P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Guide

What is cyber threat intelligence?

Threat intelligence is information analysed until it changes a decision. What NIST actually says, where the four types came from, and how to tell the two apart.

Cyber threat intelligence is information about attackers that has been analysed to the point where it changes a decision. Most products sold under the name stop before that point, which is not a scandal and is worth knowing before the invoice arrives. This guide sets out what the word means, who avoids using it and why, where the four types everybody repeats actually came from, and what the analysis step looks like when it is done on a real case rather than described in the abstract.

Last reviewed:

Cyber threat intelligence is information about attackers that has been analysed to the point where it changes a decision you were going to make anyway. That last clause is the whole subject. A feed of malicious domains is not intelligence, it is information; it becomes intelligence when somebody establishes what it means for a particular organisation and that organisation does something differently as a result.

Before the argument, the mechanism, because the words are easier to keep straight once you have watched them work on something ordinary.

The same three steps, on a cold morning and on a security problem

DATAA fact, on its ownINFORMATIONThe fact, with contextINTELLIGENCEWhat it means, for youAn ordinary morningIt is 4°C outside.It is 4°C and falling. Roads icebelow zero, and it is forecast toreach minus two by six.Send the 07:00 van out at 05:30,or take the main road. Otherwisethe delivery is late.+ context+ analysisThe same three steps, in securityA domain: shiledagent.comIt appeared in a published list ofservers used by a macOSinformation stealer.It was registered a year beforethe campaign, so ournewly-registered-domain rule wasnever going to fire. That ruleneeds revisiting.+ context+ analysisNothing new is collected in the last step. Somebody works out what the middle column means for one particular reader.
Read the top row first. Every reader already does this transformation several times a day without calling it intelligence. The bottom row is the identical operation on a real domain from a real published indicator list, and the security example is not harder, it is just less familiar.

Look at what changes between the second and third columns. Nothing new is collected. Nobody goes out and gathers another fact. Somebody takes what is already sitting in the middle column, works out what it means for one particular reader with one particular problem, and says so plainly enough to act on.

That is the whole job, and it is why a feed cannot do it for you. The feed can fill the first two columns for thousands of items a second. It cannot fill the third, because the third column contains your delivery van, your payroll supplier, your firewall rule.

The distinction sounds pedantic until you notice who insists on it. The United States government's flagship publication in this space is NIST Special Publication 800-150, Guide to Cyber Threat Information Sharing, published in October 2016 by Johnson, Badger and Waltermire of NIST with Snyder and Skorupka of MITRE. It defines its subject like this:

Cyber threat information is any information that can help an organization identify, assess, monitor, and respond to cyber threats.

Read the title again. Information sharing. Across the whole document NIST does not use the phrase "cyber threat intelligence" as its term of art, and the definition it does give is deliberately broad: any information that can help. An industry that sells intelligence has spent a decade building on a foundation whose most cited government document carefully says information instead.

Europe went the other way, which is worth knowing if you buy from vendors on both sides of the Atlantic. ENISA, the European Union Agency for Cybersecurity, uses the term freely: its 2020 threat landscape series includes a dedicated Cyber Threat Intelligence Overview, it has published a study of threat intelligence platforms, and it runs an annual CTI conference. So the same activity is called information sharing in Washington and threat intelligence in Brussels, and neither is wrong. If a definition seems to shift depending on whose document you are reading, that is because it does.

It is worth being fair to NIST about why. SP 800-150 is a guide to sharing, and sharing is something you do with information. The moment a producer analyses something for a specific consumer, it stops being generally shareable, because the analysis is bound to that consumer's estate and risk appetite. The word choice is not an oversight or a criticism of the industry. It is a precise description of what can be passed between organisations, and it quietly marks the boundary this guide is about.

The commercial consequence is the part worth carrying into a procurement meeting. Information and intelligence are priced similarly, described in similar language, and are not substitutes for one another. A buyer comparing two products on coverage, update frequency and integration count is comparing two collection systems, which is a reasonable thing to do and tells you nothing about whether either will change a decision.

