Executive Summary
Most security operations are reactive: an alert fires, an analyst responds. Cyber Threat Intelligence (CTI) inverts that posture. Done well, it lets an organization understand which adversaries are likely to target it, how they operate, and what to defend first — turning security from a series of responses into a directed strategy.
This whitepaper defines what threat intelligence actually is (and is not), and describes how to build a CTI program that produces decisions, not just data feeds. It draws on the intelligence lifecycle, the MITRE ATT&CK framework, the Diamond Model of intrusion analysis, and structured sharing standards like STIX/TAXII.
A threat feed is not threat intelligence. Intelligence is analyzed, contextualized, and actionable — it answers a specific question a decision-maker is asking. Raw indicators are just data until someone turns them into a decision.
Key findings of this paper:
- Threat intelligence spans three levels — strategic, operational, and tactical — and each serves a different audience, from the board to the SOC analyst.
- Value comes from relevance and context, not volume; a flood of unfiltered indicators creates noise, not insight.
- The intelligence must drive action — feeding detection, hunting, patching priorities, and risk decisions — or it is merely interesting.
- Frameworks like ATT&CK and the Diamond Model turn scattered observations into a coherent understanding of adversary behaviour.
What Threat Intelligence Is — and Is Not
The term is heavily marketed and widely misunderstood. Clarity about what intelligence actually is prevents a program from becoming an expensive subscription to noise.
Data, information, intelligence
There is a deliberate hierarchy:
- Data is raw and unprocessed — a list of IP addresses, file hashes, or domains.
- Information is data with some structure — a report that these hashes are associated with malware.
- Intelligence is information that has been analyzed and contextualized to answer a specific question and support a decision.
Most commercial 'threat intelligence' feeds deliver data or information. The analysis that turns them into intelligence is the hard, valuable part.
Actionable and relevant
Good intelligence is relevant to your organization, timely enough to act on, and clear about what should be done. Intelligence about threats to a sector you do not operate in, or delivered too late to matter, has little value however accurate it is.
The intelligence requirements
Everything begins with intelligence requirements — the specific questions your stakeholders need answered. Without them, a program collects everything and informs nothing.
Before subscribing to a single feed, ask: what decisions are we trying to inform? A CTI program that cannot name its intelligence requirements will drown in data and starve for insight.
The Three Levels of Threat Intelligence
Intelligence serves different audiences at different altitudes. Confusing the levels — handing a board member a list of IP indicators, or an analyst a geopolitical essay — wastes the work.
Strategic intelligence
Strategic intelligence informs leadership and risk decisions. It addresses the big picture: which threat actors target our industry, how the threat landscape is shifting, and what that means for security investment. It is non-technical, trend-focused, and consumed by executives and the board.
Operational intelligence
Operational intelligence describes specific campaigns and adversary tradecraft — the tactics, techniques, and procedures (TTPs) of the groups likely to target you. It informs how the security team prepares defenses and where to focus hunting. MITRE ATT&CK is the common language at this level.
Tactical intelligence
Tactical intelligence is the technical detail: indicators of compromise, malicious infrastructure, and signatures that feed directly into detection tools. It is the most perishable — indicators change quickly — but the most immediately operational.
Connecting the levels
- Strategic shapes what we invest in.
- Operational shapes what we prepare for.
- Tactical shapes what we detect and block today.
A mature program produces all three and routes each to the right audience. GuardsArm helps clients translate operational intelligence into concrete detection and hunting priorities.
The Intelligence Lifecycle
Producing intelligence is a repeatable process, adapted from established intelligence practice. Skipping stages is the most common reason CTI programs fail to deliver value.
Direction
Everything starts with requirements: what questions must the intelligence answer, and for whom? This stage sets priorities and prevents aimless collection.
Collection
Gather raw data from relevant sources — commercial feeds, open-source intelligence, information-sharing communities (ISACs), dark-web monitoring, and internal telemetry. The best collection is targeted at the requirements, not indiscriminate.
