Cyware at MM-ISAC Conference
Understand Where You Are on the CTI Maturity Curve
Blog
Diamond Trail

From Intelligence to Action: Rethinking Cyber Defense for the AI Era

September 13, 20268 min read
Akshat Jain
Akshat Jain

CTO and Co-Founder Cyware

Threat Intelligence in AI Era

When geopolitical tensions escalate, the effects rarely remain confined to the physical world.

Cyber operations have become part of the broader landscape of conflict. Governments, critical infrastructure providers, financial institutions, technology companies, supply chains, and enterprises can find themselves dealing with heightened activity from nation-state actors, hacktivists, criminal groups, and opportunistic attackers.

For security teams, this creates a difficult operating environment. Threats evolve quickly. New threat infrastructure appears. Vulnerabilities are weaponized. Adversary tactics shift. 

Beyond the rapidly evolving threat landscape, managing threat intelligence is further complicated by the sheer number of sources and formats in which intelligence is received. Intelligence arrives from commercial providers, governments, industry communities, open sources, partners, and an organization's own telemetry.

During periods of heightened geopolitical risk, the instinct is naturally to collect more.

But more intelligence does not necessarily create better defense.

The real advantage comes from knowing what matters to your organization, sharing what others need to know, and turning that intelligence into action before the threat becomes an incident.

That is where I believe Cyber Threat Intelligence (CTI) needs to evolve in the AI era.

Cyber Defense in Times of Conflict Has to Be Proactive

There is an important reality about cyber conflict: organizations do not need to be direct participants in a geopolitical confrontation to experience its consequences.

They may operate in a targeted geography, provide services to critical industries, use technology being actively exploited, sit within a strategic supply chain, or simply become collateral targets of disruptive campaigns.

This makes proactive defense particularly important.

The question cannot only be, "Have we been attacked?"

Security teams need to ask: 

  • Which threat actors are becoming more active?

  • Which sectors and regions are they targeting?

  • Which vulnerabilities are they exploiting?

  • Do those vulnerabilities exist in our environment?

  • Are we seeing related behaviors?

  • What have other organizations observed that could help us prepare?

CTI provides the foundation for answering these questions. But during fast-moving situations, intelligence also has a shelf life. Something another organization learns today could help someone else prevent an incident tomorrow, provided it reaches them quickly enough and they can determine its relevance.

This is why threat intelligence sharing is a defensive capability, not simply an information exchange exercise.

No single organization sees the entire threat landscape. One may identify malicious infrastructure. Another may observe a new technique. Someone else may discover how an adversary is exploiting a particular vulnerability. When those observations move across trusted communities, each participant gets a broader view than it could create alone.

That is the foundation of collective defense. But sharing is only half the problem.

More Intelligence Does Not Automatically Mean More Security

Security teams already have access to extraordinary amounts of threat data. The challenge is increasingly not finding intelligence. It is determining what deserves attention.

An indicator can be malicious but irrelevant to your environment. A critical vulnerability can dominate industry discussion while having little immediate impact on an organization that does not use the affected technology. Conversely, a less publicized campaign can be extremely important if it targets your industry, geography, infrastructure, or business model.

Intelligence becomes valuable when it meets context.

That context includes an organization's assets, technology stack, vulnerabilities, exposures, geography, industry, business priorities, and the adversaries most likely to target it.

This becomes even more important during periods of geopolitical instability. When threat activity increases, simply putting more intelligence in front of analysts can make prioritization harder.

The goal should not be to consume everything. It should be to identify what matters early enough to act.

CTI in the AI Era Should Be About Relevance

This is where AI can fundamentally change CTI, but perhaps not in the way we first imagined. The obvious use of AI is scale: summarize more reports, process more indicators, enrich more data, and help analysts search larger intelligence repositories. Those capabilities are useful. But making an overloaded intelligence pipeline faster does not necessarily solve the underlying problem.

I believe the bigger opportunity is different. AI should help us continuously connect intelligence to intent. That means understanding not simply whether a threat is important, but whether it is important to us.

Consider a newly weaponized vulnerability. A traditional workflow might enrich it with severity, exploit availability, affected products, and related threat actors.

An AI-driven intelligence workflow can go further.

  • Do we use the affected technology?

  • Is it exposed?

  • Which critical assets depend on it?

  • Are threat actors relevant to our sector exploiting it?

  • Does current geopolitical activity increase our risk?

  • Have trusted intelligence-sharing partners observed related activity?

  • Which security team needs to know?

  • What should happen next?

That is the difference between processing intelligence and determining relevance.

Start With the Questions That Matter

This brings us to Priority Intelligence Requirements, or PIRs. PIRs give intelligence programs something extremely important: intent.

Instead of beginning with "What intelligence can we collect?", they begin with "What does our organization need to know?"

During a geopolitical crisis, for example, a PIR might focus on whether specific threat actors are targeting organizations in a particular region or sector. Another might focus on exploitation of vulnerabilities affecting critical infrastructure. Another could monitor threats to strategic suppliers.

The problem is that PIRs can remain static. They are documented, reviewed, and understood by analysts, but they do not always continuously govern how every incoming piece of intelligence is evaluated.

In an environment where intelligence changes by the minute, that is a significant limitation. AI gives us the opportunity to make PIRs operational.

From Intelligence Requirements to Intelligence Actions

This is an important part of how we are thinking about Cyware AI and the PIR Agent.

The idea is to move PIRs from static intelligence requirements toward an active layer that helps determine what intelligence matters and what should happen because of it.

A PIR Agent can continuously evaluate intelligence against defined organizational requirements and context. When something relevant emerges, it can help contextualize and prioritize the intelligence, identify who needs it, and support the appropriate downstream workflow.

The model begins to change:

Intelligence → Context → Requirements → Relevance → Action

Humans remain essential to this model. Security leaders and intelligence teams define priorities, establish requirements, provide context, set thresholds, and determine where automation is appropriate. AI agents can operationalize that intent continuously at a speed and scale human teams cannot achieve manually.

The principle is straightforward: Human-defined intent. Machine-speed context. Governed action.

And ultimately, action is what matters.

Relevant intelligence might lead to a hunt, a detection update, accelerated patching, an investigation, a defensive control change, an executive escalation, or intelligence being shared with trusted partners.

The objective is not autonomous security for its own sake. It is reducing the distance between knowing and doing.

Collective Defense at Machine Speed

This becomes particularly powerful when we think beyond a single enterprise. During fast-moving cyber and geopolitical events, one organization's observation can become another organization's early warning.

But collective defense cannot simply mean exchanging larger volumes of indicators. Every participant still needs to understand what shared intelligence means in the context of its own environment.

AI can help close that gap.

Imagine intelligence moving through a trusted ecosystem while each organization continuously evaluates it against its own PIRs, assets, exposures, and priorities. The same intelligence could trigger an immediate investigation for one participant, accelerated remediation for another, and monitoring for a third.

The intelligence can be collective while the relevance remains contextual.

That is how intelligence sharing can evolve into something more operational: collective defense where organizations do not simply learn from each other faster, but defend faster because of what others have learned.

The Next CTI Advantage Is Action

In periods of heightened geopolitical risk, speed matters. But speed without relevance simply creates more noise.

The next evolution of CTI will not be defined by who collects the most intelligence or processes the most indicators. It will be defined by who can determine what matters, connect it to organizational intent, and translate it into defensive action fastest.

That is the opportunity we see with Cyware AI, and it is also a conversation we will be taking forward at GISEC Global 2026 in Dubai: how PIRs, AI agents, intelligence sharing, and collective defense can come together to help organizations respond to a threat landscape that increasingly moves at machine speed.

Because in the AI era, the defining question for CTI is changing.

It is no longer, "How much intelligence can we collect?" It is, "How quickly can we understand what matters, share what others need to know, and act?"

gisec 2026threat intelligenceAI

About the Author

Akshat Jain

Akshat Jain

CTO and Co-Founder Cyware

Business strategy, technology leader, and Co-Founder at Cyware with experience in strategy, operations, and software development. With an entrepreneurial background, has led large-scale product initiatives and thrives on innovation and execution.

Discover Related Resources