Operational Efficiency in CTI: A Blueprint for SMEs Using Open-Source AI and Cognitive Automation @FIRSTdotorg
Operational Efficiency in CTI: A Blueprint for SMEs Using Open-Source AI and Cognitive Automation  @FIRSTdotorg
Uploaded June 2026 | Updated September 2026, 1 hour ago
Omar Saenz (Google, GB), Raquel Guzman (Google, GB)

Small-to-Medium Enterprises (SMEs) are frequently unable to implement traditional CTI programs due to severe budget constraints and a lack of dedicated security expertise, leaving them critically exposed to common threats. This presentation introduces a practical, resource-optimized CTI architecture designed specifically to close this gap. Our solution relies entirely on a standardized open-source stack (OpenCTI, MISP, STIX) integrated with advanced Cognitive Automation to augment human analysis.

We will detail how to use techniques like Retrieval-Augmented Generation (RAG) and agentic AI to automate high-effort CTI tasks, such as IoC and MITRE TTP extraction, drastically reducing the reliance on manual domain expertise. Attendees will leave with a clear blueprint for establishing a maintainable, high-value CTI capability using efficient MLOps and a strict Human-in-the-Loop governance model, ensuring improved cyber resilience at minimal recurring cost.

---

Omar Saenz is a Security Specialist and Cybernetics Futurist at Google Cloud, bringing over 20 years of experience in designing secure solutions, secure cloud transitions, and pioneering security automation. A cybernetics engineer by background, he has held diverse security roles—from research and pen testing to leadership—at major organizations including Deloitte, KPMG, and HSBC. Holding a degree in Cybernetics Engineering, a Master's in Business Innovation, and advanced training in AI from institutions like Oxford University's Saïd Business School, Omar is passionate about democratizing security and sharing insights on automation, having presented at major global events such as the CONFidence Conference, ISF Annual World Congress, and the ISC2 Secure Summit.

Raquel Guzman is a Customer Engineer at Google Cloud, specializing in security, where she guides global customers on implementing best practices to secure their cloud environments. She brings a strong focus on DevSecOps, promoting secure development lifecycles, and applying broad security principles to the unique, rapid development needs of startup organizations. Leveraging her prior background in economics and financial services, Raquel transitioned into IT and information security, bringing a holistic perspective to cyber risk and cloud transformation. Originally from the Dominican Republic, her expertise is now focused on helping customers operationalize cloud security best practices in the UK and in Europe.
Operational Efficiency in CTI: A Blueprint for SMEs Using Open-Source AI and Cognitive AutomationMalicious Code-signing at Scale: How Attackers Impersonate Thousands of Real BusinessesDiving into the CVSS Base Score Metrics - An Exploratory Analysis Bridging Product Security...EU Cyber Resilience Act - A Product Owner’s ApproachContextual SBOMs: Unlocking Precise Vulnerability Management with Build-Time Content IntelligenceThe AI Arms Race in Vulnerability Management, Who’s Winning?Disparate Data, Distorted Decisions: Vendor Data Bias in CTIImproving Security Across Nations with FIRST: Enrico Lovat, FIRST MemberImproving Security Across Nations with FIRST: Cornelia Shipindo, FIRST MemberThe Clock is Ticking: CRA Compliance at ScaleAI Systems Are Software SystemsWhat Can Threat Intel Teams Learn from Journalists?
FIRST |

Operational Efficiency in CTI: A Blueprint for SME's Using Open-Source AI and Cognitive Automation

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER