Billions of Indicators, Zero Action: How We Fixed That @FIRSTdotorg
Billions of Indicators, Zero Action: How We Fixed That  @FIRSTdotorg
Uploaded June 2026 | Updated September 2026, 1 hour ago
Daniel Lima (NTT DATA, BR), Gabriel Testoni (NTT DATA, BR)

Organizations are drowning in data but starving for action. Despite billions of IOCs, feeds, and reports, less than 10% ever translate into a real defensive measure. This session demonstrates how we bridged the “intelligence-to-action gap” by building a modular, automated CTI pipeline — transforming intelligence from static reports into measurable defensive outcomes.

Through real-world examples, we’ll explore how automation, integration, and feedback loops enabled faster detection, smarter enrichment, and scalable response. Attendees will walk away with practical insights to operationalize CTI at any maturity level — even with small teams and open-source tools.

---

Daniel Lima is a specialist in cybersecurity and SOC leadership, advanced persistent threat (APT) defense, cryptography, risk management, and large-scale incident response with over 12 years experience in technology. His experience also extends to P&L management, having overseen high-growth security operations while optimizing cost efficiency and profitability.

As a cybersecurity executive at one of the world’s top three technology companies, Daniel structured and currently lead the largest Security Operations Center (SOC) in the country — a market leader recognized in the ISG Provider Lens Quadrant just two years after its creation. Under his leadership, the SOC achieved more than 100% year-over-year growth for four consecutive years, becoming a benchmark for scalable security operations with at least eight specialized domains (SOCaaS, MSS, CSIRT, OT, VM, Red Team, CTI, and Cloud Security) and over 100 top-tier certified professionals.

Gabriel Testoni is a Cyber Threat Intelligence researcher and cybersecurity instructor with extensive experience in operational intelligence, dark web investigations, and threat actor tracking. With more than a decade in technology, he has specialized in building and leading CTI programs focused on automation, intelligence integration, and large-scale threat detection. Gabriel’s work explores the intersection between intelligence and action — designing architectures that transform analysis into measurable defense outcomes. He is also dedicated to mentoring new professionals in areas such as OPSEC, threat hunting, and intelligence tradecraft, helping teams evolve from reactive operations to proactive defense.
Billions of Indicators, Zero Action: How We Fixed ThatCritical SaaS, Critical Blind Spots: A Detection Engineers Field Guide to SaaS AttacksThe Hidden Cost of CVEs: Can CSAF and VEX Change the Equation?The SOC Of The Future… The Future Is NowOne SOC, The Whole SOC, and Nothing But The SOC, So Help MeEiffel: A Tool to Oversee Incident Response From the HeightsProtecting Customers Through Smarter OSS ManagementOperationalizing AIBOMs: Extending Vulnerability Management to AI Models and DatasetsMalice in the Modules - How NPM Became a Supply-Chain Battleground?One Bad OSINT Can Ruin Everything: How Secure is Your CTI RAG System, and Can You Minimize the Risk?Improving Security Across Nations with FIRST: Sametria McKinney, FIRST MemberClimbing Toward the Summit of Defense: Practical Methods for Strengthening CSIRT Organizations
FIRST |

Billions of Indicators, Zero Action: How We Fixed That

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER