DEV Community

Cover image for Cross-Sector Threat Intelligence Fusion: Building a Unified TI Program Across IT, OT, and Healthcare Environments
Veera Sandiparthi
Veera Sandiparthi

Posted on Originally published at accessquint.com

Cross-Sector Threat Intelligence Fusion: Building a Unified TI Program Across IT, OT, and Healthcare Environments

Nation-state actors don't respect the boundaries your organization draws between its IT helpdesk, industrial control systems, and clinical networks. They map your entire attack surface — and they pivot freely across it. Yet most enterprise threat intelligence (TI) programs remain rigidly siloed: a security operations center (SOC) monitoring endpoint telemetry, an OT team watching SCADA alarms, and a healthcare security group managing EHR access logs — each operating in near-total isolation. The result is a fractured defense that sophisticated adversaries exploit with precision.

Building a unified, cross-sector threat intelligence fusion program is no longer a luxury reserved for the largest government agencies. It is now an operational imperative for any enterprise managing converged IT, operational technology (OT), and healthcare infrastructure. The stakes are high: misaligned intelligence costs critical minutes during active intrusions, enables lateral movement that would otherwise be detectable, and creates compliance exposure across HIPAA, NERC CIP, and NIS2 simultaneously.

This article outlines a structured approach to building a threat intelligence fusion program that bridges these domains and accelerates coordinated defense.

Understanding Why Silos Form — and Why They're Dangerous

The separation between IT, OT, and healthcare security teams is not arbitrary. Each domain evolved with distinct risk tolerances, vendor ecosystems, and regulatory mandates. OT environments prioritize availability above all; a patching window that IT takes for granted could mean halting a manufacturing line or disrupting a power grid. Healthcare security teams operate under strict patient data governance requirements where access controls and audit trails carry legal weight. IT security teams, by contrast, are typically optimized for rapid detection and response in highly dynamic environments.

These differences in operational tempo and culture create natural silos. But they also create intelligence blind spots. An APT group like Volt Typhoon — known for pre-positioning in U.S. critical infrastructure — routinely exploits the gap between IT and OT monitoring by using IT-side living-off-the-land (LOTL) techniques to reach OT environments that have no visibility into those initial access vectors. Similarly, ransomware groups targeting hospital systems frequently enter through general IT networks before pivoting to clinical systems where the operational pressure to restore services is highest and the propensity to pay is greatest.

The Architecture of a Unified Threat Intelligence Fusion Program

A mature cross-sector TI fusion program rests on three structural pillars: a normalized data taxonomy, a federated collection infrastructure, and a centralized intelligence production function.

Normalized Data Taxonomy. The first barrier to cross-sector intelligence fusion is language. IT teams speak in CVEs, MITRE ATT&CK techniques, and IP reputation scores. OT teams reference ICS-CERT advisories, Purdue Model zones, and protocol anomalies in Modbus or DNP3. Healthcare teams track ePHI access events, medical device firmware versions, and HIPAA breach thresholds. A unified TI program requires a shared ontology — a common data model that maps observables, tactics, techniques, and procedures (TTPs) across all three domains to a single, queryable framework. MITRE ATT&CK for ICS and MITRE ATT&CK for Enterprise, used together with sector-specific overlays, provide a defensible starting architecture.

Federated Collection Infrastructure. Centralized collection is not the same as unified collection. A well-designed fusion program maintains domain-specific collection nodes — OT protocol analyzers, healthcare network access monitoring, and IT endpoint detection — but routes enriched telemetry to a shared threat intelligence platform (TIP) using standardized formats such as STIX 2.1 and TAXII. This preserves the operational fidelity of domain-specific data while enabling cross-domain correlation at the intelligence layer. Organizations operating in regulated industries should ensure their TIP architecture supports data residency requirements and role-based access controls that satisfy both HIPAA and NERC CIP audit expectations simultaneously.

Centralized Intelligence Production. Raw telemetry is not intelligence. A cross-sector fusion program requires an intelligence production function staffed by analysts who understand the threat landscape across all three domains — or, at minimum, who can convene rapidly with domain specialists to produce finished intelligence products. This function is responsible for generating priority intelligence requirements (PIRs) that reflect cross-sector risk, producing tactical alerts enriched with cross-domain context, and delivering strategic assessments to executive stakeholders who must make resource allocation decisions across all three environments.

Operationalizing Cross-Sector Intelligence Sharing

Building the architecture is only half the challenge. Operationalizing it requires governance structures that incentivize sharing rather than penalize it.

Establish a cross-sector intelligence working group with representation from IT security, OT engineering, clinical informatics, legal, and compliance. This group should meet weekly at the tactical level and monthly at the strategic level, with a clear escalation path to the CISO and operational leadership. Define explicit rules of engagement for intelligence sharing — including what data can be shared with third-party ISACs (Information Sharing and Analysis Centers) such as FS-ISAC, H-ISAC, and E-ISAC — and ensure legal counsel has reviewed sharing agreements for liability implications under applicable breach notification laws.

Integrate threat intelligence into cross-sector tabletop exercises. A ransomware scenario that starts with a phishing email in the IT environment and cascades into an OT shutdown and a healthcare system failure is not hypothetical — it is the playbook used by groups like Cl0p and BlackCat affiliates. Your tabletop exercises should reflect this reality and use fused intelligence products to drive scenario realism.

Accelerating Coordinated Defense Through Intelligence Feedback Loops

The value of a unified TI program is realized not at the point of collection but at the point of action. Establish bidirectional feedback loops between intelligence consumers and the fusion center. When an OT analyst detects an anomalous lateral movement attempt that matches a TTP flagged in a recent IT-side advisory, that correlation should immediately enrich the original indicator and trigger cross-sector alerting. When a healthcare SOC analyst blocks a command-and-control (C2) domain, that indicator should be automatically pushed to IT and OT detection stacks within minutes — not days.

Automation is essential here. Integrate your TIP with SOAR (Security Orchestration, Automation, and Response) platforms that can enforce cross-sector playbooks. Prioritize automation for low-confidence-threshold, high-fidelity indicators — known malicious IPs, confirmed C2 infrastructure, and hash matches against threat actor toolkits — while preserving human judgment for ambiguous, high-stakes decisions in OT and clinical environments where automated blocking could cause operational harm.

Regulatory Alignment as a Strategic Advantage

A cross-sector TI fusion program, properly documented, generates compliance dividends across multiple regulatory frameworks simultaneously. NERC CIP-007 and CIP-010 require documented security monitoring and configuration management for bulk electric systems. HIPAA's Security Rule mandates risk analysis and ongoing threat assessment for ePHI. NIS2, for organizations with European operations, requires incident reporting and resilience measures across essential service sectors. A unified intelligence program that produces documented, timestamped threat assessments and response records directly satisfies the evidentiary requirements of all three frameworks — reducing the compliance burden that would otherwise require three separate programs.

Building the Program: Where to Start

For organizations beginning this journey, the highest-leverage first step is a cross-sector threat intelligence maturity assessment. Map your current collection capabilities, identify gaps in cross-domain visibility, and benchmark your sharing practices against sector peers. From there, prioritize the normalization of your data taxonomy and the deployment of a TIP capable of ingesting multi-domain feeds in STIX/TAXII format.

The adversaries targeting your organization have already fused their intelligence about you. The only rational response is to fuse yours about them — across every domain they might traverse.


Originally published at accessquint.com.

Top comments (0)