International Peer-Reviewed JournalOpen AccessISSN 2456-8880
irejournals@gmail.com+91-7433024337

Home / Current Issue / Paper 1708887

1708887 Vol 3 · Issue 8 Download Paper

Integrating Threat Intelligence into Corporate Security Strategy: A Framework for Energy Sector Operations

Ayomipo Ewuola

Subject area: Science,Engineering and Technology  ·  Area of research: Threat intelligence

Abstract

The energy sector is increasingly facing sophisticated and persistent threats that span both the cyber and physical domains, making the integration of threat intelligence into corporate security strategies essential for safeguarding critical infrastructure. This review presents a comprehensive framework for incorporating threat intelligence into the corporate security architecture of energy sector operations. By analyzing the evolving threat landscape including advanced persistent threats (APTs), insider risks, and vulnerabilities in industrial control systems (ICS) and supervisory control and data acquisition (SCADA) systems this underscores the inadequacy of traditional reactive security models. Instead, it emphasizes a proactive and intelligence-driven approach. The proposed framework includes key components such as the classification and sourcing of threat intelligence (strategic, operational, tactical, and technical), alignment with regulatory requirements (e.g., NERC CIP, ISO/IEC 27001), and integration with existing technologies like Security Information and Event Management (SIEM) systems and Threat Intelligence Platforms (TIPs). It advocates for cross-functional governance, robust information-sharing mechanisms, and the use of advanced analytics to transform raw data into actionable insights. Additionally, the framework incorporates threat intelligence into incident response protocols, thereby improving response times and resilience. The study also outlines a phased implementation roadmap tailored for energy organizations, focusing on capacity building, stakeholder engagement, and performance metrics such as mean time to detect (MTTD) and mean time to respond (MTTR). Key challenges such as interoperability, data privacy concerns, and threat intelligence fatigue are addressed to ensure sustainable adoption. Ultimately, the integration of threat intelligence enhances situational awareness, supports informed decision-making, and strengthens overall security posture. This provides both strategic insights and practical tools for energy sector stakeholders aiming to transition from reactive defenses to an anticipatory security model that mitigates risk and ensures continuity of operations.

Keywords

Integrating, Threat intelligence, Corporate security, Strategy, Framework, Energy sector operations

References

[1] Abdula, M., Averdunk, I., Barcia, R., Brown, K. and Emuchay, N., 2018. The cloud adoption playbook: proven strategies for transforming your organization with the cloud. John Wiley & Sons.

[2] Abdulraheem, A.O., 2018. Just-in-time manufacturing for improving global supply chain resilience. Int J Eng Technol Res Manag, 2(11), p.58.

[3] Abu, M.S., Selamat, S.R., Ariffin, A. and Yusof, R., 2018. Cyber threat intelligence–issue and challenges. Indonesian Journal of Electrical Engineering and Computer Science, 10(1), pp.371-379.

[4] Akinsanya, O.O., Papadaki, M. and Sun, L., 2019. Current cybersecurity maturity models: How effective in healthcare cloud?. In CEUR Workshop Proceedings (Vol. 2348, p. 211).

[5] Akinsooto, O., De Canha, D. and Pretorius, J.H.C., 2014, September. Energy savings reporting and uncertainty in Measurement & Verification. In 2014 Australasian Universities Power Engineering Conference (AUPEC) (pp. 1-5). IEEE.

[6] Akpe, O. E. E., Mgbame, A. C., Ogbuefi, E., Abayomi, A. A., & Adeyelu, O. O. (2020). Bridging the business intelligence gap in small enterprises: A conceptual framework for scalable adoption. IRE Journals, 4(2), 159–161. https://irejournals.com/paper-details/1708222

[7] Althonayan, A. and Andronache, A., 2019, June. Resiliency under strategic foresight: The effects of cybersecurity management and enterprise risk management alignment. In 2019 International conference on cyber situational awareness, data analytics and assessment (Cyber SA) (pp. 1-9). IEEE.

[8] Alves, F., Ferreira, P.M. and Bessani, A., 2019, June. Design of a classification model for a twitter-based streaming threat monitor. In 2019 49th annual IEEE/IFIP international conference on dependable systems and networks workshops (DSN-W) (pp. 9-14). IEEE.

[9] Andoni, M., Robu, V., Flynn, D., Abram, S., Geach, D., Jenkins, D., McCallum, P. and Peacock, A., 2019. Blockchain technology in the energy sector: A systematic review of challenges and opportunities. Renewable and sustainable energy reviews, 100, pp.143-174.

[10] Azevedo, R., Medeiros, I. and Bessani, A., 2019, August. PURE: Generating quality threat intelligence by clustering and correlating OSINT. In 2019 18th IEEE International Conference On Trust, Security And Privacy In Computing And Communications/13th IEEE International Conference On Big Data Science And Engineering (TrustCom/BigDataSE) (pp. 483-490). IEEE.

[11] Bauer, J.M. and Reisch, L.A., 2019. Behavioural insights and (un) healthy dietary choices: A review of current evidence. Journal of Consumer Policy, 42, pp.3-45.

[12] Bell, K. and Gill, S., 2018. Delivering a highly distributed electricity system: Technical, regulatory and policy challenges. Energy policy, 113, pp.765-777.

[13] Birkel, H.S., Veile, J.W., Müller, J.M., Hartmann, E. and Voigt, K.I., 2019. Development of a risk framework for Industry 4.0 in the context of sustainability for established manufacturers. Sustainability, 11(2), p.384.

[14] Braun, T., Fung, B.C., Iqbal, F. and Shah, B., 2018. Security and privacy challenges in smart cities. Sustainable cities and society, 39, pp.499-507.

[15] Brown, R. and Lee, R.M., 2019. The evolution of cyber threat intelligence (cti): 2019 sans cti survey. SANS Institute, pp.1-16.

[16] Chand, M., 2018. Aging in South Asia: challenges and opportunities. South Asian Journal of Business Studies, 7(2), pp.189-206.

[17] Chester, M.V. and Allenby, B., 2019. Toward adaptive infrastructure: flexibility and agility in a non-stationarity age. Sustainable and Resilient Infrastructure, 4(4), pp.173-191.

[18] Chinamanagonda, S., 2019. Security in Multi-cloud Environments-Heightened focus on securing multi-cloud deployments. Journal of Innovative Technologies, 2(1).

[19] Coffey, K., Maglaras, L.A., Smith, R., Janicke, H., Ferrag, M.A., Derhab, A., Mukherjee, M., Rallis, S. and Yousaf, A., 2018. Vulnerability assessment of cyber security for SCADA systems. Guide to Vulnerability Analysis for Computer Networks and Systems: An Artificial Intelligence Approach, pp.59-80.

[20] Colicchia, C., Creazza, A., Noè, C. and Strozzi, F., 2019. Information sharing in supply chains: a review of risks and opportunities using the systematic literature network analysis (SLNA). Supply chain management: an international journal, 24(1), pp.5-21.

[21] Dellermann, D., Lipusch, N., Ebel, P. and Leimeister, J.M., 2019. Design principles for a hybrid intelligence decision support system for business model validation. Electronic markets, 29, pp.423-441.

[22] EYEREGBA MAY EQUITOZIA, OMONIYI ONIFADE, FLORENCE SOPHIA EZEH. FEB 2020 | IRE Journals | Volume 3 Issue 8 | ISSN: 2456-8880. IRE 1708075 ICONIC RESEARCH AND ENGINEERING JOURNALS 236. Advances in Budgeting and Forecasting Models for Strategic Alignment in Financial and Nonprofit Organizations.

[23] EYEREGBA MAY EQUITOZIA, OMONIYI ONIFADE, FLORENCE SOPHIA EZEH. JAN 2020 | IRE Journals | Volume 3 Issue 7 | ISSN: 2456-8880. Systematic Review of Financial Operations and Oversight Mechanisms in Multi-Sectoral Organizational Structures.

[24] Falco, G., Caldera, C. and Shrobe, H., 2018. IIoT cybersecurity risk modeling for SCADA systems. IEEE Internet of Things Journal, 5(6), pp.4486-4495.

[25] Fedorov, M., Brunton, G., Estes, C., Fishler, B., Flegel, M., Ludwigsen, A.P., Paul, M. and Townsend, S., 2019, October. In-place technology replacement of a 24x7 operational facility: Key lessons learned and success strategies from the NIF control system modernization. In 17th Int. Conf. on Accelerator and Large Experimental Physics Control Systems (ICALEPCS'19), Brooklyn, NY, USA, Oct.

[26] Fischerkeller, M.P. and Harknett, R.J., 2019. Persistent engagement, agreed competition, and cyberspace interaction dynamics and escalation. The Cyber Defense Review, pp.267-287.

[27] Force, J.T., 2018. Risk management framework for information systems and organizations. NIST Special Publication, 800, p.37.

[28] Ghazi, Y., Anwar, Z., Mumtaz, R., Saleem, S. and Tahir, A., 2018, December. A supervised machine learning based approach for automatically extracting high-level threat intelligence from unstructured sources. In 2018 International Conference on Frontiers of Information Technology (FIT) (pp. 129-134). IEEE.

[29] Gschwandtner, M., Demetz, L., Gander, M. and Maier, R., 2018, August. Integrating threat intelligence to enhance an organization's information security management. In Proceedings of the 13th International Conference on Availability, Reliability and Security (pp. 1-8).

[30] Haider, W., Hafeez, Y., Ali, S., Jawad, M., Ahmad, F.B. and Rafi, M.N., 2019, November. Improving requirement prioritization and traceability using artificial intelligence technique for global software development. In 2019 22nd International Multitopic Conference (INMIC) (pp. 1-8). IEEE.

[31] Islam, C., Babar, M.A. and Nepal, S., 2019. A multi-vocal review of security orchestration. ACM Computing Surveys (CSUR), 52(2), pp.1-45.

[32] Ivanov, D., Dolgui, A., Das, A. and Sokolov, B., 2019. Digital supply chain twins: Managing the ripple effect, resilience, and disruption risks by data-driven optimization, simulation, and visibility. Handbook of ripple effects in the supply chain, pp.309-332.

[33] Iyabode, L.C., 2015. Career Development and Talent Management in Banking Sector. Texila International Journal.

[34] Jahn, M., Gaupp, F. and Obersteiner, M., 2019. Assessing and analysing systemic risks: mapping the topology of risk through time (Chapter 2.1).

[35] Kapsalis, V.C., Kyriakopoulos, G.L. and Aravossis, K.G., 2019. Investigation of ecosystem services and circular economy interactions under an inter-organizational framework. Energies, 12(9), p.1734.

[36] Kovanen, T., Nuojua, V. and Lehto, M., 2018, March. Cyber threat landscape in energy sector. In ICCWS 2018 13th International Conference on Cyber Warfare and Security (p. 353). Academic Conferences and publishing limited.

[37] Kure, H. and Islam, S., 2019. Cyber threat intelligence for improving cybersecurity and risk management in critical infrastructure. Journal of Universal Computer Science, 25(11), pp.1478-1502.

[38] Lamba, A., 2018. Protecting'Cybersecurity & Resiliency'of nation’s critical infrastructure-Energy, oil & gas. International Journal of Current Research, 10, pp.76865-76876.

[39] Leszczyna, R. and Wróbel, M.R., 2019. Threat intelligence platform for the energy sector. Software: Practice and Experience, 49(8), pp.1225-1254.

