All Posts
Cyber Threat Intelligence
1
min read

The Intersection of Threat Intelligence and Business Objectives

In this blog we explain how threat intelligence helps to support business objectives. Learn more...
Published on
April 12, 2018
Table of Contents

Intelligence exists as a supporting function. It always has a purpose – to inform decision making and drive action. In the government this is inherently understood and the value of intelligence is easy to derive. However, businesses often struggle to determine the value of their threat intelligence team/organization/processes/tools. The terminology of Threat Intelligence (TI) is usually not compatible with the business lexicon, leading to misunderstanding of the purpose and value of TI. There are a few ways to address this, and we will look at one of them in the following post.

Within the government exists a policy that drives all intelligence operations; the National Intelligence Priority Framework (NIPF).

“The National Intelligence Priorities Framework (NIPF) is the primary mechanism to establish, disestablish, manage, and communicate national intelligence priorities. The NIPF reflects customers’ priorities for national intelligence support and ensures that enduring and emerging national intelligence issues are addressed.” (ICD 204, Part D Section 1)

This national-level document drives the development of objectives and helps define the scope of operations at intelligence agencies and within subordinate units. Without this framework, intelligence organizations are left with no guidance and most likely would answer the wrong questions and provide incomplete or inaccurate information. As you can imagine, a framework for your intelligence team is not only important—it is a requirement.

However, businesses do not have a NIPF or any sort of intelligence framework (usually). This leads to intelligence teams that lack focus and struggle with what information to provide to decision makers across all levels within the organization. While the business might not have a NIPF, they do have a generic, macro level set of priorities as can be seen below (not all inclusive):

  • Grow revenue
  • Lower Expenses
  • Reduce/mitigate risk
  • Customer satisfaction and retention
  • Employee satisfaction and retention
  • Compliance Regulation

This list can serve as a starter framework, as it outlines enduring issues businesses constantly seek to address. With these priorities in mind, the threat intelligence team can begin to derive objectives. There are some easily definable objectives that can directly support some of the above priorities.

Once the TI team understands the business objectives, they can align their operations and efforts to support the business. Not all of the business priorities will perfectly align with threat intelligence capabilities, and that’s okay. The first step is to get something in writing; even if it seems overly simplistic or too high-level. You can develop granularity and nuance as you build out your requirements. The following are a few thoughts for a new or young threat intelligence team on where to start and what questions to ask:

  • Reduce expenses related to fraud and cyber crime
    • Collaborate with the Fraud team to determine the top 3-5 types of fraud and ask what information would help them detect/prevent this in the future?
  • Prevent data loss
    • What does analysis of Incident tickets reveal about the nature and type of data targeted in previous data breach events?
    • ​What vulnerabilities were exploited and by what means?
  • Protect PII
    • What systems store PII and how do the vulnerabilities of those systems line up with known exploitation vectors?
  • Reduce business risk
    • TIl can focus on reducing risk due to data loss and external threats by identifying actors and deriving intelligence on external threats targeting their industry, ensuring detection techniques and mechanisms are in place and able to catch these threats.

Sometimes you might get questions from executive leadership. Know how to respond - often they won’t ask the right question and you must be prepared to help them scope and rephrase in such a way that makes the ask achievable/answerable. Also, think about these ad hoc requests to see if there is a recurring theme; this may make for a good standing intelligence requirement.

As a former government intelligence analyst, my first job in the private sector was confusing and a bit daunting. However, I had good leadership that explicitly stated their requirements of the intelligence team and gave us a mission. Sadly, this won’t be the case in all organizations. New and seasoned threat intelligence analysts struggling to convey their value with executive leadership can take solace in the simple truth that they aren’t alone. The hard part is learning the business objectives and aligning your team’s activities with them. For the TI teams that can do this, their value and impact to the business will increase - as will the job satisfaction.

Reference “How to Define and Build an Effective Cyber Threat Intelligence Capability”, H. Dalziel

FEATURED RESOURCES

January 13, 2026
Anomali Cyber Watch

Anomali Cyber Watch: Cisco ISE Flaw, Ni8mare, N8scape, Zero-Click Prompt Injection and more

Anomali Cyber Watch: Cisco ISE Flaw Enables Arbitrary File Read via Administrative Access. Ni8mare and N8scape Vulnerabilities Expose n8n Automation Platforms to Full Compromise. Zero-Click Prompt Injection Abuse Enables Silent Data Exfiltration via AI Agents. Phishing Attacks Exploit Misconfigured Email Routing to Spoof Internal Domains. Ransomware Activity in the U.S. Continued to Rise in 2025. Android Ghost Tap Malware Drives Remote NFC Payment Fraud Campaigns. Black Cat SEO Poisoning Malware Campaign Exploits Software Search Results. MuddyWater Upgrades Espionage Arsenal with RustyWater RAT in Middle East Spear-Phishing. China-Linked ESXi VM Escape Exploit Observed in the Wild. Instagram Denies Data Breach Despite Claims of 17.5 Million Account Data Leak
Read More
January 6, 2026
Anomali Cyber Watch

Anomali Cyber Watch: OWASP Agentic AI, MongoBleed, WebRAT Malware, and more

Real-World Attacks Behind OWASP Agentic AI Top 10. MongoDB Memory Leak Vulnerability “MongoBleed” Actively Exploited. WebRAT Malware Spread via Fake GitHub Proof of Concept Exploits. Trusted Cloud Automation Weaponized for Credential Phishing. MacSync macOS Stealer Evolves to Abuse Code Signing and Swift Execution. Claimed Resecurity Breach Turns Out to Be Honeypot Trap. Cybersecurity Professionals Sentenced for Enabling Ransomware Attacks. Google Tests Nano Banana 2 Flash as Its Fastest Image AI Model. RondoDox Botnet Exploits React2Shell to Hijack 90,000+ Systems. Critical n8n Expression Injection Leads to Arbitrary Code Execution
Read More
December 23, 2025
Anomali Cyber Watch

Anomali Cyber Watch: SantaStealer Threat, Christmas Scams of 2025, React2Shell Exploit, Phishing via ISO, and more

SantaStealer Infostealer Threat Gains Traction in Underground Forums. From Fake Deals to Phishing: The Most Effective Christmas Scams of 2025. React2Shell Exploitation Expands With New Payloads and Broader Targeting. Russian Phishing Campaign Delivers Phantom Stealer via ISO Attachments. And More...
Read More
Explore All