In the seemingly infinite cyber realm, threat intelligence teams navigate between continents in nearly every time zone to combat cyberthreats. John Fokker, head of threat intelligence at Trellix, leads one of these diverse and specialized teams. With about 50 threat intelligence analysts worldwide, they deal with hundreds of millions to a billion malicious file detections each month.

Based in Amsterdam, Netherlands, Fokker's day typically starts between six and seven in the morning. Depending on his workload and schedule, he may start with a trip to the gym before delving into the world of cybersecurity from his home office for most of the days.

He works across various time zones with remote team members from Asia, Europe, Australia and the U.S., so most of the communications are via chat channels like Slack.

As the alerts and messages roll in, Fokker’s typical morning is filled with different activities such as briefings, project-based work, addressing information-collection process hiccups and urgent requests, back-end systems improvements and customer briefings.

In the afternoon, as the U.S. team wakes up, the team meetings will pick up. And by evening, sometimes the team works on a deep dive and connects the dots for malware, threats and attacks analysis and contacts law enforcement agencies like the FBI when significant discoveries are made.

Fokker noted the team operates based on a strategic framework and guidelines. “The team itself will operate,” he told SDxCentral. “Everyone within the team has the responsibility and the ability to alert things internally to say: 'Okay, I think that this is an important thing that we need to have explicit coverage.'

“I don't want to be the person that calls that shot every single time," he added, "because that's an unhealthy organization. I want to make sure to set out the guidelines and the thought process; that's where we're going, this is what we want to achieve. And the people we hire are smart enough to make that judgment call.”

In certain situations, especially when liaising with law enforcement or when legal considerations are involved, the decision-making falls under John's responsibilities. He ensures that shared information is within legal boundaries and does not compromise personally identifiable information (PII).

Trellix’s threat intelligence group, by the numbers

Trellix’s threat intelligence group operates around the clock, collecting and digesting research and intelligence from industry peers and government agencies, analyzing cybercriminal behaviors and attacks, alerting customers, offering threat intelligence services and working with the vendor’s product teams to enhance its cybersecurity services. They also closely collaborate with law enforcement, sharing information and assisting in takedowns of nefarious groups.

Fokker revealed that the team:

  • Has about 45 to 50 dedicated threat intelligence analysts all over the globe, who speak a myriad of languages including Chinese, Hebrew, French, German, Russian and Dutch, reflecting the global perspective of their operations.
  • Receives, on average, between hundreds of millions to a billion malicious file detections through Trellix’s sensors across the globe per month.
  • Follows loosely and tracks information on around 250 different threat groups, keeping closer eyes on at least 100 nefarious families and groups.
  • Tracks about 2,000 to 2,500 malicious and non-malicious tools.
  • Gets around 1,000 indicators per day on average and prioritizes providing relevant and critical information to customers rather than overwhelming them with every detected threat.
Using AI and automation

Trellix’s threat intelligence team has been using artificial intelligence (AI) and automation to help with research and intelligence collection, integrate with alert and malware analysis tools and conduct code analysis.

“I think we've only scratched the surface of what we can do. And it's not in all areas at the level that we actually need it to be,” Fokker said.

He added that AI, especially generative AI (genAI), could be used extensively for disseminating large portions of information to brief the customers and create executive summaries.

Large language models and genAI can help translate highly technical content into business-related context, understandable by senior-level management, and aid in making cybersecurity more comprehensible at a board level. This translation could also help demonstrate the return on investment in cybersecurity to the higher management, bridging the gap between technical and business perspectives, Fokker said.