
“Enterprise CISOs should be careful before feeding telemetry into these programs,” said Neil Shah, vice president for research at Counterpoint Research. “The threat intelligence is used to block and defend, but in the future, if it is used under this framework for monitoring, intelligence, and to actively disrupt and/or destroy, it would be detrimental.”
Shah said CISOs will also want assurance that information they share does not expose details of their own infrastructure, particularly where systems may already have been compromised by attackers. Data sharing could also raise privacy concerns if it involves deep tracking of customers, he said.
CISOs should also check whether existing contracts and privacy rules allow such information to be shared if it could later be used for an offensive operation, according to Jain.