Processing and analysis
Raw collection is normalized, correlated, and — critically — analyzed by people. This is where structured analytic techniques and frameworks like the Diamond Model (adversary, capability, infrastructure, victim) turn observations into understanding of who is doing what and why.
Dissemination and feedback
Finished intelligence is delivered to each stakeholder in a form they can act on, and their feedback refines the next cycle's requirements.
The lifecycle is a loop, not a line. The feedback stage is where a program learns whether its intelligence actually informed decisions — and most organizations neglect it entirely, producing reports no one reads.
From Intelligence to Action
Intelligence that does not change behaviour is a cost, not a capability. The measure of a CTI program is the decisions and actions it drives.
Feeding detection and hunting
Operational and tactical intelligence should flow directly into the security stack: enriching SIEM correlation rules, seeding EDR detections, and providing hypotheses for threat hunts. Knowing that a particular adversary favours a specific technique tells the SOC exactly what to hunt for.
Prioritizing defense
Intelligence about which threats are most relevant lets an organization prioritize scarce resources — which vulnerabilities to patch first based on active exploitation, which controls to strengthen, which attack surfaces to harden. This is intelligence-driven vulnerability management: fixing what attackers are actually using, not just what scores highest in the abstract.
Informing risk decisions
Strategic intelligence shapes executive decisions about security investment, cyber insurance, and acceptable risk. When leadership understands the specific threats facing the business, security spending becomes a targeted decision rather than a guess.
Enriching incident response
During an incident, intelligence about the likely adversary — their known TTPs and objectives — accelerates scoping and response. Knowing who you are likely dealing with tells you where else to look.
Every piece of intelligence should have a consumer and an action. If you cannot name who will use a report and what they will do with it, you are collecting data, not producing intelligence.
Sharing, Standards, and Building the Program
Threat intelligence is a collective endeavour. Adversaries reuse infrastructure and techniques across many targets, so what one organization sees can protect many others.
The case for sharing
Information-sharing communities — sector ISACs, government partnerships, and trusted peer groups — multiply everyone's visibility. An indicator seen at one member becomes a detection at all of them. Contributing, not just consuming, strengthens the whole community.
Standards that make sharing work
- STIX (Structured Threat Information eXpression) provides a common language to describe threats.
- TAXII provides the transport to exchange them automatically.
- MITRE ATT&CK gives shared vocabulary for adversary behaviour, so a technique described by one team is understood by all.
These standards let intelligence flow between organizations and tools without manual reformatting.
Building the program pragmatically
- Start with requirements, not feeds. Define the questions before buying sources.
- Right-size the sources. A few relevant, high-quality sources beat many noisy ones.
- Invest in analysis. Tools collect; people produce intelligence.
- Integrate, don't isolate. Wire intelligence into detection, hunting, patching, and risk processes.
- Measure impact. Track how often intelligence changed a decision or drove an action.
Many organizations lack the staff to run a full CTI function in-house. GuardsArm delivers threat intelligence as a managed capability — collecting, analyzing, and translating it into the detection and response priorities that fit each client's actual threat exposure.
Key Takeaways
- 1.Threat intelligence is analyzed, contextual, and actionable — a raw feed of indicators is data, not intelligence.
- 2.Serve all three levels: strategic for leadership, operational for the security team, tactical for detection tools.
- 3.Run the full intelligence lifecycle, and don't skip the feedback stage that proves whether intelligence drove decisions.
- 4.Every report needs a named consumer and an action — feeding detection, hunting, patch prioritization, or risk decisions.
- 5.Adopt STIX/TAXII and ATT&CK and participate in sharing communities so collective visibility strengthens everyone's defense.
Sources & Further Reading
- MITRE ATT&CK Framework
- The Diamond Model of Intrusion Analysis
- OASIS STIX/TAXII Standards for Threat Intelligence Sharing
- CISA Automated Indicator Sharing (AIS) and ISAC guidance
- Verizon Data Breach Investigations Report (annual)