An illustration of a heap of identical blank paper slips spilling across a dark surface on the left, and on the right a single sheet of the same paper raised upright in a shaft of warm light, with three thin lines connecting it back to particular slips in the heap.
The illustration is generated and deliberately wordless. Both sides are the same paper, because intelligence is not a different substance from information. What separates them is that somebody picked out which pieces mattered, established how they related, and held the result up where a decision was being made.

Information or intelligence: the test is whether it changes a decision

Most products sold as threat intelligence sit in one quadrant, and it is not the one the brochure implies.

Where a threat product actually sits

A decision changesNothing changes

Raw feed

Domains, hashes and addresses at volume. Useful as input, and on its own it changes nothing.

Tuned detection

The same feed filtered to your stack and wired to an alert somebody owns. Specific, and it changes what your tooling does.

Vendor report

A well-written account of a campaign that may or may not touch you. Generic by design, and often excellent.

Intelligence

An assessment of what a threat means for your organisation, delivered to somebody who can act, with the uncertainty stated.

Generic, true of everyoneSpecific to your estate
The axes are the two questions worth asking of anything you are paying for. Specificity is whether it accounts for your estate, your sector and your exposure. Consequence is whether anybody changed anything after reading it. Most commercial feeds land bottom left and are still worth buying, provided nobody calls them intelligence.

The bottom-left quadrant is not a criticism. A raw feed is a perfectly good product and every programme needs one. The failure is a budget line labelled threat intelligence that buys only the bottom left, and an annual review that never asks which decisions moved.

Notice also that the top right cell is the only one that cannot be bought as a product, because it is defined partly by your organisation. A vendor can get most of the way there with a well-run intelligence service that knows your sector and your stack, and the last step, deciding what to do, is not something anybody can sell you.

The intelligence cycle, and the single phase that does the work

Every textbook draws the same loop, and the loop is genuinely useful. What the textbooks tend not to say is that five of its six phases move information around and exactly one of them produces intelligence.

The cycle, with what each phase produced on one real case

A · THE CYCLE, AND WHAT EACH PHASE PRODUCED ON ONE REAL CASEDirectionDoes this touch our estate?CollectionMicrosoft and RST Cloud reportsProcessingTheir 31 domain indicator tableAnalysisRDAP: one registrar, none from 2026DisseminationThe published briefingFeedbackDid any control actually change?One phase of sixturns information into intelligence.The rest move it around.Handles informationProduces intelligenceUsually absent in practice
Phase names are the standard six. The case is MacSync Stealer, a macOS information stealer analysed by Microsoft Defender Experts and RST Cloud on 18 August 2026 and covered on this site. Analysis is picked out because it is the only phase whose output did not exist before somebody did the work.

One more thing about the loop before leaving it. The phases are drawn as a circle because the output of feedback is supposed to become the input to direction: you learn what your last assessment missed, and that shapes the next question you ask. In practice most programmes run it as a line, and a line has no mechanism for getting better. The organisations that produce genuinely good internal intelligence are almost always the ones that treat the last arrow as real, which costs nothing except the willingness to hear that a report changed nothing.

Direction is a question. Collection is acquisition. Processing is parsing and deduplication. Dissemination is delivery. Feedback is asking whether it mattered. Only analysis takes a set of facts that were already public and produces a statement that was not.

That is why the cycle is worth drawing rather than listing. If you can buy the first three phases and automate the fourth, then a programme can be fully staffed, fully funded and producing nothing that did not arrive in the post.

The cost profile explains why this happens. Direction is a meeting. Collection is a subscription. Processing is a pipeline somebody builds once. Each has a clear owner, a clear price and a clear completion state. Analysis has none of those: it takes an experienced person an unpredictable amount of time, produces a judgement rather than an artefact, and cannot be scheduled in advance because you do not know what you will find. It is the only phase in the loop that behaves like research, and it is therefore the first thing cut when the quarter is tight.

Feedback fails for a different reason. It requires going back to somebody and asking whether the thing you sent them made any difference, which is a question with an uncomfortable answer often enough that the habit rarely forms. A cycle that never closes is not a cycle. It is a pipeline with an arrow drawn on the diagram.

Where programmes actually stop

The rungs a programme reaches, and the ones it does not

B · Where most programmes stop

  1. Direction

    A question someone asked

  2. Collection

    The feed, the report, the alert

  3. Processing

    Deduplicated, parsed, in a table

  4. Analysis

    Someone decides what it means

  5. Dissemination

    To a person who can act

  6. Feedback

    Did a control change?

Buying a feed accomplishes the first three rungs on the day the contract is signed, which is why a programme can look complete while having done none of the work. Analysis is where it starts. Feedback is the rung that would tell you whether any of it changed a control, and it is the one nobody schedules.

Not measured, and it is not offered as a statistic. It is the shape of every threat intelligence function this site has looked at, and it is the reason the question to ask a programme is not what it collects but what it last changed.

Buying a feed accomplishes direction, collection and processing on the day the contract is signed. That is what makes the failure so hard to see from a management report: three of six phases are green, the invoice is being paid, and nobody has yet had to form a view about anything.

The four types everyone repeats came from one paper

Search for threat intelligence types and you will find the same four on almost every page: strategic, operational, tactical and technical. They are usually presented as though they were doctrine, in a pyramid, with no source attached.

It is worth pausing on how unusual that is. Four categories, repeated across hundreds of vendor pages, training courses and job descriptions, presented as settled professional consensus, with no citation anywhere. Not because anybody is hiding the source, but because each page copied the page before it and the attribution fell off somewhere around the third hop. This is worth knowing for its own sake, and it is also a reasonable proxy for how carefully a given page was researched: if it lists the four types and names the origin, somebody read something.

They come from one document. Threat Intelligence: Collecting, Analysing, Evaluating, written by David Chismon and Martyn Ruks at MWR InfoSecurity, published in 2015 in conjunction with CERT-UK and the Centre for the Protection of National Infrastructure. Thirty-six pages, and every page footer carries all three sponsors.

Two of those three no longer exist under those names, which matters if you go looking. CERT-UK was absorbed into the National Cyber Security Centre when it became operational on 3 October 2016, alongside CESG and the Centre for Cyber Assessment. The Centre for the Protection of National Infrastructure became the National Protective Security Authority in March 2023, with a broader remit, under MI5. The model outlived both of its institutional sponsors, which is a reasonable definition of influential and also a reason the citation trail went cold.

The four types, and who they are actually for

TypeWho consumes itWhat it is for
StrategicBoards and executivesRisk, motivation and direction of travel. Prose, not indicators.
OperationalThose defending a specific expected attackThe form and scale of something incoming. The hardest of the four to obtain.
TacticalSecurity managers and architectsAttacker methodology, so defences are built against how people actually work.
TechnicalDetection and response toolingIndicators consumed by machines, with the shortest useful life of the four.
Names and consumers as set out in Chismon and Ruks, MWR InfoSecurity with CERT-UK and CPNI, 2015. The framing there is by consumer rather than by a hierarchy of value, which is a distinction most later summaries drop when they redraw it as a pyramid.

The four-type split is more useful than the pyramid that later replaced it, because it divides by consumer rather than by seniority. A board paper and a detection rule are not two rungs of the same ladder with the board at the top. They are different products, for different readers, with different useful lifetimes, and the same underlying finding may support both or neither.

The paper is also careful about something the summaries drop entirely: operational intelligence, meaning specific forewarning of an attack about to happen to you, is by far the hardest of the four to obtain, and for most organisations it is not realistically available at all. Anyone selling it should be asked how they came by it. That caution is not a footnote in the original and it is absent almost everywhere the four types are repeated.

