Interview question
A board member asks you what your team does and why it is worth the budget. You have two minutes. What do you say?
A communication test disguised as a definitions question. The scoring is almost entirely about whether you can drop the jargon and name a decision.
What a strong answer covers
- Leads with the business outcome, not the process or the tooling.
- Uses no unexplained jargon — no ATT&CK, no TTPs, no actor names, unless immediately translated.
- Frames value as better decisions and prioritisation, not as volume of reports or feeds consumed.
- Gives a concrete example of a decision the team changed.
- Is honest about what intelligence cannot do — it does not predict specific attacks.
- Proposes a measure of value the board can actually check.
Expert answer
"We work out which attackers are realistically likely to come after this organisation, how they operate, and what that means for where we spend money and attention.
Concretely: there are thousands of things we could defend against and a finite budget. Our job is to narrow that down using evidence about who is actually targeting organisations like ours and how. Last quarter that meant we found that the groups hitting our sector were getting in through a particular type of internet-facing appliance rather than through phishing, which changed the order of the security programme — we brought a piece of work forward by two quarters and deferred something else.
What we do not do is predict specific attacks. Anyone who promises that is selling something. What we do is make the prioritisation less of a guess.
If you want a way to judge whether we are worth it, do not look at how many reports we produce. Look at how many decisions changed because of them, and ask the people who receive our work whether it was useful. We track both."
The technique is to lead with the outcome, give one specific example with a decision attached, state the limits honestly, and hand over a way to measure the team that is not vanity.
Mistakes that cost candidates points
- Explaining the intelligence cycle to a board member.
- Using ATT&CK, TTP, IOC or actor names without translating them.
- Claiming intelligence predicts attacks, which overpromises and damages credibility.
- Measuring the team by report volume or feed count.
- Giving no concrete example of a decision that changed.
You have read the answer, which is the easy part. Answer it in your own words and get graded against this same rubric, with the follow-up probe an interviewer would ask next.
Go deeper
Related questions
- You have been producing reports for six months and you suspect nobody is reading them. How do you find out, and what do you change?
- The incident is contained. You have 10 minutes with the board next week. The technical picture is still incomplete and attribution is unresolved. What do you present?
- What is cyber threat intelligence, and how is it different from a threat feed?
- Why do you want to work in threat intelligence rather than another security discipline?
- What threat intelligence do you read regularly, and how do you decide whether to believe a vendor report?