats. They require impeccable IT security across all platforms, often taking on risks that stretch beyond their risk appetite. Email systems, provided ubiquitously by major vendors, remain a prime target despite advanced security measures. Meanwhile, the rise of Ransomware as a Service has given a new edge to this already formidable threat, turning organizations into unwitting participants in attacks aimed at third-party applications.

What You Will Learn:

  • How to build a world leading cyber threat intelligence capability that is threat vector focused.
  • Estimate the size of the cyber threat intelligence team you require,
  • How to build the prioritized intelligence requirements (PIRs) and collection plan.
  • How to select the correct cyber security vendor--in line with the PIRs.
  • How to develop 'pull intelligence' production and reporting writing.

Who This Book is for:

This book is for all levels of cyber analyst capability. From the beginner, with a hunger to find a definitive answer to 'what is a cyber threat intelligence capability'? To the expert, who is keen to learn of a better way to do their tradecraft. this book is also for the frustrated and burnt out in-house cyber specialist, who has grown cautious of the vendor market, the costs, the lack of integrations. The 10 year cyber expert who is aware of the changing threat landscape and the need to be more dynamic, responsive and efficient.

商品描述(中文翻譯)

在不斷演變的網路安全世界中,強大且主動的威脅情報需求從未如此關鍵。本書旨在為您提供建立世界級網路威脅情報(CTI)能力所需的基本知識和工具。作者克勞福·托馬斯(Crawford Thomas)是一位擁有超過二十年軍事情報和金融領域網路威脅情報前線經驗的資深專家,本指南不僅僅是理論,而是艱苦獲得的實用智慧的提煉。

本書不是一本典型的諮詢手冊,充滿了檢查清單和一般建議。相反,它源自一位實踐者的真實經驗,他在應對監管壓力的複雜性中游刃有餘,並在要求卓越的環境中表現出色。值得注意的是,在最近的CBEST測試中,托馬斯的領導能力和他的CTI團隊的表現被形容為「強大」。這一認可突顯了您可以期待學習到的專業知識和有效性。

您將被邀請進行一場全面的旅程,探索建立CTI功能的關鍵階段:從制定戰略願景、制定優先的情報需求、選擇合適的供應商,到掌握情報報告的細微差別。本書旨在指導您創建一個不僅能保護您的業務,還能提升其效率並促進內部和外部可靠性與信任的CTI能力。

本書的必要性源於當前的網路安全環境,企業面臨著不斷增加的威脅攻擊。他們需要在所有平台上提供無可挑剔的IT安全,經常承擔超出其風險承受能力的風險。儘管有先進的安全措施,主要供應商普遍提供的電子郵件系統仍然是主要目標。與此同時,勒索軟體即服務(Ransomware as a Service)的興起為這一已經強大的威脅增添了新的優勢,使組織成為針對第三方應用程序攻擊的無意參與者。

您將學到的內容:
- 如何建立以威脅向量為重點的世界領先網路威脅情報能力。
- 如何估算所需的網路威脅情報團隊規模。
- 如何建立優先的情報需求(PIRs)和收集計劃。
- 如何選擇符合PIRs的正確網路安全供應商。
- 如何開發「拉取情報」的生產和報告寫作。

本書適合對象:
本書適合所有層級的網路分析師能力。從渴望找到「什麼是網路威脅情報能力?」的初學者,到希望學習更好技藝的專家。本書也適合那些對供應商市場、成本和整合缺乏信心的沮喪和疲憊的內部網路專家,以及意識到威脅環境變化並需要更具動態、反應迅速和高效的十年網路專家。

作者簡介

Crawford Thomas is a former officer in the British Army, with over 20 years service. As a Scotsman, he joined a Scottish infantry regiment, The Argyll and Sutherland Highlanders. After an eventful 10 years, deploying on rural and urban tours in Northern Ireland, as well as squeezing in a 8 month tour as a platoon commander in the 2/1 New Zealand Infantry Regiment, Crawford found himself in command of the UK Ministry of Defence Anti-Terrorist, Training and Advisory Team at the time of 9/11. Immediately after the attack, he deployed to the British Embassy in Washington, marking the start of his transition to the world of intelligence.

Crawford very quickly made the permanent move to military intelligence, seeing tours of Iraq, Afghanistan, Pakistan, Bangladesh and Latin America. During this busy time, Crawford specialised in all aspects of the Intelligence Life Cycle and all capabilities, with one eye on the future and the day when he'd be hunting for a job in the corporate world. Since leaving the military in 2014, Crawford has built award winning 'intelligence led' approaches to cyber security in both regional and global financial institutions. He continues to work in a global bank and finds the most rewarding aspect comes from sharing with peers and benevolent nature of public/private communities. He now is keen to take the sharing one step further in consulting and as an author, putting to print his experiences.

作者簡介(中文翻譯)

克勞福德·托馬斯(Crawford Thomas)是英國陸軍的前軍官,服役超過20年。作為一名蘇格蘭人,他加入了蘇格蘭步兵團——阿蓋爾與薩瑟蘭高地軍團(The Argyll and Sutherland Highlanders)。在經歷了充滿事件的10年後,他在北愛爾蘭進行了鄉村和城市的巡邏,並在新西蘭第2/1步兵團擔任排長的8個月巡邏後,克勞福德在911事件發生時負責英國國防部反恐訓練與顧問小組。攻擊發生後不久,他被派往位於華盛頓的英國大使館,這標誌著他向情報界轉型的開始。

克勞福德很快就永久轉向軍事情報,曾在伊拉克、阿富汗、巴基斯坦、孟加拉國和拉丁美洲執行任務。在這段繁忙的時期,克勞福德專注於情報生命週期的各個方面及所有能力,並對未來充滿期待,期待有一天能在企業界尋找工作。自2014年離開軍隊以來,克勞福德在區域和全球金融機構中建立了獲獎的「以情報為主導」的網絡安全方法。他目前在一家全球銀行工作,並發現最有成就感的部分來自於與同行分享以及公私社區的善意。他現在渴望在顧問和作家的角色中更進一步分享,將他的經驗付諸於印刷。