3.1.1. Emerging Risk and Threat Landscape
💡 First Principle: Yesterday's threat model only tells you what already happened to someone else; a risk program that reacts solely to known incidents is always a step behind, because by definition a genuinely new attack technique has no incident history yet.
Threat intelligence exists to close that gap by pulling in signal before an organization's own logs contain it: open-source intelligence, information sharing and analysis centers (ISACs) specific to an industry, commercial threat feeds, and monitoring of criminal marketplaces and forums. Horizon scanning — periodically reviewing how the threat landscape is shifting, not just responding to alerts as they arrive — lets a risk program update its register proactively, ahead of exploitation, rather than only after a vendor advisory or a headline breach forces the issue.
| Source Type | Example | Best For |
|---|---|---|
| Open-source intelligence | Public vulnerability disclosures, security research blogs | Broad awareness, early warning |
| ISACs (industry sharing) | Sector-specific threat bulletins | Peer-validated, industry-relevant threats |
| Commercial threat feeds | Vendor-curated indicators of compromise | Automated detection integration |
| Dark web / criminal marketplace monitoring | Stolen credential listings, exploit sales | Early signal on targeted attacks |
This forward-looking posture is precisely what distinguishes a mature risk management function from a purely reactive security operations team: the two roles use much of the same raw intelligence, but risk management is asking "what does this change about our exposure going forward," while operations is asking "is this happening to us right now."
⚠️ Exam Trap: A scenario may suggest that a risk can't be meaningfully assessed until a working exploit exists in the wild. The correct reasoning treats risk assessment as forward-looking — threat intelligence and horizon scanning are meant to support assessing emerging risk before exploitation, not after.
Reflection Question: Your threat intelligence feed reports a novel attack technique with no known exploit yet, targeting technology your organization uses. Should this update your risk register today, or should you wait for a confirmed incident? What does your answer say about the purpose of threat intelligence?