A Service Architecture for an Enhanced Cyber Threat Intelligence Capability and its Value for the Cyber Resilience of Financial Market Infrastructures

35 Pages Posted: 29 May 2025

Date Written: November 23, 2023

Abstract

In recent years, more and more organizations have been building up or enhancing their own Cyber Threat Intelligence (CTI) capability. Financial entities need to improve their own cyber resilience posture to face the ever-expanding range of money-driven or state sponsored threat actors aiming to undermine the stability of targeted countries by compromising their financial infrastructures. At the same time, the digital transformation process and steadily growing information sharing initiatives make a huge amount of data available for CTI analysis. International committees related to Financial Market Infrastructures (FMI), via commonly agreed policies or directives, and EU institutions, through normative initiatives, are firmly committed to improving the cybersecurity posture of FMIs. To this end, one of the main lines of action is to increase information sharing among financial entities. The large number of heterogeneous information sources and the overwhelming quantity and variety of available data could have negative impacts on the efficiency of CTI activities and compromise the effectiveness of defence capabilities. Therefore, the consolidation and automation of CTI processes must be prioritized in order to improve the effectiveness and sustainability of CTI operations. However, the definition and automation of CTI processes is still at a rather immature stage: for example, well-established and vendor-neutral best practices do not yet exist. The present paper proposes a framework, developed and adopted by the Computer Emergency Response Team of Banca d’Italia (CERTBI) that integrates a taxonomy and specific processes to develop an enhanced CTI capability.

Keywords: CTI service architecture, CTI service components, information triage, intelligence case, technical investigation, security orchestration and automation

JEL Classification: F50, O33, G20, L50, M15

Suggested Citation

Amato, Giuseppe and Ciccarone, Simone and Digregorio, Pasquale and Natalucci, Giuseppe, A Service Architecture for an Enhanced Cyber Threat Intelligence Capability and its Value for the Cyber Resilience of Financial Market Infrastructures (November 23, 2023). Bank of Italy: Markets, Infrastructures, Payment Systems No. 43, Available at SSRN: https://ssrn.com/abstract=5274354 or http://dx.doi.org/10.2139/ssrn.5274354

Simone Ciccarone

Bank of Italy ( email )

Pasquale Digregorio

Bank of Italy ( email )

Giuseppe Natalucci

Bank of Italy ( email )

Do you have a job opening that you would like to promote on SSRN?

Paper statistics

Downloads
4
Abstract Views
67
PlumX Metrics