Threat intelligence, explained through the people who do it
Threat intelligence is the practice of studying attackers closely enough to act before they reach you.
Picture an analyst at the end of a long shift, reading through a feed of alerts that nobody else has time to open. Most of it is noise. Then one line catches her eye: a domain registered three hours ago, spelled almost like her employer's, hosting a login page that is almost convincing. She traces the registrant, links it to a phishing kit seen elsewhere that week, and writes two sentences for the response team before she logs off. That is threat intelligence. Not the report, not the platform, but the judgement of a person who connected a small signal to a real risk.
The phrase sounds like software, and plenty of vendors are happy to let it. The work itself is human. Someone has to decide what matters, what it means, and what the people defending an organisation should do about it tonight.
What the analysts actually do all day
The job has a rhythm to it. Analysts gather raw observations from many sources at once: malware samples, network logs, phishing reports, posts on criminal forums, and the patterns visible across thousands of other victims. None of it arrives sorted. The first task is separating the rare meaningful event from the enormous volume of ordinary traffic.
From there the work becomes interpretation. An analyst asks who is likely behind an attack, what they appear to want, and whether their behaviour matches a group seen before. This is where experience shows. A junior analyst sees an indicator. A seasoned one sees a habit, recognises the tooling, and predicts the next move. The Verizon Data Breach Investigations Report has documented for years how often the same techniques recur, stolen credentials and unpatched software chief among them, which is exactly why pattern recognition pays off.
The day usually ends in writing. A finding that stays in an analyst's head helps nobody. The deliverable is a clear note that a tired engineer can read at speed and act on without a second meeting. The craft of the trade is as much about plain English as it is about technical depth, because intelligence that the reader cannot use is simply research that nobody asked for.
The three altitudes of the work
Practitioners tend to describe their output at three levels, and each one belongs to a different reader.
Strategic intelligence is for the boardroom. It explains which threats matter to a particular organisation over the coming year and why, in language a director can use to set budget. The annual assessments from ENISA and the NCSC sit at this altitude, mapping how attacker behaviour is shifting across whole sectors.
Operational intelligence sits in the middle. It describes a specific campaign or group: the infrastructure they use, the order in which they tend to act, the warning signs that they have arrived. A SOC manager uses it to decide where to point the team.
Tactical intelligence is the close detail, the indicators and techniques that a defender feeds straight into tooling. It is the most perishable layer, because an attacker can change a domain or a hash overnight. Each level depends on the people producing the one beneath it, and the credit usually flows in the wrong direction. The strategist gets quoted. The analyst who found the first indicator rarely does.
Why the human judgement cannot be automated away
Automation has changed the volume of this work enormously. Feeds now enrich indicators, flag duplicates, and surface anomalies at a scale no person could match. That is genuine progress, and analysts welcome it, because it clears the routine and leaves the hard part.
The hard part resists automation. Deciding whether a cluster of weak signals adds up to a real campaign is a judgement call. So is weighing how confident you are, and saying so plainly, because intelligence delivered with false certainty does more harm than none at all. An analyst who writes "we assess with moderate confidence" is doing something a model still struggles with: owning the limits of what the evidence supports.
There is also the matter of relevance. A finding that is true but irrelevant to your organisation is a distraction. Knowing which threats apply to a particular hospital, bank, or council requires understanding that organisation, and that understanding lives in a person who has spent time inside it. A tool can tell you a vulnerability exists. Only someone who knows your systems can tell you whether it sits behind three other controls or one careless click away from your most sensitive data.
How the field tells good intelligence from noise
Ask any experienced analyst how they judge their own work and three tests come up.
The first is timeliness. Intelligence that arrives after the decision has been made is history, not intelligence. The value sits in the window before an attacker succeeds.
The second is specificity. "Phishing is rising" helps nobody. "This group is impersonating your finance team using these three domains" lets someone act. The closer a finding gets to a named action, the more it is worth.
The third is honesty about confidence. The best practitioners are precise about what they know, what they suspect, and what they are guessing. That discipline is what separates intelligence a defender can stake a decision on from a feed they learn to ignore.
Why the people behind it deserve naming
Threat intelligence has a recognition problem built into its nature. When the work succeeds, nothing happens. The phishing campaign is blocked before anyone clicks. The intrusion is spotted while it is still a foothold. There is no incident to report, and so there is no story, and so the analyst who saw it coming goes unmentioned in the very week she did her best work.
This is the same standard we apply when we read a nomination. We look for the specific thing a person did, the evidence behind it, and whether it held up under pressure. An analyst who shortened the time an attacker spent inside a network, or who called a campaign early and was right, has done something measurable, even when the absence of a breach makes it invisible to everyone else.
The market rewards what it can see, and quiet defence is hard to see. Naming the people who do this work, on merit and against published criteria, is one of the few ways the field corrects for that.
So when someone asks what threat intelligence is, the honest answer points past the dashboards and the feeds to the analyst at the end of a shift, reading one more line. The tooling will keep improving, and it should. The volume it handles will keep rising, and that is welcome. What stays constant is the judgement at the centre: a person deciding what a signal means, how sure they are, and what the people defending an organisation should do tonight. That judgement is the whole of the work, and it deserves to be seen.
Threat intelligence
What is the difference between threat intelligence and threat data?
Threat data is the raw material: indicators, logs, and samples with no context. Threat intelligence is what an analyst produces after interpreting that data, answering who is attacking, how, and what a defender should do about it.
Who produces threat intelligence?
In-house analysts produce tactical and operational intelligence for their own organisation. National bodies such as the UK NCSC and the EU agency ENISA publish broader strategic assessments of the threat landscape for whole sectors.
Can threat intelligence be fully automated?
No. Automation handles volume well, enriching and de-duplicating signals at scale, but deciding whether weak signals add up to a real campaign, judging confidence, and knowing what matters to a specific organisation still depend on human analysts.
How do you know if threat intelligence is any good?
Three tests apply: is it timely enough to act on, is it specific enough to point to a clear action, and is it honest about how confident the analyst is. Findings that fail any of these tend to be ignored.