Know Your {Cybersecurity} Customer (KYCC)
In banking and financial services, there’s a concept known as KYC, or Know Your Customer, an essential regulatory obligation. It’s how these organisations:
Provide the right service
Spot red flags early
Manage risk before it becomes a problem
Cybersecurity is no different.
if you don’t know who (or what) you’re protecting and how they consume security information, you’re already behind the eight ball. Inside your organisation, your “customers” are the people who need threat intelligence to make better, faster, more informed decisions.
The type of intelligence they need depends on their role. Here’s the breakdown:
Tactical Threat Intelligence
For teams dealing with incident response and managing threats in real-time:
Security Operations Centre (SOC) Analysts
Incident Responders
Security Engineers
Threat Hunters
Operational Threat Intelligence
For those analysing attack campaigns, reviewing breach data and assessing threat context:
Threat Intelligence Analysts
Security Researchers
Incident Response Leads
Security Architects
Strategic Threat Intelligence
For decision-makers shaping business risk strategy:
C-level Executives, CISOs/BISOs, CxO
Business Unit/Portfolio Leads
When you tailor your communication and information to match your customer:
Tactical teams get the speed and detail they need to detect and respond right now
Operational teams get the patterns and trends they need to adjust defences and anticipate what happens next
Strategic leaders get the business risk context they need to decide what’s worth ($) protecting
The Takeaway:
If your threat intelligence doesn’t provide business leaders with the clarity, context, and confidence to act decisively, the organisation remains vulnerable, regardless of how effective your technology is.
Below is an interactive poster that helps illustrate the above with examples of the different types of information each stakeholder typically requires.
KYCC
Know Your Cybersecurity Customer