When Cyber Incidents Escalate to Crisis
Most cyber incidents never become crises. Three recent ones did. The Microsoft SharePoint zero-day gave attackers a window into US and German government networks; patches existed, but organizations that sat on them faced ransomware. Salt Typhoon compromised telecom infrastructure across the US and UK at a scale the US government officially classified as a national cyber security crisis. Scatter Spider hit the Collins Aerospace Muse check-in platform — a cloud single point of failure — and grounded flights at Heathrow, Berlin, and Brussels.
“Who is taking the decision? I’m afraid not the tech people. The decision belongs to business guys, the board of the organization. They should take informed decisions.” — George Dobrea
The pattern is the same each time: a technical incident crosses into crisis when impact reaches industry or national scale and the board has to act. Incident response playbooks don’t cover that. Crisis management does.
Crisis Management Framework and Simulation Tools
Crisis response runs on four pillars: preparedness, stakeholder engagement, leadership and decision-making, and strategic communication. Communication shifts at each stage — facts and clear instructions first, then service-recovery updates, then a forward-looking vision once systems are back. Most organizations skip rehearsal entirely. Dobrea showed why that’s a problem by walking through the AI Crisis Simulator live demo (16:12) — a timed online platform where teams pick a response under a three-minute clock and get scored across stakeholder trust, risk management, and ethical leadership. No option scores 100%; that’s the point. Boards and tech teams need to feel that pressure before a real breach forces the decision.
How AI-Driven CTI Works and What It Produces
CTI produces four report types: technical (IOCs, indicators of attack), operational (details on incoming attacks), tactical (campaigns and TTPs for IT management), and strategic. Strategic is the one that matters most during a crisis.
“Cyber threat intelligence is connecting the dots and transforming actually the unknown unknowns and no knowns in the cyber security field.” — George Dobrea
Strategic reports pull from dark web feeds, external threat platforms, and internal telemetry to give boards and executives the context they need for decisions. Using Mandiant and Recorded Future, Dobrea’s team correlated apparently unrelated incidents across Germany, Poland, and the Baltic states and attributed them to APT44 Sandworm — in minutes, not weeks.
CTI Platforms Applied to Real Crisis Cases
Dobrea mapped CTI outputs to the three cases. SharePoint: unpatched internet-facing servers and no forensic containment guidance. Salt Typhoon: long dwell times, unpatched network devices, no telco segmentation. Collins Aerospace: a single cloud check-in platform with no vendor backup took airports offline across multiple countries — untested manual procedures meant staff couldn’t fall back. CTI platforms flagged every failure. For countermeasure mapping, he opened the D3FEND CAD live demo (29:18) — an AI-backed graph tool at cyber-defense.org — then showed how the STIX-to-graph tool (GitHub) (31:14) converts a multi-hundred-page Microsoft threat report into an actor-relationship graph in minutes.
Agentic AI in CTI: Reliability Tiers and Human Oversight
Agentic AI in CTI splits cleanly into three reliability tiers. Threat data ingestion, alert triage, and predictive attack simulation sit at the high end — agents can run those with minimal supervision. Patch deployment and endpoint quarantine in non-critical zones land in the middle. Credential revocation, access control changes, and any crisis-level containment decision belong at the bottom: a false positive triggering automated access revocation could cause more damage than the attack it was meant to stop.
“AI is still not reliable. Honestly, we cannot let AI and CTI to work autonomously.” — George Dobrea
The answer is human-on-the-loop, not human-in-the-loop — oversight at the decision boundary, not at every step. Dobrea’s recommendation: integrate CTI output directly with your SOC, so analysts review agentic recommendations before anything touches national infrastructure or access controls.
Q&A
How do you deal with hallucinations when Gen AI models are used to detect attacks like the SharePoint zero-day, given that models don’t have a concept of correct or incorrect — only statistically most likely? The speaker did not address hallucinations — he redirected to patch speed, noting that Microsoft published CVEs and remediation guidance quickly and organizations that applied the patches were protected. ▶ 37:46
Do you think the EU Cyber Resilience Act will have a real impact on preventing and better handling crisis in the future, will companies be ready by December 2027, and will there be market impact? The speaker did not answer the CRA question — after mishearing it as a CTI question, he pivoted to describing CYCLONE E, the ENISA-operated EU crisis response center that deploys cross-country expert teams to member states during large-scale incidents. ▶ 39:54
Are there any AI tools you would recommend for companies to look into for conducting threat hunts internally? He pointed to two categories: commercial platforms that integrate CTI with threat hunting, and free open-source tools on GitHub built around MITRE ATT&CK. ▶ 42:36
Notable Quotes
Cyber threat intelligence is connecting the dots and transforming actually the unknown unknowns and no knowns in the cyber security field. George Dobrea · ▶ 19:22
in theory can be done autonomously but in a real world situation probably we are not yet prepared to consider full autonomy on this George Dobrea · ▶ 34:47
AI is still not reliable. Honestly, we cannot let AI and CTI to work autonomously George Dobrea · ▶ 36:38
who is taking the decision I’m afraid not the tech people the decision belongs to business guys the board of the organization they should take informed decisions George Dobrea · ▶ 3:37
Key Takeaways
- Treat every high-impact cyber incident as a potential crisis from day one — incident response playbooks are not enough.
- Run AI-powered tabletop simulations before a crisis; boards and tech teams must rehearse decisions together under time pressure.
- Keep humans on the loop for any CTI-driven action that touches credentials, access control, or national infrastructure — autonomous agentic AI is not ready for those decisions.
About the Speaker
George Dobrea
Co-founder and CEO of XEDUCO Institute, George Dobrea is a cybersecurity expert and a renowned technical instructor with over 35 years of business experience providing consulting and training services to military, commercial, and public organizations in more than 30 countries. He has received fifteen Microsoft Most Valuable Professional (MVP) awards for Security and six “Instructor of The Year” awards from EC-Council.