The Threat Intelligence Support Unit (TISU) is an innovative, free, semester-long training program and community, often held at Grand Canyon University (GCU) in Phoenix, designed to provide hands-on cybersecurity skills for students and professionals. Jointly developed with the Arizona Cyber Threat Response Alliance (ACTRA), the program focuses on open-source intelligence (OSINT), threat hunting, and practical, real-world case analysis, frequently training over 200 participants by 2024.
ACTRA is a trusted cybersecurity community where members collaborate under appropriate confidentiality expectations to better understand the threats affecting organizations, why those threats continue to succeed, and what can be done to reduce risk.
Threat intelligence is part of that mission, but ACTRA is not simply another source of alerts, indicators, or reports. ACTRA helps members cut through noise, prioritize what matters, and turn information about threats into practical defensive action.
Modern cybersecurity teams are managing more vendors, more tools, more alerts, more compliance expectations, and more public reporting than ever. ACTRA gives members a trusted environment to share, learn, ask questions, request research, and act on intelligence that has been reviewed for practical value.
ACTRA helps members move from passive awareness to practical readiness.
ACTRA provides a trusted environment where members, analysts, partners, and leaders can discuss threats, defensive challenges, lessons learned, and sensitive security topics with appropriate confidentiality.
This trust enables conversations that often do not happen in public forums, vendor briefings, or broad industry reporting.
ACTRA treats advisories as a disruption to the work members are already doing. For that reason, ACTRA prioritizes intelligence that warrants attention, supports action, and helps members make better defensive decisions.
The goal is not to distribute more information. The goal is to make information about threats result in action again.
Many successful cyber threats are not new. They persist because adversaries continue to find gaps in visibility, process, architecture, vendor coverage, identity controls, remote access, software supply chains, and operational discipline.
ACTRA focuses on these persistent threat patterns and helps members understand what they can do to reduce exposure over time.
ACTRA emphasizes guidance that helps members ask better questions, validate assumptions, improve readiness, and take practical steps against threats that are actively affecting organizations.
Members receive advisories and reports reviewed and promoted by ACTRA’s volunteer analyst community. These products are designed to help organizations understand what matters, why it matters, and what actions may reduce risk.
ACTRA prioritizes advisories that warrant member attention and support practical defensive decisions.
Members receive access to ACTRA’s threat intelligence platform, including web-based access and machine-to-machine intelligence delivery options such as API and STIX/TAXII feeds.
Members receive access to enrichment capabilities that help analysts evaluate indicators, related context, and supporting intelligence as part of their investigative workflows.
ACTRA focuses on these persistent threat patterns and helps members understand what they can do to reduce exposure over time.
ACTRA uses custom-developed automation and orchestration workflows to process, enrich, prioritize, and disseminate intelligence at scale. This helps ACTRA provide more consistent reporting while preserving the practical judgment of its volunteer analyst community.
ACTRA produces ransomware reports that provide statistical analysis of ransomware activity.
These reports help members understand patterns across victims, industries, threat actors, and targeting trends, providing data-driven insight beyond sporadic news coverage of major incidents.
Members benefit from selected partner intelligence reporting, systems, and pre-publication reporting opportunities where available. ACTRA also receives ACTRA-specific intelligence briefs from a primary intelligence partner on a recurring basis.
Members participate in quarterly meetings with ACTRA’s technical volunteer analyst community.
These meetings provide a forum for intelligence sharing, threat discussion, practical collaboration, and community-driven prioritization.
Senior leaders from member organizations are invited to quarterly community leadership sessions focused on strategic awareness, emerging risks, persistent threat patterns, and ACTRA priorities.
ACTRA members can request support to help focus research, reporting, and discussion around the questions that matter most to their organizations.
Member requests may include:
This member-driven model helps ACTRA focus its resources on questions, threats, and defensive challenges that are relevant to the community.