[40] Li, V.G., Dunn, M., Pearce, P., McCoy, D., Voelker, G.M. and Savage, S., 2019. Reading the tea leaves: A comparative analysis of threat intelligence. In 28th USENIX security symposium (USENIX Security 19) (pp. 851-867).

[41] Lin, W.C. and Saebeler, D., 2019. Risk-based v. compliance-based utility cybersecurity-a false dichotomy. Energy LJ, 40, p.243.

[42] Masombuka, M., Grobler, M. and Watson, B., 2018, June. Towards an artificial intelligence framework to actively defend cyberspace. In European Conference on Cyber Warfare and Security (pp. 589-XIII). Academic Conferences International Limited.

[43] Mgbame, A. C., Akpe, O. E. E., Abayomi, A. A., Ogbuefi, E., & Adeyelu, O. O. (2020). Barriers and enablers of BI tool implementation in underserved SME communities. IRE Journals, 3(7), 211–213. https://irejournals.com/paper-details/1708221

[44] Michels, J.D. and Walden, I., 2018. How Safe is Safe Enough? Improving Cybersecurity in Europe's Critical Infrastructure Under the NIS Directive. Improving Cybersecurity in Europe's Critical Infrastructure Under the NIS Directive (December 7, 2018). Queen Mary School of Law Legal Studies Research Paper, (291).

[45] Moore, D., 2018, May. Targeting technology: Mapping military offensive network operations. In 2018 10th International Conference on Cyber Conflict (CyCon) (pp. 89-108). IEEE.

[46] Nagar, G., 2018. Leveraging Artificial Intelligence to Automate and Enhance Security Operations: Balancing Efficiency and Human Oversight. Valley International Journal Digital Library, pp.78-94.

[47] Nina, P. and Ethan, K., 2019. AI-driven threat detection: Enhancing cloud security with cutting-edge technologies. International Journal of Trend in Scientific Research and Development, 4(1), pp.1362-1374.

[48] Ofori-Asenso, R., Ogundipe, O., Agyeman, A.A., Chin, K.L., Mazidi, M., Ademi, Z., De Bruin, M.L. and Liew, D., 2020. Cancer is associated with severe disease in COVID-19 patients: a systematic review and meta-analysis. Ecancermedicalscience, 14, p.1047.

[49] Omisola, J.O., Etukudoh, E.A., Okenwa, O.K. and Tokunbo, G.I., 2020. Innovating Project Delivery and Piping Design for Sustainability in the Oil and Gas Industry: A Conceptual Framework. perception, 24, pp.28-35.

[50] ONIFADE OMONIYI, MAY EQUITOZIA EYEREGBA, FLORENCE SOPHIA EZEH. MAR 2020 | IRE Journals | Volume 3 Issue 9 | ISSN: 2456-8880. A Conceptual Framework for Enhancing Grant Compliance through Digital Process Mapping and Visual Reporting Tools

[51] Overdevest, C. and Zeitlin, J., 2018. Experimentalism in transnational forest governance: Implementing european union forest law enforcement, governance and trade (FLEGT) voluntary partnership agreements in Indonesia and Ghana. Regulation & Governance, 12(1), pp.64-87.

[52] Pescaroli, G., Wicks, R.T., Giacomello, G. and Alexander, D.E., 2018. Increasing resilience to cascading events: The M. OR. D. OR. scenario. Safety science, 110, pp.131-140.

[53] Peterson, J., Haney, M. and Borrelli, R.A., 2019. An overview of methodologies for cybersecurity vulnerability assessments conducted in nuclear power plants. Nuclear Engineering and Design, 346, pp.75-84.

[54] Pimenta, M.L., 2019. Cross-functional integration in product development processes in the era of industry 4.0. Revista produção e desenvolvimento, 5(1), p.350.

[55] Poore, J., 2018. Delivering on the promise of your brand. Management in Healthcare, 3(2), pp.174-186.

