Digital Content Editor, Eve Goode speaks exclusively with Deborah Galea, PMM for OpenCTI at Filigran about European cyber-defence.
What is the significance of the decision to mandate STIX/TAXII 2.1?
The decision is significant because it changes threat intelligence sharing from a voluntary technical preference to a common operating requirement.
Sharing real-time intelligence is important because it lets organisations learn from attacks happening elsewhere and act before the same threat reaches them, turning isolated defence into a collective one.
However, when organisations use different data formats, versions and proprietary systems, intelligence may technically be available but still require manual conversion or export before it can be shared, causing delays and risking losing the relationships, context and fidelity that make the intelligence actionable.
By mandating the use of STIX/TAXII 2.1 (the global standard for exchanging cyber-threat intelligence), a common language and transport mechanism is established, making fast, automated and two-way sharing far more achievable – while minimising the risk of information getting lost along the way.
It also sends a wider policy signal.
The Netherlands is recognising that cyber-defence is more robust when threat information flows quickly and easily between government bodies, critical infrastructure operators, and their suppliers.
Filigran’s research found that organisations use an average of 14 threat intelligence feeds, yet fewer than half have fully integrated and operationalised their intelligence.
A common standard can help reduce that gap between receiving intelligence and putting it to work.
What are the key advantages of STIX/TAXII 2.1 compared to previous versions?
STIX/TAXII 2.1 represents a major leap in usability and interoperability compared to earlier versions.
Where STIX 1.x relied on complex, verbose XML that was difficult to parse and required specialized tooling, STIX 2.1 uses a lightweight, JSON-based data model.
This makes it far easier to implement, automate, and interpret the intelligence.
The newer version also introduces a more mature and expressive object model.
STIX 2.1 defines clearer relationship objects that link indicators, malware, threat actors, campaigns and attack patterns together, giving a much richer context than the flatter structures in earlier versions.
It also adds standardised patterning language for expressing detection logic consistently across tools, plus new object types (like notes, opinions and grouping objects) that better reflect how analysts actually collaborate.
TAXII 2.1 modernises the transport layer itself by moving to a simple, RESTful API architecture, replacing the more rigid and less scalable messaging protocols of TAXII 1.x.
This makes two-way, machine-to-machine sharing between platforms and organisations far more practical, reliable and scalable.
How important are open standards for improving threat intelligence sharing, particularly against supply chain attacks?
They are critical.
Supply chain attacks cross organisational boundaries, which means no individual company has a complete view of the threat.
A software provider may observe one indicator, a customer may detect suspicious activity elsewhere, and a government agency may understand the wider campaign.
Those fragments become much more useful when they can be exchanged quickly to connect the dots.
Open standards allow organisations with different tools, budgets and levels of maturity to participate without being locked into the same vendor ecosystem.
This is particularly important across large supply chains, where smaller suppliers may otherwise struggle to share intelligence in a usable format.
Speed is also crucial.
When intelligence is trapped in reports, emails or incompatible systems, defenders lose time translating it before they can assess whether they are exposed.
Filigran’s research found that 84% of organisations say attacks often exploit risks that were already known but had not been prioritised.
Better sharing will not solve prioritisation by itself, but structured intelligence gives organisations a stronger basis for identifying which threats are relevant to their sector, location, technologies and suppliers – and which attack patterns they should be checking for.
Should the UK and other European governments follow the Netherlands’ lead and mandate open standards? What impact would this have if they did?
There is a strong case for doing so, particularly across government, critical national infrastructure and regulated supply chains.
A mandate would establish a minimum level of interoperability and prevent threat intelligence sharing from depending on bilateral arrangements, proprietary formats or the technical maturity of individual organisations.
However, governments should mandate outcomes as well as formats.
Requiring organisations to produce STIX 2.1 data would achieve little if the information remained of low quality, lacked context or arrived too late to influence decisions.
Any mandate should therefore be accompanied by practical guidance, implementation support, clear sharing protocols and appropriate safeguards for sensitive information.
If adopted consistently across Europe, open standards could create a much stronger collective defence capability.
Intelligence generated in one country or sector could be consumed more readily elsewhere, enabling faster recognition of campaigns that move through multinational suppliers.
It could also reduce duplicated analysis and make it easier for organisations to integrate public-sector intelligence into their existing security tools.
The longer-term impact would be a move from fragmented threat feeds towards a shared and continuously updated understanding of risk.
That aligns with the wider shift towards intelligence-led exposure management, where real-time threat information informs prioritisation, validation and remediation rather than sitting separately from operational security workflows.
What are the biggest barriers to wider adoption of standardised threat intelligence sharing?
The first barrier is operational complexity. Many organisations already receive large volumes of intelligence but lack the people, processes and integrations needed to structure, contextualise and prioritise it.
Filigran’s research found that 86% still rely to some extent on manual processes for threat analysis, while only 45% have fully integrated and operationalised threat intelligence.
The second is inconsistent maturity across organisations and suppliers.
Larger organisations may have dedicated threat intelligence teams and platforms, while smaller partners may rely on spreadsheets, email alerts or managed services.
A standard only creates value when participants have the ability to produce, consume and act on the information.
Trust and governance also remain substantial challenges.
Organisations may be reluctant to share intelligence that could reveal incidents, weaknesses, customers or investigative activity.
Clear rules are needed around classification, anonymisation, liability, access controls and how shared information may be used.
Finally, there is a cultural barrier.
Threat intelligence sharing is sometimes treated as an additional reporting obligation rather than a core defensive capability.
Wider adoption will require leadership support and workflows that demonstrate a clear benefit to participants.
Organisations are more likely to share consistently when the intelligence they receive in return helps them connect the dots, focus on threats that genuinely matter and improve their defences.