Summary
The core message of the available transcript is that cyber threat intelligence should act as an accelerator for stakeholders by giving direction, visibility, and practical decision support amid overwhelming security information. The Dutch Railways speakers frame CTI as “the Rising Sun”: an independent source that shines light across different domains and helps the organization decide what information is relevant, what is a real threat, and what can be deprioritized. They explain that NS created a CTI team not only to produce intelligence, but to build a capability that integrates intelligence into security processes so the organization can make faster, better, and more threat-driven decisions.
The first major section focuses on building a CTI capability through structure and cadence. The speakers describe combining the Cyber Threat Intelligence Capability Maturity Model, or CTI CMM, with the plan-do-check-act cycle to create the NS CTI framework. The CTI CMM gave them a way to assess maturity across stakeholder domains, while PDCA provided a governance rhythm for continuous improvement. In the planning phase, they began by engaging stakeholders, identifying intelligence needs, and translating that input into a CTI strategy, governance model, and multi-year roadmap. They stress that stakeholder needs must guide everything, including technology requirements, which led them to select EclecticIQ as their threat intelligence platform.
The implementation section describes how the team moved from roadmap to practice. They created an intelligence planning workbook, set up a structured request-for-information process, and began integrating CTI into existing stakeholder processes step by step. The speakers emphasize that stakeholder roadmaps can conflict with CTI ambitions, slowing maturity, and that people holding multiple roles across CTI and SOC functions can create competing priorities and ambiguity. They also describe plans to expand in 2027 into more domains such as identity and access management, third-party risk, and architecture, while pursuing the longer-term ambition of becoming a threat-driven organization and ecosystem driver.
The final available section turns from framework to hands-on examples, especially continuous monitoring. The team uses a “specialist on duty” to monitor external channels, internal channels, and EclecticIQ, triaging information based on relevance, reliability, and urgency for NS. Outputs range from weekly technical threat bulletins with courses of action and detection logic input to simple Teams messages to stakeholder teams. A practical scenario shows CTI helping vulnerability management by flagging active exploitation, then helping supply chain risk and leadership when a vendor breach alert appears. The repeated conclusion is that CTI adds value only when it is measured, fed by stakeholder feedback, and embedded into the real decisions stakeholders must make.
Key Topics
5 key topics from Florianne Kortmann, Marthe Stegehuis and Erik Slingerland at ONE Conference. Thicker branches were mentioned more often in the talk.
Key Takeaways
- Start CTI planning from stakeholder intelligence needs.
- Use structured RFIs to prioritize ad hoc questions.
- Measure CTI value with consistent data and feedback.
- Separate CTI roles to reduce competing priorities.
- Integrate intelligence gradually into existing stakeholder processes.
“we want to become a threat driven organization”
Up Next

Next in agenda
Aligning NIS2 in Practice Across the EU
Dániel Váczi

Also on threat intelligence
VShell: Tracking a State-Actor C2 Framework in the Wild

Also on threat intelligence
A Pragmatic Path to Continuous Purple Teaming
Cas van Cooten