First Edition · Coming Soon

Cyber Threat Intelligence Planning

A Special Forces Approach

Turn threat data into decisions.

Cybersecurity teams have access to more threat information than ever before. The challenge is not finding more data. The challenge is knowing what actually matters, and what anyone is supposed to do about it.

Four practical resources, free, based on the methodology in the book.

Cover of Cyber Threat Intelligence Planning by Christopher G. Ruel and Ajay Menendez

The Problem

More data has not made cybersecurity risk and operational decisions any easier.

Every threat intelligence program reaches the same five questions, and no feed answers them for you:

  • What information actually matters
  • What questions need to be answered
  • What should be collected
  • How that information should be analyzed
  • How intelligence should support organizational decisions

Cyber Threat Intelligence Planning presents a practical methodology for planning, collecting, analyzing, and communicating cyber threat intelligence in a way that connects intelligence activities to organizational requirements, risk, and decision-making.

Whether you are building a threat intelligence capability, working in a SOC, supporting cybersecurity operations, managing risk, or learning how professional intelligence programs operate, the book is written to move past collecting indicators, alerts, and threat feeds.

Ninety Seconds

What the book does, and who it is for.

The Starter Kit

Four practical resources, free.

Each one is drawn from the methodology presented in the book, and each one works on its own.

01

Cyber Mission Analysis Process Map

A visual overview of the process for connecting organizational missions, intelligence requirements, collection, analysis, and decision support.

02

Intelligence Requirements Worksheet

A practical tool for developing and organizing the intelligence requirements that guide collection and analysis.

03

MATATC Worksheet

A structured worksheet for applying the MATATC methodology and working through the factors that shape a cyber threat intelligence problem.

04

Worked ACME Example

A completed example showing how the methodology is applied to a fictional organization and translated from business concerns into actionable intelligence requirements.

The Approach

Intelligence should begin with a question, not a feed.

Many threat intelligence programs begin by collecting data. Threat feeds. Indicators. Vulnerabilities. Reports. Malware. News. Alerts. More information does not automatically produce better intelligence.

Effective intelligence begins by understanding

What does the organization need to know?

Then

Why does it need to know it?

And finally

What decision will the intelligence help someone make?

The objective is not to produce more threat intelligence. The objective is to produce intelligence that matters.

From Need to Intelligence

A structured route from what the business cares about to what someone does next.

Organizational concerns

What does the organization need to accomplish, protect, understand, or decide?

Intelligence requirements

What questions need to be answered to support those objectives?

Collection

What information is needed, and where can it be obtained?

Analysis

What does the collected information tell us?

Assessment

What does it mean against the organization's mission, threats, vulnerabilities, and risk?

Decision support

What should a leader, analyst, defender, or other stakeholder do with the intelligence?

This treats cyber threat intelligence as an organizational capability rather than another security product or a collection of threat feeds.

What You Can Build With It

A repeatable process, not a reading list.

Cyber Threat Intelligence Planning brings together cybersecurity, intelligence analysis, risk management, threat intelligence, and operational planning. The emphasis throughout is practical application.

  • Understanding organizational intelligence needs
  • Developing meaningful intelligence requirements
  • Planning intelligence collection
  • Identifying relevant information sources
  • Organizing and analyzing collected information
  • Assessing threats in organizational context
  • Communicating intelligence clearly
  • Supporting operational and strategic decisions

Who It Is For

People who have to turn information into a decision.

  • Cyber threat intelligence analysts
  • SOC analysts
  • Security operations professionals
  • Incident responders
  • Cybersecurity managers and leaders
  • Risk and governance professionals
  • Security architects
  • Threat hunters
  • Intelligence professionals entering cybersecurity
  • Students and educators
  • Organizations building a CTI capability

You do not need to sit on a dedicated threat intelligence team to use the methodology. If your role asks you to understand threats, prioritize information, assess adversaries, communicate risk, or hand something to the person making a cybersecurity decision, it applies.

Before the Release

Get the Free Cyber Threat Intelligence Starter Kit

Four practical resources now, and word from us when the book is available, where to buy it, and what ships alongside it.