ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Embracing collective defence against cyber-threats

Jason Keirstead at Cyware explains why collective defence can deliver the cyber-security strength-in-depth organisations need

 

The security market is a rapidly expanding ecosystem driven by a sense of urgency as organisations try to stay ahead of threat actors. From monitoring, encryption and compliance to the internet, endpoints, and every type of tool in between, there are almost endless options available.

 

It’s unsurprising, for instance, that the typical organisation will have anything between 11 and 75 tools to manage, depending on which study you reference. On top of that, there is a rush to integrate AI as vendors upgrade their offerings or develop new products entirely. According to Gartner, “Thirty-four percent of organisations are either already using or implementing artificial intelligence (AI) application security tools.”

 

Clearly, organisations benefit from these advanced technologies, but what often goes missing in the wider security conversation is the value of collaboration. More specifically, the concept of ‘collective defence’ draws on the value that can be derived when organisations share intelligence and insight to significantly boost resilience.

 

The approach is analogous to NATO security doctrine, which states that an attack on one member is an attack on all, with resources pooled to defend against a common threat. In a cyber-security context, collective defence means organisations collaborate across threat intelligence and response functions to identify, mitigate and defeat malicious activity.

 

A community approach

When implemented correctly, this is an extremely powerful strategy to address challenges that might otherwise be much harder to tackle alone. The legal action launched by Microsoft, Fortra LLC and Health-ISAC in 2023 is an interesting example of the approach, with the emphasis on collaboration coming across in the statement they shared last year. The point is that when organisations band together to pursue a common goal, the impact can be much more powerful, unifying, and effective.

 

It’s a message that also comes through very clearly in Microsoft’s 130-page 2023 Digital Defence Report, where collective defence is covered in detail. As Microsoft points out, “The fragmented cyber-security landscape means we are not making the most of the vast amount of threat intelligence and data that is available.” In response, the report offers support for a range of approaches, including the Cybercrime Atlas community project, a public-private approach to building a collective understanding of how criminal groups operate and how they can be disrupted.

 

In addition, Microsoft argues that collective defence can be improved by focusing on the opportunities presented by open-source security, closing the digital talent gap, empowering nonprofits and integrating cyber-security into global sustainability efforts. The point is...

 

Getting involved

So, how can organisations shift their security perspective from one of ‘splendid isolation’ to collective defence? The first step is to understand which stakeholders can provide the relevant support required to get started. These can include a mixture of government agencies, private companies or not-for-profit organisations that have the experience, contacts and processes already in place.

 

When establishing a role within a collective defence community, trust is a key commodity. This can be established via the use of non-disclosure agreements, a commitment to operational transparency and abiding by defined roles and responsibilities. Clear communication is also fundamental to the pursuit of collective defence, with real-time collaboration giving participants scope to exchange everything from intelligence reports to best practices.

 

Looking more closely at information sharing in particular, there can be a lengthy list of indicators of compromise (IoCs), tactics, techniques and procedures (TTPs) to collect and analyse. Through the collaborative development of detection rules, threat-hunting procedures, and incident response playbooks, organisations can work together to create a much more robust approach to their security. If elements of this process can be automated, so much the better.

 

Given the aggressively dynamic risk landscape, it’s important that organisations also work together to analyse security data, which not only identifies patterns and potential threats but also develops and maintains detection and incident response strategies. Without this shared insight, it’s much more likely that security teams will experience gaps in their knowledge, an issue that can seriously exacerbate an emerging security challenge.

 

These priorities can be unified under the umbrella of a Cyber Fusion Centre to combine the way security teams approach key processes around threat intelligence, security automation, threat and incident response and security orchestration. In this situation, the whole can quickly become greater than the sum of the parts by bringing the right experts, tools and technologies together at the right time to respond to threats in the most effective way possible.

 

For those organisations focused on delivering a proactive approach to security, embracing the collective defence doctrine can offer the transformational impact they need.

 


 

Jason Keirstead is VP of Collective Defence at Cyware 

 

Main image courtesy of iStockPhoto.com and Image Source


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543