Teil von: it-sa Expo&Congress 2026 – Intelligence-Driven Cyber-Threat-Modelling, von CTI zur realen Abwehr

Session 01

Cyber Threat Intelligence and the Cyber Threat Model — Webinar 1 (English)

WebinarEnglisch

14 October 2026, 12:30–14:30 CEST

Online

Programm

14 October 202612:30–14:30 CEST

Online

120 min·Track: Technik

What is Cyber Threat Intelligence, how does it differ from a Cyber Threat Model — and what makes a threat model defensible to a supervisor?

Lerninhalte
  • Part 1 · What is Cyber Threat Intelligence (approx. 25 min)
    • 1.1) Definition of Cyber Threat Intelligence (CREST, NCA and CIA definitions — intelligence supports decisions)
    • 1.2) TIBER-EU — framework, roles and deliverables: Scoping Specification Document, Generic Threat Landscape, Targeted Threat Intelligence Report
    • 1.3) Three levels of threat intelligence — strategic, operational, tactical — plus technical intelligence
    • 1.4) Intelligence disciplines (INTs) and intelligence sources
    • 1.5) The intelligence cycle — how bespoke CTI is produced
    • 1.6) From data to intelligence — worked examples: Emotet (MUMMY SPIDER) and Ryuk (WIZARD SPIDER)
    • 1.7) Threat actor attribution — why WIZARD SPIDER (CrowdStrike) is not necessarily FIN12 (Mandiant); AI acceleration as a new kind of intelligence source
  • Part 2 · Cyber Threat Models (approx. 20 min)
    • 2.1) Cyber Threat Intelligence vs. Cyber Threat Modelling — evidence-based knowledge about real attackers vs. structured representations of how attacks could occur
    • 2.2) Definition of a Cyber Threat Model
    • 2.3) Key elements: threat actors · adversary goals, intent and motives · capabilities and resources · attack vectors and paths · target assets and system components · consequences (confidentiality, integrity, availability)
    • 2.4) The threat modelling process in TIBER-EU
  • Part 3 · Formalised vs. non-formalised Cyber Threat Models (approx. 20 min)
    • 3.1) Definition and categorisation of the frameworks by formalisation and modelling perspective — STRIDE, CBEST, TIBER-EU, CAPEC, MITRE ATT&CK
    • 3.2) Why formalisation matters under DORA — a threat model that withstands challenge by supervisor, management, blue team and successor
    • 3.3) Quality criteria for a governed Cyber Threat Model
    • 3.4) Asset-centric, system-centric and threat-centric approaches
  • Part 4 · Building the model — a TIBER-EU worked example (approx. 40 min)
    • 4.1) The Intelligence Collection Plan, aligned with the TIBER-EU TTIR: business parameters, Critical or Important Functions (asset-centric)
    • 4.2) System-centric modelling — decomposition along TIBER-EU operational depth 0 – 6: business context, function decomposition, supporting systems and services, technical components, technical reconnaissance, attack-path relevance, threat intelligence context and threat profiles
    • 4.3) One intelligence requirement, end to end
    • 4.4) Threat-centric modelling — from the Generic Threat Landscape to threat profiles: threat assessment and recent adverse cyber events, relevant threat actors of the German threat landscape, threat-scenario risk scoring, modi operandi (MUMMY SPIDER / Emotet, WIZARD SPIDER / Ryuk) and MITRE ATT&CK
    • 4.5) Threat scenario 1 — attack tree mapped to operational depth, kill chain and modus operandi; CAPEC, CWE and CVE as the formalisation layer under the attack tree
    • 4.6) Environmental effects (PESTLE-M) and the digital footprint — the attacker’s view
    • 4.7) How the three perspectives converge in the threat scenario
  • Q&A (approx. 15 min)
  • What participants take home
    • Participants can say what a Cyber Threat Model is, which elements it must contain, and what makes one defensible under DORA and TIBER-EU — and they have seen one built, from business parameters to a scored threat scenario with an attack tree.
Zielgruppe
  • Security Consultants
  • Security Analysts
  • Security Investigators
  • Threat Hunters
  • Incident Responders
  • CTI Analysts and CTI Managers
  • TLPT / Red-Team Leads

Anmelden

Sessions auswählen *

Webinare (Online)

Workshops (Vor Ort bei der it-sa Expo&Congress)

Diese Website ist durch reCAPTCHA geschützt. Informationen zur Verarbeitung Ihrer Daten finden Sie in unserer Datenschutzerklärung.