Module 3: Types of Intelligence

Strategic, Operational, and Tactical CTI

Learn the difference between high-level trends and ground-level technical indicators.

In this lesson, you will learn to:

  • Identify which type of intelligence is most appropriate for a given audience.

Strategic, Operational, and Tactical CTI

Understanding the different audiences and purposes for CTI.

One Size Does Not Fit All

When you are producing intelligence, knowing your audience is everything. If you hand a CISO a list of malicious IP addresses, they won’t know what to do with it. If you hand a Security Operations Center (SOC) analyst a 50-page report on the geopolitical motivations of a nation-state actor, they will be equally frustrated.

To solve this, Cyber Threat Intelligence is generally broken down into three main levels:

  1. Strategic Intelligence
  2. Operational Intelligence
  3. Tactical Intelligence

Let’s break down what each of these means and who consumes them.

The Three Levels of CTI

Strategic Intelligence is the “big picture.” It focuses on broad trends, financial impacts, and long-term risks. It asks questions like, “Are threat actors targeting our industry more this year than last year?” or “How does a new data privacy law affect our risk exposure?”

  • Audience: Executives, the Board of Directors, CISOs, and other high-level decision-makers.
  • Format: Whitepapers, executive summaries, risk assessments, and briefings.

Operational Intelligence zooms in a bit closer. It focuses on the specific capabilities, infrastructure, and campaigns of threat actors. It asks questions like, “What vulnerabilities is this specific ransomware group currently exploiting?” or “What techniques do they use to move laterally inside a network?”

  • Audience: Security managers, incident response leads, and threat hunters.
  • Format: Adversary profiles, campaign reports, and threat models.

Tactical Intelligence is ground-level data. It is highly technical and highly actionable, often with a very short lifespan. This is the realm of Indicators of Compromise (IoCs) - the specific IP addresses, domain names, file hashes, and registry keys associated with a threat.

  • Audience: Security Operations Center (SOC) analysts, firewall administrators, and automated security tools (SIEMs, SOARs).
  • Format: Data feeds (like STIX/TAXII), YARA rules, and alert signatures.