[56] Provan, D.J., Rae, A.J. and Dekker, S.W., 2019. An ethnography of the safety professional’s dilemma: Safety work or the safety of work?. Safety science, 117, pp.276-289.

[57] Rajivan, P. and Gonzalez, C., 2018. Human factors in cyber security defense. Human Factors and Ergonomics for the Gulf Cooperation Council. Edited by Shatha Saman. CRC Press, Boca Raton, Florida, pp.85-104.

[58] Rapuzzi, R. and Repetto, M., 2018. Building situational awareness for network threats in fog/edge computing: Emerging paradigms beyond the security perimeter model. Future Generation Computer Systems, 85, pp.235-249.

[59] Riesco, R. and Villagrá, V.A., 2019. Leveraging cyber threat intelligence for a dynamic risk framework: Automation by using a semantic reasoner and a new combination of standards (STIX™, SWRL and OWL). International Journal of Information Security, 18(6), pp.715-739.

[60] Ross, R., Pillitteri, V., Graubart, R., Bodeau, D. and McQuaid, R., 2019. Developing cyber resilient systems: a systems security engineering approach (No. NIST Special Publication (SP) 800-160 Vol. 2 (Draft)). National Institute of Standards and Technology.

[61] Samuel, T. and Jessica, L., 2019. From Perimeter to Cloud: Innovative Approaches to Firewall and Cybersecurity Integration. International Journal of Trend in Scientific Research and Development, 3(5), pp.2751-2759.

[62] Sandoval, C.J., 2018. Cybersecurity Paradigm Shift: The Risks of Net Neutrality Repeal to Energy Reliability, Public Safety, and Climate Change Solutions. San Diego J. Climate & Energy L., 10, p.91.

[63] Sha, K., Wei, W., Yang, T.A., Wang, Z. and Shi, W., 2018. On security challenges and open issues in Internet of Things. Future generation computer systems, 83, pp.326-337.

[64] Sisinni, E., Saifullah, A., Han, S., Jennehag, U. and Gidlund, M., 2018. Industrial internet of things: Challenges, opportunities, and directions. IEEE transactions on industrial informatics, 14(11), pp.4724-4734.

[65] Srinivas, J., Das, A.K. and Kumar, N., 2019. Government regulations in cyber security: Framework, standards and recommendations. Future generation computer systems, 92, pp.178-188.

[66] Stein, V., Wiedemann, A. and Bouten, C., 2019. Framing risk governance. Management Research Review, 42(11), pp.1224-1242.

[67] Thomas, J., 2018. Individual cyber security: Empowering employees to resist spear phishing to prevent identity theft and ransomware attacks. Thomas, JE (2018). Individual cyber security: Empowering employees to resist spear phishing to prevent identity theft and ransomware attacks. International Journal of Business Management, 12(3), pp.1-23.

[68] Thompson, D.R., Rainwater, C.E., Di, J. and Ricke, S.C., 2018. Student cross-training opportunities for combining food, transportation, and critical infrastructure cybersecurity into an academic food systems education program. In Food and feed safety systems and analysis (pp. 375-391). Academic Press.

[69] Torres, R., Sidorova, A. and Jones, M.C., 2018. Enabling firm performance through business intelligence and analytics: A dynamic capabilities perspective. Information & Management, 55(7), pp.822-839.

[70] Tounsi, W. and Rais, H., 2018. A survey on technical threat intelligence in the age of sophisticated cyber attacks. Computers & security, 72, pp.212-233.

[71] Tounsi, W., 2019. What is cyber threat intelligence and how is it evolving?. Cyber‐Vigilance and Digital Trust: Cyber Security in the Era of Cloud Computing and IoT, pp.1-49.

[72] Vitunskaite, M., He, Y., Brandstetter, T. and Janicke, H., 2019. Smart cities and cyber security: Are we there yet? A comparative study on the role of standards, third party risk management and security ownership. Computers & Security, 83, pp.313-331.

