By Raj Samani, SVP, Chief Scientist, Rapid7

Navigating the past decade of turmoil and coming through this period even stronger is no mean feat. Having been involved with the CTA as far back as 2017, it is so heartwarming to see the CTA team have the opportunity to reflect upon their list of achievements and look to reinforcing their mission of bringing together members to improve the security of the digital ecosystem.

I recall the early meetings with the CTA, where the vision set out by Michael Daniel was to establish a trusted method for commercial competitors to exchange threat intelligence through a shared, reliable platform. What seemed an unlikely path is now a core foundation for how many organisations develop detection logic to protect millions of companies worldwide. 

Whilst this capability should rightly be lauded, for me the most critical component is the opportunity to collectively address the difficulties our industry encounters. From huge geopolitical shifts, to critical industry bodies confronting threats of extinction, to the unintended consequences of regulatory pressures impacting the transparency we depend upon as we conduct digital investigations. In facing each of these risks, the CTA has provided security leaders the opportunity to take action collectively by supplying the much needed voice we would often otherwise lack.

Fostering collaboration

We often cite the need for the information security industry to collaborate with the public sector more effectively, and there are so many examples where the CTA has been able to foster that collaboration. This sounds like a simple task, but if we consider the amount of major political change that has occurred since 2017, we begin to understand just how effective the CTA has been.

To be clear, the political shifts of the last 9 years have not simply been limited to a single geography, but have indeed taken place the world over. Times such as these require an immense amount of effort to not only recruit members, but to maintain member engagement. This is a challenge that I myself witnessed first hand as a founding member of the No More Ransom initiative.

Threat intelligence sharing

I know for many, the CTA is best known for its threat intelligence sharing. With over 700 million observables shared (that’s approximately 16 million per month), this represents a very viable source of intelligence for members. We can easily get lost amongst such massive numbers, and whilst they are certainly extraordinary, we must not overlook the value that the early shares provide. There have been well over a thousand early shares to date, and this data brings a critical deliverable to every security team: namely, time. Having the ability to garner insight into upcoming threat research, and having time to determine potential exposure or coverage without the added burden of global panic is so crucial.

The CTA plays a necessary role in facilitating this collaboration, especially in a commercial environment where sharing relationships can easily become imbalanced. By allowing for the measurement of the volume and quality of intelligence shared, the CTA ensures that all members meet the core governing principle of contributing a minimum level of intelligence.

Achievement unlocked

So as we roll into 2026, a big thank-you to the team at the CTA for building and nurturing a community that shares critical insights, and for providing a platform through which we can collectively articulate the needs of our industry. Congratulations on the nine-year anniversary, which in this world is a remarkable achievement in longevity.   

Back to News