Reading the table is one thing and using it is another, so here is the same finding from the case later in this guide, turned into four different products for four different readers.

One finding becomes four products, or three and a gap

One finding, four readers

The finding

The domains this campaign rotated through were bought in batches up to a year before anyone reported it.

  • Strategic

    The board, the budget holder

    A control we rely on is weaker than assumed against prepared adversaries. Worth revisiting what else assumes newness equals risk.

  • Operational

    Whoever would defend a specific incoming attack

    Nothing. This tells us no attack is coming, and no feed can.

  • Tactical

    Security managers and architects

    Attackers buy infrastructure in bulk, months ahead. Stop weighting domain age, and pivot on registrar and registration window instead.

  • Technical

    Detection tooling, and the people who feed it

    31 domains, one registrar, two purchase dates. A hunting query, with the shortest useful life of the four.

Four audiences, not four levels of quality. The same finding is a budget conversation, a design decision and a detection rule, and for one of the four it is nothing at all. A vendor selling you the second column should be asked how they came by it.

The finding is real and appears later in this guide. The operational box is drawn empty on purpose: it is the one type that requires forewarning of a specific attack aimed at you, which is the hardest of the four to obtain and which no amount of feed subscription produces. Chismon and Ruks say so, and almost every later summary drops it.

Two things to take from that. The first is that the four types are not four levels of quality with the board at the top, they are four audiences, and a finding that is valuable to one may be worthless to another. The second is that the empty box is the normal case, not a failure. If somebody offers to sell you operational intelligence, the reasonable question is how they came by advance knowledge of an attack aimed specifically at you.

The paper is worth reading in full for a second reason, and it is the thing that reframed this guide while researching it. Its first reference is the Butler Review of Intelligence on Weapons of Mass Destruction, 2004: the British public inquiry into how intelligence assessments on Iraq went wrong.

That is the founding document of UK cyber threat intelligence opening with a citation to an inquiry into intelligence failure. The lineage is worth naming as British rather than universal: an American account of the same discipline would more likely start from military doctrine and the intelligence cycle as taught at Langley, and a European one from ENISA's threat landscape work. The vocabulary is shared, the ancestry is not. Not a vendor case study, not a breach report. An inquiry into confident assessments that turned out to be untrue.

That choice sets the professional standard the field inherited and mostly ignores. The lesson of Butler is not that intelligence is unreliable. It is that intelligence which does not carry its own uncertainty is dangerous, because the caveats get stripped as an assessment travels upward and what reaches the decision-maker is a confident sentence that nobody in the chain would have signed. Any threat report that never says probably, never says we could not verify this, and never distinguishes what was observed from what was inferred, has failed a test that predates cyber security by decades.

Where the vocabulary came from

  1. 2004

    The Butler Review

    UK inquiry into intelligence on Iraqi weapons of mass destruction, and reference 1 of the 2015 paper below.

  2. 2015

    Chismon and Ruks

    Threat Intelligence: Collecting, Analysing, Evaluating. MWR InfoSecurity with CERT-UK and CPNI. Source of strategic, operational, tactical and technical.

  3. Oct 2016

    NIST SP 800-150

    Guide to Cyber Threat Information Sharing. Defines cyber threat information and does not adopt the word intelligence.

  4. 2020

    ENISA takes the opposite view

    The EU agency publishes a Cyber Threat Intelligence Overview in its threat landscape series, using the term the US guidance avoids.

  5. 2026

    Where it has got to

    A market in which most products are information, sold under a word borrowed from a discipline that audits its own failures.

Four fixed points behind the terms used every day. The 2015 paper is the origin of the four-type model repeated on nearly every commercial page since, and it is rarely cited by them.

