Evaluating Threat Intelligence Through Velocity @FIRSTdotorg
Evaluating Threat Intelligence Through Velocity  @FIRSTdotorg
Uploaded June 2026 | Updated September 2026, 33 minutes ago
Joe Slowik (Paralus, US)

Cyber threat intelligence (CTI) is, at its core, a discipline of decision support. CTI that cannot enable, improve, or otherwise facilitate a security action is of questionable operational value. In evaluating CTI efficacy, we typically focus on applicability, accuracy, and contextuality, but the relationship of CTI to security actions (particularly for tactical flavors of CTI) also demands examination of another metric: timeliness. Put simply, CTI that arrives too late for the decisions supported is irrelevant.

In this discussion we will explore the implications of a time-oriented view to CTI production, dissemination, and integration into operational decision making. From this we will identify a tension at the core of CTI production: between the speed at which CTI is disseminated and the depth or quality of the CTI produced. Put simply, organizations cannot have immediate decision support while simultaneously having deep contextuality in the current environment, leading to discussions of tradeoffs and continuums of possible CTI outcomes. Evaluating CTI thus becomes a question of determining audience and customer needs, purpose, and response timelines to appropriately structure finished CTI for the given entity in question.

---

Joe Slowik has over 15 years of experience across multiple information security domains, with specializations in cyber threat intelligence, detection engineering, and threat hunting. Joe currently is Director of Cybersecurity Alerting Strategy for Dataminr, and has previously held roles at the MITRE corporation, Huntress, DomainTools, Dragos, Los Alamos National Laboratory, and the US Navy. In addition to the above, Joe also provides threat intelligence training and advising through his company, Paralus LLC.
Evaluating Threat Intelligence Through VelocitySaving Ourselves the ID Headache: How Purls Can Work for Models and DatasetsImproving Security Across Nations with FIRST: Sneha Rangari, FIRSTCON26 SpeakerNational CSIRT as a CVD Hub: Lessons from CERT.PL’s Vulnerability Coordination CasesFrom Roadmap to Results: Measuring CWE Adoption to Enable PreventionFiltering the Noise: Crafting an Actionable Threat Feed from Community-Shared IntelligenceThe Convergence of Threat Behaviors Across IntrusionsForecasting Cybersecurity Data: Making Sense of the SenselessHow EPSS Is Wrong and Useful at the Same TimeWhy is Finnish Healthcare Doing So Well Against Ransomware?The Funny Story of Active Directory BackdooringPivoting To Resilience: Disruptive Incidents And How We Prepare For Them
FIRST |

Evaluating Threat Intelligence Through Velocity

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER