Cyber Mission Analysis Process Map
A visual overview of the process for connecting organizational missions, intelligence requirements, collection, analysis, and decision support.
First Edition · Coming Soon
A Special Forces Approach
Turn threat data into decisions.
Cybersecurity teams have access to more threat information than ever before. The challenge is not finding more data. The challenge is knowing what actually matters, and what anyone is supposed to do about it.
Four practical resources, free, based on the methodology in the book.
The Problem
Every threat intelligence program reaches the same five questions, and no feed answers them for you:
Cyber Threat Intelligence Planning presents a practical methodology for planning, collecting, analyzing, and communicating cyber threat intelligence in a way that connects intelligence activities to organizational requirements, risk, and decision-making.
Whether you are building a threat intelligence capability, working in a SOC, supporting cybersecurity operations, managing risk, or learning how professional intelligence programs operate, the book is written to move past collecting indicators, alerts, and threat feeds.
Ninety Seconds
The Starter Kit
Each one is drawn from the methodology presented in the book, and each one works on its own.
A visual overview of the process for connecting organizational missions, intelligence requirements, collection, analysis, and decision support.
A practical tool for developing and organizing the intelligence requirements that guide collection and analysis.
A structured worksheet for applying the MATATC methodology and working through the factors that shape a cyber threat intelligence problem.
A completed example showing how the methodology is applied to a fictional organization and translated from business concerns into actionable intelligence requirements.
The Approach
Many threat intelligence programs begin by collecting data. Threat feeds. Indicators. Vulnerabilities. Reports. Malware. News. Alerts. More information does not automatically produce better intelligence.
Effective intelligence begins by understanding
What does the organization need to know?
Then
Why does it need to know it?
And finally
What decision will the intelligence help someone make?
The objective is not to produce more threat intelligence. The objective is to produce intelligence that matters.
From Need to Intelligence
What does the organization need to accomplish, protect, understand, or decide?
What questions need to be answered to support those objectives?
What information is needed, and where can it be obtained?
What does the collected information tell us?
What does it mean against the organization's mission, threats, vulnerabilities, and risk?
What should a leader, analyst, defender, or other stakeholder do with the intelligence?
This treats cyber threat intelligence as an organizational capability rather than another security product or a collection of threat feeds.
What You Can Build With It
Cyber Threat Intelligence Planning brings together cybersecurity, intelligence analysis, risk management, threat intelligence, and operational planning. The emphasis throughout is practical application.
Who It Is For
You do not need to sit on a dedicated threat intelligence team to use the methodology. If your role asks you to understand threats, prioritize information, assess adversaries, communicate risk, or hand something to the person making a cybersecurity decision, it applies.
Before the Release
Four practical resources now, and word from us when the book is available, where to buy it, and what ships alongside it.