How to present Threat Intelligence properly to execs????
So, to give some background. I lead the threat intelligence program of a major bank. Now we receive tons of IOCs/CVEs and brand abuse/impersonation cases and we do take action on them accordingly.
But whenever we create a presentation, it's always numbers
- no. Of IOCs we received, sources (regulator/commercials)
- social media/brand abuse/impersonation/rogue apps count & takedown status.
But execs don't understand these numbers. How can I present the data such that they are assured that we are safe from any kind of threat & prepared for what's coming in the future.
Been researching lots of things but didn't quite get anything. Would really appreciate your views and guidance here.