What analysis actually looks like, on one real case

Abstractions are cheap here, so this section walks one case end to end. On 18 August 2026 Microsoft Defender Experts published an analysis of MacSync Stealer, a macOS information stealer, extending earlier work by RST Cloud. The report links more than thirty domains by behaviour rather than by matching, and is explicit that the domain count is a by-product of the method rather than the finding.

That report is collection. The indicator table in it is processing. Neither is intelligence yet, and Microsoft would not claim otherwise.

Direction came first, though it is easy to skip past. The question was not what is MacSync Stealer, which the report already answers well. The question was whether the controls a typical organisation already runs would have caught this infrastructure, because that is the thing a reader can act on and the thing no vendor report can answer for them.

Analysis was querying every domain in that table against Verisign's RDAP service and looking at when each was registered.

The reasoning was ordinary, which is the point. If infrastructure is being rotated in response to disclosure, as the reporting describes, then replacement domains should be young: registered shortly before or during the campaign. That is a prediction, it is cheap to test, and registry data is public. Nothing here required access to the malware, a sandbox, or a commercial feed.

Terminal
$ curl -sL -H 'Accept: application/rdap+json' https://rdap.org/domain/lumenagnet.com
{"objectClassName":"domain","ldhName":"LUMENAGNET.COM",
"events":[{"eventAction":"registration","eventDate":"2025-09-26T14:02:11Z"},
{"eventAction":"expiration","eventDate":"2026-09-26T14:02:11Z"}]}

One of the 31 domains in Microsoft's indicator table, queried on 18 August 2026. Repeated across all 31 and counted with a script rather than by eye. RDAP is a passive registry lookup: it does not contact the malicious host.

31

Domains checked

Every entry in the published indicator table, not a sample.

1

Registrar, for all of them

A single registrar of record across the entire set.

0

Registered in 2026

The newest predates the report by 263 days. The oldest is October 2024.

14

Bought on two days

Eight on 26 September 2025 and six on 28 November 2025.

All 31 domains from Microsoft's published indicator table, queried against Verisign RDAP on 18 August 2026. Twenty-nine returned a registration date and two did not resolve, so the counts below are of the twenty-nine.

When the rotating infrastructure was actually registered

Oct 20242 domains
Nov 20241 domains
Aug 20251 domains
Sep 20258 domains
Oct 202510 domains
Nov 20257 domains
20260 domains
Registration month for the 29 domains that resolved, from Verisign RDAP on 18 August 2026. Nothing was registered in the eight months before the report. Two months carry half the estate, which is what buying in batches looks like from the registry.

The conclusion is one sentence and it is not in either vendor report: the domains were not registered as the campaign rotated, they were bought in batches up to a year in advance. Rotation and registration are different activities.

The prediction failed, and a failed prediction is usually where the finding is. Every domain predated the report by months. The operator was not registering infrastructure as the campaign burned through it. They were working through stock bought in advance, which is a different operation with different economics and a different detection profile.

That is intelligence rather than information, by the test set out at the top, because it changes a decision. Scoring or blocking newly registered domains is a widely deployed control, it is cheap, and against this campaign it is worth nothing, because every one of these domains had been sitting unused for months before it served anything.

One indicator, and what it does and does not tell you

dogtrainersgeorgia[.]comRegistered 28 November 2025Same registrar as the other 30Same purchase day as five othersAn innocuous small-business name
  1. 01dogtrainersgeorgia[.]com: The indicator itself. Blockable, and worthless the moment it is replaced.
  2. 02Registered 28 November 2025: Older than the campaign report by 263 days, so a domain-age control never fires.
  3. 03Same registrar as the other 30: A pivot available from DNS logs alone, with no endpoint telemetry required.
  4. 04Same purchase day as five others: One confirmed hit is a thread back to a batch, which is what makes this analysis rather than a list.
  5. 05An innocuous small-business name: Reads like a compromised third party and is not one. Registration places it in the same batch as the rest, so there is nobody to notify.
A single row from a published indicator list, read for everything it carries. The domain string is the part everyone uses and the least durable thing on the line.

