How to Write a Cyber Threat Intelligence Report That Supports Decisions

Write CTI reports that readers can use by defining the decision, separating evidence from judgment, leading with key assessments, expressing likelihood and confidence, tailoring depth, explaining implications, citing sources, conducting analytic review, and editing for clarity.

A useful Cyber Threat Intelligence report tells the reader what the analyst assesses, why the evidence supports that view, how uncertain it is, why it matters, and which decision follows. It does not make the reader reconstruct the answer from a timeline of research.

Good intelligence writing is therefore not decoration added after analysis. Writing exposes the analysis. If the key judgment cannot be stated clearly, the requirement may be vague, the evidence may not distinguish alternatives, or the analyst may not yet know what the evidence means.

This guide takes you from requirement to publication. It explains how to construct key judgments, separate observations and assessments, structure products for different audiences, express likelihood and confidence, present implications without overstepping authority, cite evidence, review tradecraft, and edit for a human reader. The goal is not a particular length or template. It is a report that survives scrutiny and arrives in time to help someone decide.

Define the Report Before You Draft It

Write these facts at the top of your working notes:

  • Requirement: which question must the report answer?
  • Consumer: who will use it?
  • Decision: what will that person investigate, prioritize, prepare, approve, change, or leave unchanged?
  • Deadline: when does the answer stop being useful?
  • Scope: which time, geography, organization, platform, actor, campaign, or business process is included?
  • Standard: how much evidence, confidence, detail, and review does the decision require?
  • Format and channel: alert, assessment, briefing, case note, structured package, or executive memo?
  • Handling: who may receive it, and which source, privacy, legal, or operational restrictions apply?

If you cannot name the decision, ask the requester. “Write a report on Group X” is a topic. “Assess whether Group X’s current access methods create a material detection gap for our cloud environment during the next six months” is a requirement.

The complete requirement and production process is explained in the Cyber Threat Intelligence lifecycle.

Build an Evidence and Judgment Map

Before prose, create a table with four columns:

Item Type Supports or challenges Quality and limits
Authentication log shows a new device enrollment Direct observation Supports account takeover and persistence Authoritative log; user intent unknown
Vendor says the actor uses MFA enrollment External claim Supports actor hypothesis Relevant access; underlying cases undisclosed
Login originated from residential infrastructure Observation plus enrichment Compatible with proxy use Not unique to malicious activity
User states they did not enroll the device Source report Challenges legitimate-use explanation Direct participant; memory and timing require validation

This prevents source claims from being written as observed facts and makes contradictory evidence visible.

Evaluate each source and claim separately. Trace repeated reporting to the earliest accessible evidence. Record observation time, source access, reliability, credibility, independence, handling, and relevance. The method in Cyber Threat Intelligence Sources provides the full framework.

Then map evidence to competing hypotheses. Ask what the leading hypothesis fails to explain and which collection could distinguish the alternatives. Write only after the judgment has a visible evidence path.

Label the Difference Between Observation, Claim, Assumption, and Judgment

Observation: what a sensor, artifact, document, or analyst directly recorded. “Endpoint telemetry recorded PowerShell launching with an encoded command.”

Source claim: what another source says. “The provider assesses that the activity is associated with Cluster A.”

Assumption: an unverified condition the analysis relies on. “We assume the account was not intentionally shared.”

Judgment: what the analyst concludes from evidence and reasoning. “We assess the encoded command was probably used to reduce visibility during execution.”

Implication: why the judgment matters to the consumer. “Current logging records process start but not decoded content, limiting the team’s ability to distinguish this procedure.”

Use verbs deliberately: observed, recorded, reported, claimed, confirmed, indicated, assessed, judged, likely, and may do different work. Avoid “confirmed actor attribution” when only an external source made the claim.

Readers should be able to challenge a judgment without disputing the underlying observation, and update the judgment when an assumption fails.

Write Key Judgments That Contain the Answer

A strong key judgment usually contains:

  • the assessed event, relationship, or future development;
  • relevant actor, target, behavior, or exposure;
  • scope and time horizon;
  • likelihood where appropriate;
  • confidence;
  • the implication that makes it important.

Weak:

Ransomware remains a threat to healthcare.

Stronger:

We assess that ransomware affiliates are likely to continue prioritizing externally reachable remote-access services at regional healthcare providers during the next six months. Our organization operates two such services with incomplete MFA coverage, making identity hardening and access review the most immediate exposure-reduction decisions. We have moderate confidence because sector incident reporting is consistent, but affiliate-specific visibility is incomplete.

The stronger judgment is bounded and connects external behavior to a decision. Its supporting section should explain evidence, alternatives, gaps, and affected systems rather than repeat the sentence in more words.

Give each key judgment one main idea. Order judgments by decision importance, not by chronology or certainty. Do not bury a low-confidence but high-consequence scenario if it requires leadership attention; label it correctly and explain the tradeoff.

Use Layered Structure So Different Readers Can Stop at the Right Depth

A practical structure is:

  1. Title: communicate the subject and, when appropriate, the main change or judgment.
  2. Lede: give the answer, relevance, and urgency in a short opening.
  3. Scope and key judgments: state what the product covers and the main assessments.
  4. Implications or decision points: explain why the consumer should care.
  5. Supporting analysis: organize evidence by judgment or decision question.
  6. Indicators and warning: state what to monitor, how, and what changes.
  7. Gaps, assumptions, and alternatives: include those material to the decision.
  8. Sources and methods: enable review and traceability.
  9. Technical annex: provide artifacts, timelines, mappings, queries, and detailed methods for specialist consumers.

A flash alert may compress this to one screen. An operational assessment may include a timeline, infrastructure, and procedures. A strategic product should emphasize scenarios, business exposure, warning, and options. See Strategic Cyber Threat Intelligence for the leadership-specific structure.

Use headings that answer questions: “The exposed identity path is more important than the malware” is more informative than “Technical analysis.” Tables are useful for exact comparison; timelines for sequence; diagrams for relationships; prose for reasoning and nuance.

Express Uncertainty Without Becoming Vague

Likelihood describes how probable an assessed event or explanation is. Use a consistent vocabulary and time horizon. “Likely during the next three months” is clearer than “may happen soon.”

Confidence describes how strongly evidence and reasoning support the judgment. Explain the drivers: direct access, source quality, independence, consistency, gaps, assumptions, and alternatives.

Avoid phrases that hide the judgment:

  • “It is possible that” is nearly always true and often unhelpful.
  • “We cannot rule out” gives no likelihood.
  • “Potentially linked” does not explain the assessed relationship.
  • “High risk” blurs likelihood, impact, confidence, and organizational risk.

If evidence supports only a possibility, state why the possibility matters and which evidence would raise or lower it. If the deadline requires a preliminary view, label the product, timestamp it, state collection gaps, and schedule the next update.

Different judgments can carry different confidence. Do not assign one confidence label to an entire report if the evidence varies.

Explain Implications Without Taking Someone Else’s Decision Authority

Move from “So what?” to “What decision does this create?”

Useful implications identify:

  • affected assets, identities, suppliers, people, or business processes;
  • the plausible attacker path and consequence;
  • current controls and gaps;
  • urgency and time window;
  • low-regret actions;
  • options and tradeoffs;
  • warning or escalation triggers;
  • accountable decision owners.

CTI may be able to recommend searching for a procedure, restricting a malicious domain, or increasing collection. Decisions about accepting operational outage, paying for a control, public attribution, legal action, market entry, or risk tolerance belong to accountable specialists and leaders.

Use conditional advice where uncertainty matters: “If the supplier confirms that delegated access remained active during the compromise window, suspend the trust pending log review.” This connects action to evidence and avoids presenting a contingent scenario as fact.

Cite Sources So the Assessment Can Be Reproduced and Corrected

A citation should allow a reviewer to identify the source, date, exact claim, and relevant location. For internal evidence, reference the case, query, artifact, or controlled record without exposing sensitive details to unauthorized readers.

Preserve:

  • original source and upstream dependency;
  • publication, observation, collection, and access dates;
  • version, archive, or stable identifier;
  • direct quotation only when exact wording matters;
  • analyst transformations and enrichment;
  • handling and redistribution restrictions;
  • corrections and retractions.

Do not create citation volume for appearance. Five articles derived from one source remain one stream. Cite the original where possible and explain why a secondary source adds value.

Separate source footnotes from confidence. A cited claim can still be weak. The body should explain why the evidence supports the judgment.

Review Analysis Before Editing Style

Use two passes.

Analytic review checks:

  • requirement and scope;
  • evidence for every material claim;
  • source provenance, independence, and credibility;
  • alternative hypotheses and contradictory evidence;
  • key assumptions and collection bias;
  • likelihood, confidence, and time horizon;
  • consistency between key judgments and body;
  • relevance and implications;
  • handling and potential harm;
  • what would change the assessment.

Editorial review checks:

  • the lede gives the answer;
  • headings make the reasoning scannable;
  • paragraphs carry one main idea;
  • acronyms and specialist terms are explained;
  • active voice identifies who did what;
  • dates, units, names, and probability terms are consistent;
  • tables and visuals reduce effort rather than decorate;
  • repetition, throat-clearing, and unsupported adjectives are removed;
  • the conclusion does not introduce new analysis.

