Building a Threat Intelligence Program for Healthcare
Most threat intelligence spending buys feeds nobody acts on. Defining requirements first, choosing sources that match them, and the difference between intelligence and a list of IPs.
GuardsArm Team
Security Experts
Most threat intelligence programmes begin by buying a feed and end by ignoring it. Indicators arrive, get loaded into the SIEM, generate some alerts on stale infrastructure, and the subscription renews out of habit. Nothing about how the organisation defends itself has changed.
Intelligence is not data. It is data that answers a question somebody actually has.
Start with requirements, not vendors
Intelligence requirements are the questions the organisation needs answered. They should be written down, owned, and reviewed. For a hospital they usually look like:
- Which ransomware groups are currently targeting healthcare, and how do they gain initial access?
- Are any of our specific clinical vendors or products under active exploitation?
- Is our data appearing on leak sites or in credential dumps?
- What is being exploited right now that we are exposed to?
- What did the last attack on a comparable organisation actually involve?
Each of these points at a decision: patch priority, a hunt hypothesis, a tabletop scenario, a vendor conversation. A requirement that points at no decision is not a requirement.
Sources, in order of value for healthcare
| Source | Strength | Note |
|---|---|---|
| Health-ISAC | Sector-specific, peer-shared, contextual | The highest-value single source for most hospitals |
| CISA advisories and KEV | Authoritative, actionable, free | KEV should drive patch priority directly |
| FDA and manufacturer advisories | Device-specific | Nobody else covers clinical equipment |
| Government national CERT | Jurisdiction-specific obligations and warnings | Varies by country |
| Commercial feeds | Volume, some enrichment | Easiest to over-buy and under-use |
| Your own incidents | Perfectly relevant by definition | Consistently the most underused source |
Indicators versus behaviour
Indicator intelligence — IPs, domains, hashes — is easy to consume and decays fast. An adversary changes infrastructure between campaigns, sometimes between victims. Blocking last month's IPs is housekeeping, not defence.
Behavioural intelligence describes how a group operates: the initial access vector, the tools, the sequence. That persists, because changing tradecraft is expensive. A group that consistently gains access through a particular remote access product and then uses a particular living-off-the-land technique gives you something durable to detect and to hunt.
Turning intelligence into action
Intelligence that does not reach a decision-maker in a usable form is overhead. Define the routes in advance:
Concrete outputs worth committing to:
- KEV entries present in our estate → emergency patch queue, same week
- A group's initial access vector → a hunt hypothesis, within the month
- A vendor under active exploitation → a direct conversation and a compensating control
- Credentials in a dump → forced reset for the affected accounts
- A peer's incident → next quarter's tabletop scenario
Sizing it honestly
A small hospital does not need an intelligence team. It needs:
- Health-ISAC membership and someone who reads it weekly
- CISA KEV wired into patch prioritisation
- A named person, with allocated time, not a volunteer
- Manufacturer advisory tracking for clinical devices
- A monthly half-page: what changed, what we did
That is a genuine programme. It is also achievable with a few hours a week, which matters more than sophistication nobody can sustain.
For how this feeds detection work, see threat hunting.
GuardsArm helps healthcare organisations define intelligence requirements and build the routes that turn intelligence into changed decisions. Book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on “Building a Threat Intelligence Program for Healthcare”
Talk to the GuardsArm team about how these services apply to your environment.


