Intelligence Support to Cyber Operations
Convert commander questions into collection that supports access, effects, protection, assessment, and warning.
In this lesson, you will learn to:
- Write prioritized intelligence requirements and a collection matrix for a notional campaign decision.
Intelligence Support to Cyber Operations
This lesson connects the intelligence cycle to operational tempo. Learners create decision-linked requirements and balance target understanding with counterintelligence and intelligence-gain-or-loss concerns.
Build requirements around decisions
Begin with a decision and deadline: whether to protect an access, change posture, approve an effect, warn a partner, or attribute publicly. Turn it into a question whose answer could change the choice. “Monitor Sandworm” is a topic; “Will this access enable disruption of regional electricity restoration during the next 30 days?” is a decision-linked requirement.
Decompose the requirement using the cyber strategic warning and intelligence-requirements workflow: define indicators, observables, sources, owners, update cadence, and thresholds. Collect across technical telemetry, malware analysis, infrastructure, vulnerabilities, identity, organizational behavior, geopolitical events, public messaging, partner reporting, and target-system knowledge. Grade source reliability separately from information credibility. Record alternative explanations and what would disconfirm the leading judgment.
Intelligence supports more than targeting. It estimates civilian dependencies, partner equities, recovery behavior, adversary adaptation, probability of attribution, blowback, and post-operation effect. The declassified Operation Glowing Symphony material shows collection management, intelligence gain/loss, political-military assessment, collateral-effects estimation, legal review, and measures of effectiveness intertwined with offensive planning.
Manage intelligence gain, loss, and counterintelligence
Acting can reveal collection, burn access, teach the adversary, expose a partner, or disclose what is known. Waiting can allow harm. Create an intelligence gain/loss assessment for every consequential action: information gained through execution, information lost through disclosure or changed behavior, sources at risk, recovery opportunities, and future access cost.
Use staged decisions. Preserve passive observation where it answers a higher-priority requirement; take protective action when mission or civilian risk crosses an agreed threshold; share enough with a partner to reduce harm while protecting sensitive provenance. Maintain strict handling for operational data and avoid contaminating intelligence with assumptions from planning. After action, compare predicted adversary reaction with observed adaptation and update collection.
Resources
- Operation Glowing Symphony 30-Day Assessment — Declassified material illustrating collection, approval, target vetting, intelligence gain/loss, and assessment in a real campaign.