Back to Blog
Threat Intelligence
9 min read

Building a Threat Intelligence Program for Healthcare

Most threat intelligence spending buys feeds nobody acts on. Defining requirements first, choosing sources that match them, and the difference between intelligence and a list of IPs.

GuardsArm Team

Security Experts

January 8, 2026

Threat intelligence

Most threat intelligence programmes begin by buying a feed and end by ignoring it. Indicators arrive, get loaded into the SIEM, generate some alerts on stale infrastructure, and the subscription renews out of habit. Nothing about how the organisation defends itself has changed.

Intelligence is not data. It is data that answers a question somebody actually has.

Requirements first
Without stated questions, a feed is just more data to ignore
Sector sources
Health-ISAC and government advisories carry the context generic feeds lack
Behaviour beats indicators
IPs and hashes expire in days; tradecraft persists for years

Start with requirements, not vendors

Intelligence requirements are the questions the organisation needs answered. They should be written down, owned, and reviewed. For a hospital they usually look like:

  • Which ransomware groups are currently targeting healthcare, and how do they gain initial access?
  • Are any of our specific clinical vendors or products under active exploitation?
  • Is our data appearing on leak sites or in credential dumps?
  • What is being exploited right now that we are exposed to?
  • What did the last attack on a comparable organisation actually involve?

Each of these points at a decision: patch priority, a hunt hypothesis, a tabletop scenario, a vendor conversation. A requirement that points at no decision is not a requirement.


Sources, in order of value for healthcare

SourceStrengthNote
Health-ISACSector-specific, peer-shared, contextualThe highest-value single source for most hospitals
CISA advisories and KEVAuthoritative, actionable, freeKEV should drive patch priority directly
FDA and manufacturer advisoriesDevice-specificNobody else covers clinical equipment
Government national CERTJurisdiction-specific obligations and warningsVaries by country
Commercial feedsVolume, some enrichmentEasiest to over-buy and under-use
Your own incidentsPerfectly relevant by definitionConsistently the most underused source
Your own data is the best feed you have
The phishing your staff reported last month, the credentials found in a dump, the indicators from your last incident — all of it is exactly targeted at you, and most organisations never turn it into structured intelligence. Start here before buying anything.

Indicators versus behaviour

Indicator intelligence — IPs, domains, hashes — is easy to consume and decays fast. An adversary changes infrastructure between campaigns, sometimes between victims. Blocking last month's IPs is housekeeping, not defence.

Behavioural intelligence describes how a group operates: the initial access vector, the tools, the sequence. That persists, because changing tradecraft is expensive. A group that consistently gains access through a particular remote access product and then uses a particular living-off-the-land technique gives you something durable to detect and to hunt.

Indicative useful life of intelligence typesIndicative durability of different intelligence types, showing why behavioural intelligence outlasts indicators.IP addresses8 daysDays of useful lifeDomains21 daysFile hashes30 daysTrivially changed by recompilingTooling / technique400 daysPersists across campaigns
Indicative. The ratio is the point: tradecraft outlives infrastructure by an order of magnitude.

Turning intelligence into action

Intelligence that does not reach a decision-maker in a usable form is overhead. Define the routes in advance:

Intelligence cycle with an action stepCollection is driven by requirements, analysed for relevance, converted into a specific decision and action, then reviewed for whether it helped.Collectagainst requirementsAnalyseis this relevant to us?Decidewhat changes?Actpatch, hunt, detect, briefFeed backdid it help?
Most programmes stop after "analyse". The value is entirely in the last two steps.

Concrete outputs worth committing to:

  • KEV entries present in our estate → emergency patch queue, same week
  • A group's initial access vector → a hunt hypothesis, within the month
  • A vendor under active exploitation → a direct conversation and a compensating control
  • Credentials in a dump → forced reset for the affected accounts
  • A peer's incident → next quarter's tabletop scenario

Sizing it honestly

A small hospital does not need an intelligence team. It needs:

  • Health-ISAC membership and someone who reads it weekly
  • CISA KEV wired into patch prioritisation
  • A named person, with allocated time, not a volunteer
  • Manufacturer advisory tracking for clinical devices
  • A monthly half-page: what changed, what we did

That is a genuine programme. It is also achievable with a few hours a week, which matters more than sophistication nobody can sustain.

For how this feeds detection work, see threat hunting.

GuardsArm helps healthcare organisations define intelligence requirements and build the routes that turn intelligence into changed decisions. Book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on “Building a Threat Intelligence Program for Healthcare”

Talk to the GuardsArm team about how these services apply to your environment.