Is This Threat Relevant to Us? A Practical CTI Relevance Test

Decide whether a reported threat deserves attention by testing exposure, adversary intent, capability, opportunity, potential consequence, and the value of acting now.

A threat report can be accurate and still be unimportant to your organization. The practical question is not “Is this threat real?” but “Could it reach something we depend on, does the adversary have reason and ability to try, and would a response improve an actual decision?”

Use this test before escalating a headline, purchasing a feed, opening a detection project, or asking a business owner to act. The result is not merely relevant or irrelevant. It should state why the threat matters, what remains uncertain, and what proportionate next step would reduce that uncertainty or exposure.

Define What “Us” Includes

Start with the decision boundary. “Us” may include corporate systems, factories, cloud tenants, executives, subsidiaries, brands, data, customers, and critical suppliers. A threat that misses the corporate network may still affect a managed service or a product customers rely on.

Name the time horizon too. A campaign may be immaterial today but relevant before a product launch, election, acquisition, or regional expansion. Record which assets and period the judgment covers so readers do not apply it more broadly than the evidence allows.

Test Six Factors, Not One Keyword

Examine six factors and preserve the evidence behind each:

  • Exposure: Do you use the targeted product, service, identity path, supplier, location, or process?
  • Victim fit: Do observed victims resemble you in sector, size, geography, business role, or technology?
  • Intent: Would harming, spying on, extorting, or using your organization advance the actor’s objective?
  • Capability: Has the actor demonstrated the required access, resources, or tradecraft?
  • Opportunity: Are reachable paths, timing, and operating conditions favorable?
  • Consequence: Could successful activity affect safety, operations, money, trust, legal duties, or strategy?

One strong factor can change urgency. Confirmed exposure to active exploitation may matter even when actor identity is unknown. High actor intent means little when the relevant system does not exist in your environment.

Separate Confirmed Facts From Proxies

Direct evidence includes an affected asset in your inventory, matching activity in telemetry, a named supplier notification, or exploitation of an exposed version. Proxies include sector lists, broad geography, claimed targeting, or resemblance to another victim. Proxies can justify checking; they should not be presented as proof.

For every important claim, record source, freshness, corroboration, and confidence. State missing information explicitly: “We have not confirmed whether the subsidiary exposes the affected appliance.” That sentence gives someone a useful collection task. The source evaluation and corroboration method is covered in CTI Sources and Collection.

Match the Response to Relevance and Urgency

Use a simple action ladder:

  • Act now: confirmed exposure, credible exploitation, meaningful consequence, and a time-sensitive control or investigation.
  • Validate quickly: plausible exposure or victim fit, but one decisive fact is missing.
  • Monitor: weak current exposure but credible warning indicators could change the judgment.
  • Record and close: no reasonable path to impact, with assumptions documented.

Avoid turning every relevant item into an incident. Some findings belong in patch prioritization, supplier assurance, a hunt hypothesis, executive awareness, or a future warning list. The output should name an owner and a review trigger.

Write the Judgment So It Can Be Challenged

A useful relevance statement fits in a short paragraph: “This activity is relevant to our European retail operations because we run the targeted remote-access product and observed victims share our operating model. We have no evidence of compromise. Confidence is moderate because external exposure is confirmed but internal version coverage is incomplete. Validate versions within 24 hours; escalate to incident response only if the listed behaviors or access evidence appear.”

This format connects conclusion, evidence, uncertainty, and action. It also makes later review possible. If the assessment changes, update the reason rather than silently changing a color on a dashboard.

Know When to Stop

Stop investigating when the decision has enough evidence, not when every question is answered. More research is wasteful if it cannot change the owner, urgency, or action. Conversely, a low-confidence judgment with high potential consequence may justify one targeted check rather than passive monitoring.

Relevance is a disciplined claim about your environment, not a property attached permanently to a threat. Keep the reasoning visible, define what would change it, and give the next decision owner a clear choice.

Frequently asked questions

Is a threat relevant because it targeted our sector?

Sector targeting is a useful signal but not a conclusion. Confirm whether the victim profile, technologies, geography, business model, and access paths resemble yours.

Can a threat be relevant when none of its indicators appear in our environment?

Yes. Indicators may be absent, expired, or unobserved. Relevant behavior, exploited technology, supplier access, or strategic intent can still justify detection or prevention work.

Should CTI use a single relevance score?

A score can support triage if its components remain visible. Do not let one number hide a decisive exposure or a major evidence gap.

Who decides whether a threat is relevant?

CTI assesses the evidence, while affected owners such as security operations, vulnerability management, business risk, or leadership decide the response within their remit.

When should relevance be reassessed?

Reassess when exploitation changes, new victims appear, your exposure changes, a supplier is implicated, or an earlier assumption is disproved.