Two honest limits belong with that finding. Registry data is point-in-time and a registrar of record can be a reseller, so this identifies a pattern rather than an owner, and none of it names a person. And two of the 31 domains did not resolve at all, so the counts describe twenty-nine. Stating both is not throat-clearing. An assessment that hides its own limits is exactly the failure mode the Butler Review was convened to examine.

That last part is the one that changes an incident response. A defender who sees a dog-training company in a malicious domain list reasonably assumes a small business got compromised and starts looking for someone to contact. There is no one. The name is cover, bought on the same day as five others.

The same case, mapped to the cycle

PhaseWhat it was hereInformation or intelligence
DirectionDoes this campaign touch our estate, and do our controls catch itNeither, it is a question
CollectionThe Microsoft and RST Cloud reports, both primaryInformation
ProcessingTheir table of 31 domains, parsed into a listInformation
AnalysisRDAP on all 31: one registrar, none from 2026, 14 on two daysIntelligence
DisseminationA published briefing naming the affected controlIntelligence, if it reaches someone who can act
FeedbackDid anyone actually stop scoring domains by ageThe phase that decides whether the rest counted
Phase by phase, with what each one actually consisted of. The point of laying it out this way is how much of it was already public before the analysis step, and how little of it was intelligence until then.

Try the analysis step yourself, in about ten minutes

The fastest way to understand the difference is to do the last column once. Nothing here needs a licence, a platform or a login.

Take any published indicator list, from any vendor report you can find. Pick the domains out of it. For each one, ask a public registry when it was registered, which is a single command and costs nothing:

Terminal
$ curl -sL https://rdap.org/domain/example.com | python3 -m json.tool | grep -A1 registration

RDAP is the structured successor to WHOIS. This is a passive registry lookup and nothing contacts the domain itself. example.com is used here because it is reserved for documentation and is always safe to query.

Now ask one question of the answers: is this pattern what I expected? If every domain in a supposedly fast-rotating campaign turns out to be older than the campaign, you have found something the report did not say. If they are all a week old, you have confirmed the report and learned that domain-age scoring would help you here.

Either answer is intelligence, because either one changes what you would do. That is the entire step, and the only expensive part is being willing to look.

Where this sits next to the SOC

A common and reasonable confusion is where threat intelligence ends and the security operations centre begins, because both look at attacker activity and both produce written output.

The difference is the direction of the question. A SOC starts from something that happened in your estate and works outward: this alert fired, what is it, does it matter. Threat intelligence starts from something happening in the world and works inward: this campaign exists, does it reach us, and would we notice. Threat hunting sits between them, starting from a hypothesis about what might already be present and looking for evidence either way.

They feed each other in both directions, and a programme that runs one without the others tends to fail in a predictable way. Intelligence with no SOC produces assessments nobody can action. A SOC with no intelligence is permanently reactive, because every alert is triaged on its own merits with no view of what is currently being done to organisations like yours. Hunting without intelligence is a search with no priority ordering, which in a large estate is indistinguishable from luck.

What to ask anyone selling you intelligence

The market's structural problem is that the first three phases are easy to sell and the fourth is expensive to staff.

What a feed subscription delivers, and where it stops

  1. Direction, collection, processingFeed subscription
  2. Matching, at volumeYour SIEM or EDR
  3. Some true, most notAlerts
  4. Analysis, and the part nobody sold youA person deciding what it means
Not an argument against buying feeds. It is an argument against believing the invoice describes the whole cycle. Everything after the third box needs a person, and that person is the product.

