Entering the Cyber Battlespace
Digital Systems as Mission Terrain Evidence, Threat Intelligence, and Incident Response Authorization, Ethics, and Safe Practice What Cyberwarfare Is—and Is Not Cyberspace as an Operational Environment
The Road to Persistent Cyber Conflict
Estonia, Georgia, Stuxnet, and the First Shock Ukraine, 2015–2026: Campaigning Under Fire
Actors, Proxies, and Strategic Behavior
The State Cyber Ecosystem Strategic Cultures Without Stereotypes
Law, Authority, and Civilian Protection
Below Armed Conflict: Sovereignty, Intervention, Force, and Responsibility Armed Conflict: IHL and Cyber Effects
Intelligence, Indications, and Attribution
Intelligence Support to Cyber Operations Attribution Under Deception
Campaign Design and Command
From Policy Aim to Cyber Campaign Command, Authorities, and Deconfliction
Target Systems, Access, and Operational Security
Target-System Analysis and Cyber Key Terrain Access Stewardship, Capability Fit, and OPSEC
Effects Engineering and Campaign Assessment
Designing and Bounding Cyber Effects Measuring What the Campaign Changed
Critical Infrastructure and Cross-Domain Operations
Operational Technology, Safety, and Restoration Space, Telecommunications, and Multi-Domain Integration
Influence, Perception, and Public Truth
Cyber-Enabled Influence Operations Defending Truth, Trust, and Decision Space
Daily Defence in Competition and War
Mission Assurance and the Wartime Operations Floor Continuity, Recovery, and Collective Defence
Deterrence, Emerging Change, and the Final Campaign
Deterrence, Norms, and Collective Response The 2026 Horizon: AI, Supply Chains, Edge, and Identity Capstone: Build, Challenge, and Defend a Cyber Campaign
Intelligence, Indications, and Attribution

Intelligence Support to Cyber Operations

Convert commander questions into collection that supports access, effects, protection, assessment, and warning.

About this learning content: Courses, lessons, assessments, explanations and illustrations may be created with the help of artificial intelligence. We review and check the material and do our best to avoid incorrect or outdated information, but mistakes, omissions or ambiguous questions may remain. Please verify information before relying on it for professional, security, legal or operational decisions. Read the full notice or report an issue.

In this lesson, you will learn to:

  • Write prioritized intelligence requirements and a collection matrix for a notional campaign decision.

Intelligence Support to Cyber Operations

This lesson connects the intelligence cycle to operational tempo. Learners create decision-linked requirements and balance target understanding with counterintelligence and intelligence-gain-or-loss concerns.

Build requirements around decisions

Begin with a decision and deadline: whether to protect an access, change posture, approve an effect, warn a partner, or attribute publicly. Turn it into a question whose answer could change the choice. “Monitor Sandworm” is a topic; “Will this access enable disruption of regional electricity restoration during the next 30 days?” is a decision-linked requirement.

Decompose the requirement using the cyber strategic warning and intelligence-requirements workflow: define indicators, observables, sources, owners, update cadence, and thresholds. Collect across technical telemetry, malware analysis, infrastructure, vulnerabilities, identity, organizational behavior, geopolitical events, public messaging, partner reporting, and target-system knowledge. Grade source reliability separately from information credibility. Record alternative explanations and what would disconfirm the leading judgment.

Intelligence supports more than targeting. It estimates civilian dependencies, partner equities, recovery behavior, adversary adaptation, probability of attribution, blowback, and post-operation effect. The declassified Operation Glowing Symphony material shows collection management, intelligence gain/loss, political-military assessment, collateral-effects estimation, legal review, and measures of effectiveness intertwined with offensive planning.

Manage intelligence gain, loss, and counterintelligence

Acting can reveal collection, burn access, teach the adversary, expose a partner, or disclose what is known. Waiting can allow harm. Create an intelligence gain/loss assessment for every consequential action: information gained through execution, information lost through disclosure or changed behavior, sources at risk, recovery opportunities, and future access cost.

Use staged decisions. Preserve passive observation where it answers a higher-priority requirement; take protective action when mission or civilian risk crosses an agreed threshold; share enough with a partner to reduce harm while protecting sensitive provenance. Maintain strict handling for operational data and avoid contaminating intelligence with assumptions from planning. After action, compare predicted adversary reaction with observed adaptation and update collection.

Resources