High-consequence assessments need an independent reviewer. The author is often too familiar with the evidence to notice an unstated assumption or missing step.

Edit for the Person Who Must Use the Answer

Read the draft from the consumer’s position:

  • Can I find the answer in the first minute?
  • Do I know what is observed and what is assessed?
  • Can I tell how likely the event is and how strong the support is?
  • Do I understand why this matters to my environment or decision?
  • Are alternatives and gaps clear without overwhelming the answer?
  • Do I know what happens next, who owns it, and when the view will change?

Replace abstract nouns with actors and actions. “Credential access activity was observed” becomes “The actor used the captured session to register a new authentication method.”

Remove adjectives that imply analysis without providing it: sophisticated, advanced, significant, targeted, widespread, novel. Keep them only when the report defines the comparison and evidence.

Slow down at the difficult parts. Explain why infrastructure overlap can mislead attribution, why a negative search depends on telemetry coverage, or why a severity score is not patch priority. Brevity that forces the reader to guess is not clarity.

A Reusable CTI Assessment Outline

Use this outline as a starting point, then remove fields the decision does not need:

Title

State the subject and important change or judgment.

Lede

In two or three sentences: what do we assess, why does it matter to this reader, and is action or attention time-sensitive?

Requirement and scope

Decision supported; consumer; time horizon; included and excluded activity; information cutoff.

Key judgments

  1. Assessment, likelihood, timeframe, confidence, and main implication.
  2. Second decision-relevant assessment with its own confidence.
  3. Significant alternative, warning, or exposure where needed.

Supporting analysis

Organize one section per key judgment. Explain evidence, source access, reasoning, contradictions, and alternatives. Do not repeat background that does not support the answer.

Implications and decision points

Affected assets or business processes; likely consequence; options; owners; tradeoffs; low-regret actions.

Indicators and warning

Observable condition; source; threshold; owner; cadence; interpretation; action triggered.

Assumptions, gaps, and what would change the assessment

Include only items material to the decision and assign collection or review ownership.

Sources, handling, and methods

Preserve traceability, restrictions, publication time, version, reviewer, and next review date.

The outline is a decision scaffold, not a requirement to fill every heading. A flash warning may fit on one screen; a consequential attribution may need a substantial evidence annex.

The Publication Checklist

Before release, confirm:

  • the product answers a named requirement and decision;
  • the title and lede communicate the main answer;
  • key judgments are specific, bounded, and supported;
  • observations, source claims, assumptions, judgments, and implications are distinguishable;
  • likelihood, confidence, scope, and time horizon are consistent;
  • material contradictions and alternatives are addressed;
  • citations preserve provenance and restrictions;
  • implications identify decision points without overstepping authority;
  • technical detail is layered for the right readers;
  • visuals improve understanding and are accessible;
  • analytic and editorial review are complete;
  • version, publication time, review date, owner, and correction channel are recorded;
  • every intended consumer can receive and use the product in time.

After publication, collect feedback and outcomes. Did the report answer the question? Which judgment affected action? What was misunderstood? Which gap created a new requirement? Intelligence writing improves when publication is treated as a handoff in a decision cycle, not the end of the analyst’s work.

Frequently asked questions

What should a CTI report start with?

Start with a lede that gives the reader the most important answer and why it matters. The report itself should be built from a defined intelligence requirement, consumer, decision, scope, and deadline before drafting begins.

What is a key intelligence judgment?

A key judgment is a concise analytic answer to an important part of the requirement. It states what the analyst assesses, the relevant scope and time horizon, likelihood where appropriate, and confidence, while the supporting text explains the evidence and alternatives.

How do facts and analytic judgments differ?

A fact or observation describes what a source or sensor recorded. A judgment explains what the evidence likely means. Reports should also distinguish source claims and assumptions so readers can see where evidence ends and analysis begins.

Where should confidence appear in a CTI report?

Confidence should appear close to the judgment it qualifies, with a brief explanation of the evidence quality, source access, consistency, gaps, assumptions, and alternatives that drive it. One report can contain judgments with different confidence levels.

How long should a threat intelligence report be?

Long enough to answer the requirement and support scrutiny, but no longer. Put the answer and implications first, layer supporting detail beneath them, and move specialist evidence or methods into annexes. Length should follow the decision, not an arbitrary page target.

Should a CTI report make recommendations?

It should explain implications, decision points, options, triggers, and relevant actions. Whether it should recommend one treatment depends on the team's mandate and expertise. Risk, legal, operational, and business owners retain their decision authority.

What should an intelligence report review check?

Review should test requirement fit, source provenance, claim support, alternative explanations, assumptions, likelihood, confidence, internal consistency, handling, audience relevance, clarity, and whether the title, lede, key judgments, body, and visuals communicate the same assessment.