Article

Where threat intelligence planning breaks down

Six places the chain from mission to action gives way. How to find which one is yours, using one business activity and about twenty minutes.

Cyber threat intelligence should help somebody decide what to protect, what to investigate, or what to change. When it does not, the reason is almost never that the analysis was bad. It is that the chain from the mission to the action has a break in it, and the break is usually somewhere nobody is looking.

There are six links. Working out which one is yours is a twenty-minute conversation, not a project, and it is worth doing before buying anything.

Pick one activity first

Not the organization. One service, team, or business process: customer payments, product development, online service delivery. Assessing everything at once produces averages, and averages hide exactly the thing you are looking for.

Name the business outcome that has to be protected for that activity, and keep it in view throughout. A business owner and a security professional doing this together will get further than either alone, because the break is often at the seam between what the business knows and what security knows.

Rate on evidence, not on intent

For each link, the useful question is not whether you do this but whether you can show a current example. Absent, partial, demonstrated. And a fourth answer that matters more than it looks: unknown.

A tool, a policy, or a subscription is not evidence that a practice works. This is the single most common way an assessment like this comes out flattering and useless. Owning a threat intelligence platform is not evidence that questions are being written; it is evidence that a platform was bought.

Unknown is a real answer and should be used. It means you cannot establish what is happening yet, which is different from knowing it is absent, and it resolves by assigning a person to find out rather than by guessing.

The six links

Mission and decisions. Can you explain the business outcome at stake, and what disruption, theft, or manipulation would mean for it? Can you name a decision that threat intelligence should support, the person making it, and when they need the answer?

Mission environment. Do you know which people, systems, data, and outside providers the activity depends on? Have you identified the access paths, dependencies, and constraints that affect how you protect it?

Relevant threats. Can you describe a plausible scenario for this activity, including how an adversary would cause harm? Can you explain why it deserves attention here, with evidence, and say what you are assuming?

Intelligence requirements. Have you turned the most important uncertainty into a specific question tied to that decision? Have you prioritized it and said what an adequate answer must establish, and by when?

Collection and analysis. Do you know which sources could answer it, who will obtain the information, and what gaps remain? Do you evaluate source reliability, separate fact from assumption, and state your confidence?

Action and feedback. Do findings arrive in time, in language the decision maker can use, with implications and workable options? Do you record the decision that resulted, and let it change the next question?

Do not add it up

The temptation is to total the ratings into a score. Resist it, because a total is exactly the thing that hides the break.

A strong practice in one area does not cancel a missing decision owner or an unanswered critical question. A program that collects and analyzes superbly but has nobody who owns the decision is not average. It is broken in a specific place, and the excellent collection is what makes that hard to see from the outside.

This is a structured planning conversation, not an audit and not a maturity score. It describes planning practice. It does not measure the likelihood of a breach, and reading it as though it does will produce the wrong next step.

Read the pattern instead

  • Any unknown. Establish what is actually happening before judging the practice. Name someone who can confirm it.
  • Any absent. A practice is missing. Work out what that does to the decision you named.
  • Mostly partial. The work happens but not reliably. Make it repeatable: an owner, an output, a review date.
  • Mostly demonstrated. Test whether the evidence still holds when the business or the threat environment changes.

Then pick one priority. Look at the first link first: if the business outcome or the decision is unclear, fix that before expanding collection, because everything downstream inherits the ambiguity. Otherwise take the gap most likely to leave the decision maker without a useful answer by their deadline, and break ties on business impact and urgency.

What this looks like in practice

A twenty-five person services firm takes supplier bank-detail changes by email. The finance manager has to decide this month whether to require an independent callback before any payment details change.

The assessment finds the team can describe the fraud scenario perfectly well. They know how supplier impersonation works. But the requirements link comes out absent: nobody has written the question they actually need answered.

So they write it. How could supplier impersonation bypass our payment-change process, and would an independent callback interrupt the plausible paths? The security lead and the finance manager compare relevant supplier-impersonation reporting against their own process and their recent requests, identify the plausible paths, the checks already in place, and what they still cannot see. Then they brief the decision maker on whether a callback would help and what exposure would remain.

Nothing exotic happened there. The gap was one link, the fix was a written question, and the firm bought nothing.

One caution before you act

Do not delay a protective action you already know is necessary while you wait for more intelligence. If the callback is obviously worth doing, do it. Intelligence planning is for the decisions that are genuinely uncertain, and using it to defer the ones that are not is a way of looking rigorous while nothing improves.

The output of a pass like this should be small and specific: one gap that matters, one question worth answering, and a next step with somebody's name on it and a date to check whether it helped.

The self-assessment behind this

The CTI Planning Self-Assessment runs all twelve statements with evidence prompts, the pattern guide, and a page for turning your priority gap into a next step. It comes with the MATATC and intelligence requirements worksheets, a process map, and a worked example, free in the Cyber Threat Intelligence Starter Kit.

Drawn from the CTI Planning Self-Assessment by Christopher G. Ruel and Ajay Menendez, authors of Cyber Threat Intelligence Planning: A Special Forces Approach. The services firm is illustrative.