How a security question becomes a decision
A suspicious payroll email, from the first help-desk report to the password reset. No prior intelligence training needed to follow it.
Articles
Short pieces on planning cyber threat intelligence, each drawn from the methodology in Cyber Threat Intelligence Planning and from the worksheets in the free Starter Kit.
A suspicious payroll email, from the first help-desk report to the password reset. No prior intelligence training needed to follow it.
Start at the decision, not the question. The five requirement types, the three tests, and why threshold and trigger get written first.
Mission, adversary, terrain, assets, time, customer — six sentences that come before any threat evaluation, and the error each prevents.
What each stage produces, why entering at collection planning fails, and the two restart conditions everyone forgets.
Six links, one business activity, twenty minutes. Why a total score hides the break, and what a useful output looks like.
The Worksheets
The worksheets these articles work from: a mission environment worksheet, an intelligence requirements worksheet, a one-page process map, and a worked example.