Take this with you

Questions that separate the two, and none of them is technical

  • Ask what decision the last report changed. Not what it covered, what changed. A vendor with a good answer will have one ready and a vendor without one will describe their collection.
  • Ask how the product accounts for your estate. If nothing in it would differ for a competitor in your sector, it is information, which may be exactly what you need and should be priced accordingly.
  • Ask how uncertainty is expressed. Analysis that never says probably, or never says we could not verify this, is either extraordinary or is not analysis. The Butler Review is largely about this.
  • Ask who receives it and whether they can act. Intelligence delivered to a mailbox nobody owns has failed at dissemination regardless of quality.
  • Ask what happens at feedback. Almost nobody has a good answer, and asking the question tells you more about the programme than any sample report will.

Starting without a budget

Everything above is achievable with no platform and no subscription, and the worked example in this guide was done that way deliberately to prove it.

The three things that actually gate a useful programme are a named question, a place to write the answer down, and somebody who will read it. Registry lookups are free. Vendor reports are free. Your own logs are the highest-value collection source you have and you already own them, because they are the only source that knows your estate. What a platform buys is scale and speed in the phases that were never the bottleneck.

If you are starting from nothing, the honest first move is not to buy a feed. It is to write down the last three security decisions your organisation made and ask what information would have made each of them better. That list is your collection requirement, and it will be shorter and stranger than any vendor's coverage map.

The position

Most of what is sold as cyber threat intelligence is cyber threat information, and NIST has been quietly using the more accurate word since 2016.

That is not a reason to buy less of it. Information is the input and the pipeline does not run without it. It is a reason to be precise about what has been bought, because a programme that mistakes the input for the output will keep paying for collection and wonder why nothing changes.

None of this is an argument for cynicism about the vendors. The MacSync analysis this guide leans on is careful work, states its own method, and explicitly declines to lead with the number that would have made the better headline. The gap that mattered was not a mistake in it. The gap was that an indicator table is not an analysis and was never presented as one, and the reader who wanted a decision had to do the last step themselves.

That last step is the job. It is also the only part of this that cannot be outsourced, bought as a subscription, or automated by the current generation of tooling, which makes it the part worth building a team around.

The test survives every vendor conversation and every internal review: name the decision that changed. If nobody can, then whatever else was produced, it was not intelligence. The discipline this one borrowed its name from learned that lesson expensively enough to hold a public inquiry into it, and the paper that gave this field its vocabulary put that inquiry first in its bibliography.

Common questions

What is the difference between threat data, threat information and threat intelligence?

Data is raw observations such as a list of addresses. Information is data with context, which is what NIST SP 800-150 defines and what most commercial feeds sell. Intelligence is information that has been analysed for a specific consumer and that changes a decision. The boundary that matters commercially is the second one, because products either side of it are priced similarly and are not comparable.

What are the four types of cyber threat intelligence?

Strategic, operational, tactical and technical. They come from Threat Intelligence: Collecting, Analysing, Evaluating by Chismon and Ruks, published in 2015 by MWR InfoSecurity with CERT-UK and CPNI. The model divides intelligence by who consumes it rather than by a hierarchy of value, which is a distinction lost in most later summaries that redraw it as a pyramid.

Does NIST define cyber threat intelligence?

Not as a term of art. NIST SP 800-150, Guide to Cyber Threat Information Sharing, October 2016, defines cyber threat information as any information that can help an organisation identify, assess, monitor and respond to cyber threats. The publication is about information sharing throughout and does not adopt intelligence as its subject.

Do we need a threat intelligence platform to start?

No. A platform helps with collection and processing, which are the phases you can already buy. The step that produces intelligence is somebody forming an assessment, and the worked example in this guide was done with a public indicator list and passive registry queries. Start by naming a decision you want to make better, then find the smallest thing that informs it.

How do we know whether our threat intelligence is any good?

Ask what it last changed. A programme that can point to a control that was altered, a hunt that was prioritised, or a purchase that was cancelled because of an assessment is producing intelligence. One that reports volumes collected and reports published is measuring its own activity, which is the failure the feedback phase of the cycle exists to catch.

Where to go next

Share this guide

Useful to someone learning this? Pass it on.

← All guides