[73] Wagner, T.D., Mahbub, K., Palomar, E. and Abdallah, A.E., 2019. Cyber threat intelligence sharing: Survey and research directions. Computers & Security, 87, p.101589.

[74] Walcutt, J.J. and Schatz, S., 2019. Modernizing Learning: Building the Future Learning Ecosystem. Advanced distributed learning initiative.

[75] Wall, T. and Correia, D., 2018. Police: A Field Guide. Verso Books.

[76] Zhang, L. and Guo, H., 2019. Enabling knowledge diversity to benefit cross-functional project teams: Joint roles of knowledge leadership and transactive memory system. Information & Management, 56(8), p.103156.

How to cite this paper

Ayomipo Ewuola "Integrating Threat Intelligence into Corporate Security Strategy: A Framework for Energy Sector Operations" Iconic Research And Engineering Journals Volume 3 Issue 8 2020 Page 294-310
Ayomipo Ewuola "Integrating Threat Intelligence into Corporate Security Strategy: A Framework for Energy Sector Operations" Iconic Research And Engineering Journals, vol. 3, no. 8, Feb. 2020
Ayomipo Ewuola (2020). Integrating Threat Intelligence into Corporate Security Strategy: A Framework for Energy Sector Operations. Iconic Research And Engineering Journals, 3(8).
Ayomipo Ewuola "Integrating Threat Intelligence into Corporate Security Strategy: A Framework for Energy Sector Operations" Iconic Research And Engineering Journals, vol. 3, no. 8, Feb. 2020.
@article{1708887,
      author = {Ayomipo Ewuola},
      title = {Integrating Threat Intelligence into Corporate Security Strategy: A Framework for Energy Sector Operations},
      journal = {Iconic Research And Engineering Journals},
      year = {2020},
      volume = {3},
      number = {8},
      pages = {294-310},
      issn = {2456-8880},
      url = {https://www.irejournals.com/formatedpaper/1708887.pdf},
      abstract = {The energy sector is increasingly facing sophisticated and persistent threats that span both the cyber and physical domains, making the integration of threat intelligence into corporate security strategies essential for safeguarding critical infrastructure. This review presents a comprehensive framework for incorporating threat intelligence into the corporate security architecture of energy sector operations. By analyzing the evolving threat landscape including advanced persistent threats (APTs), insider risks, and vulnerabilities in industrial control systems (ICS) and supervisory control and data acquisition (SCADA) systems this underscores the inadequacy of traditional reactive security models. Instead, it emphasizes a proactive and intelligence-driven approach. The proposed framework includes key components such as the classification and sourcing of threat intelligence (strategic, operational, tactical, and technical), alignment with regulatory requirements (e.g., NERC CIP, ISO/IEC 27001), and integration with existing technologies like Security Information and Event Management (SIEM) systems and Threat Intelligence Platforms (TIPs). It advocates for cross-functional governance, robust information-sharing mechanisms, and the use of advanced analytics to transform raw data into actionable insights. Additionally, the framework incorporates threat intelligence into incident response protocols, thereby improving response times and resilience. The study also outlines a phased implementation roadmap tailored for energy organizations, focusing on capacity building, stakeholder engagement, and performance metrics such as mean time to detect (MTTD) and mean time to respond (MTTR). Key challenges such as interoperability, data privacy concerns, and threat intelligence fatigue are addressed to ensure sustainable adoption. Ultimately, the integration of threat intelligence enhances situational awareness, supports informed decision-making, and strengthens overall security posture. This provides both strategic insights and practical tools for energy sector stakeholders aiming to transition from reactive defenses to an anticipatory security model that mitigates risk and ensures continuity of operations.},
      keywords = {Integrating, Threat intelligence, Corporate security, Strategy, Framework, Energy sector operations},
      month = {February},
  }