Know Your {Cybersecurity} Customer (KYCC)

In banking and financial services, there’s a concept known as KYC, or Know Your Customer, an essential regulatory obligation. It’s how these organisations:

  • Provide the right service

  • Spot red flags early

  • Manage risk before it becomes a problem

Cybersecurity is no different.

if you don’t know who (or what) you’re protecting and how they consume security information, you’re already behind the eight ball. Inside your organisation, your “customers” are the people who need threat intelligence to make better, faster, more informed decisions.

The type of intelligence they need depends on their role. Here’s the breakdown:

Tactical Threat Intelligence

For teams dealing with incident response and managing threats in real-time:

  • Security Operations Centre (SOC) Analysts

  • Incident Responders

  • Security Engineers

  • Threat Hunters

Operational Threat Intelligence

For those analysing attack campaigns, reviewing breach data and assessing threat context:

  • Threat Intelligence Analysts

  • Security Researchers

  • Incident Response Leads

  • Security Architects

Strategic Threat Intelligence

For decision-makers shaping business risk strategy:

  • C-level Executives, CISOs/BISOs, CxO

  • Business Unit/Portfolio Leads

When you tailor your communication and information to match your customer:

  • Tactical teams get the speed and detail they need to detect and respond right now

  • Operational teams get the patterns and trends they need to adjust defences and anticipate what happens next

  • Strategic leaders get the business risk context they need to decide what’s worth ($) protecting

The Takeaway:

If your threat intelligence doesn’t provide business leaders with the clarity, context, and confidence to act decisively, the organisation remains vulnerable, regardless of how effective your technology is.

Below is an interactive poster that helps illustrate the above with examples of the different types of information each stakeholder typically requires.

KYCC

Know Your Cybersecurity Customer

The Challenge: Security professionals often struggle to influence decisions because vital threat intelligence fails to reach the right people. Just as KYC is essential in banking to understand customer risks, KYCC helps security teams identify who their internal customers are and deliver the right intelligence to the right stakeholders.
T
TACTICAL THREAT INTELLIGENCE
Security Operations Centre (SOC) Analysts
Front-line defenders who monitor security events 24/7. They need real-time IOCs, signatures, and actionable threat data to detect, investigate, and respond to immediate security incidents and alerts.
Click to see examples →
Tactical Intelligence Examples
IP Addresses Malicious C2 servers and botnet infrastructure
File Hashes MD5, SHA1, SHA256 of known malware
DNS Names Blacklisted domains and suspicious FQDNs
YARA Rules Pattern matching for malware detection
← Click to go back
Incident Responders
Rapid response specialists who contain and remediate active security incidents. They require immediate threat context, attack patterns, and technical indicators to effectively isolate threats and prevent further damage.
Click to see examples →
Tactical Intelligence Examples
Attack Vectors Entry points and exploitation methods
C2 Protocols Command & control communication patterns
Malware Families Specific threat indicators and signatures
Containment IOCs Immediate blocking and isolation indicators
← Click to go back
Security Engineers
Technical specialists who implement and configure security tools and controls. They need actionable threat feeds and technical specifications to tune detection systems and automate threat responses.
Click to see examples →
Tactical Intelligence Examples
SIEM Rules Detection logic and log correlation rules
Threat Feeds Automated IOC feeds for tool integration
Firewall Policies Network defence and traffic filtering policies
Regex Patterns Pattern matching for automated detection
← Click to go back
Threat Hunters
Proactive security analysts who search for hidden threats within the environment. They need detailed behavioural indicators, hunting hypotheses, and advanced persistent threat patterns to identify sophisticated attacks.
Click to see examples →
Tactical Intelligence Examples
Behavioural IOCs Suspicious activity patterns and anomalies
Hunting Queries Advanced search queries (KQL, Sigma)
Living-off-the-Land (LOTL) Legitimate tool abuse indicators
Persistence Methods Techniques for maintaining access
← Click to go back
O
OPERATIONAL THREAT INTELLIGENCE
Threat Intelligence Analysts
Specialists who analyse threat data and produce intelligence reports. They need comprehensive threat actor profiles, campaign analysis, and contextual information to develop actionable intelligence products for various stakeholders.
Click to see examples →
Operational Intelligence Examples
Threat Actor Profiles Attribution and behavioural analysis
Campaign Analysis Multi-stage attack lifecycle analysis
TTPs Mapping MITRE ATT&CK technique correlation
Intelligence Reports and Threat Trends Structured analytical products
← Click to go back
Security Researchers
Deep-dive analysts who investigate emerging threats and vulnerabilities. They require detailed malware analysis, exploit research, and vulnerability intelligence to understand new attack techniques and develop countermeasures.
Click to see examples →
Operational Intelligence Examples
Malware Analysis Reverse engineering and behaviour analysis
Exploit Research Vulnerability exploitation techniques
Emerging Threats Zero-day and novel attack methods
Infrastructure Analysis Threat actor infrastructure patterns
← Click to go back
Incident Response Leads
Senior practitioners who coordinate major incident responses and forensic investigations. They need strategic context about threat actors, attack patterns, and campaign intelligence to guide investigation priorities and resource allocation.
Click to see examples →
Operational Intelligence Examples
Attribution Analysis Threat actor identification and motives
Attack Timelines Campaign progression and phases
Similar Incidents Historical attack pattern correlations
Scope Assessment Potential impact and vulnerability enumeration
← Click to go back
Security Architects
Strategic designers who develop security frameworks and controls. They need threat landscape assessments, attack pattern analysis, and architectural implications to design resilient security systems and defensive strategies.
Click to see examples →
Operational Intelligence Examples
Attack Surface Analysis Vulnerability exposure assessments
Control Effectiveness Security measure performance evaluation
Threat Modelling Architecture-specific threat analysis
Industry Patterns Sector-specific attack trends
← Click to go back
S
STRATEGIC THREAT INTELLIGENCE
C-level Executives, CISOs/BISOs, CxO
Senior security and business leaders responsible for organisational cyber risk management. They need high-level threat landscape assessments, business impact analysis, and strategic recommendations to inform executive decision-making and budget allocation.
Click to see examples →
Strategic Intelligence Examples
Business Risk Impact Financial and operational threat assessments
Investment Strategy Security budget allocation priorities
Regulatory Compliance Legal and compliance threat implications
Board Reporting Executive-level risk communications
← Click to go back
Business Unit/Portfolio Leads
Senior business managers responsible for specific divisions or product portfolios. They require business-focused threat briefings that translate cyber risks into operational impacts and help inform strategic business decisions.
Click to see examples →
Strategic Intelligence Examples
Industry Targeting Sector-specific threat landscape trends
Competitive Intelligence Threats targeting industry competitors
Business Continuity Operational resilience and recovery planning
Stakeholder Communication Customer and partner risk messaging
← Click to go back
Previous
Previous

RECAP: AISA CyberCon 2025

Next
Next

From Conceptual to Actual: Intelligence-led Security Architecture