Interview question
You have been producing reports for six months and you suspect nobody is reading them. How do you find out, and what do you change?
A question about the feedback step of the intelligence cycle — the one most teams skip, and the reason many CTI functions get cut.
What a strong answer covers
- Treats it as a requirements and feedback failure rather than a distribution problem.
- Goes and asks consumers directly rather than inferring from open rates.
- Asks about decisions, not satisfaction — "what did you do differently" beats "was this useful".
- Considers that the product may be pitched at the wrong altitude or audience.
- Considers timing — intelligence arriving after the decision point is unread by definition.
- Considers format and length, and whether the BLUF is doing its job.
- Willing to stop producing a product nobody needs rather than defending the output.
- Proposes measures based on decisions influenced and requirements satisfied, not report volume.
- Re-establishes requirements with named stakeholders.
Expert answer
I would treat this as a requirements failure rather than a distribution problem, because "nobody reads it" almost always means "it does not answer a question anyone had".
First I would go and ask, in person, and ask the right question. Not "are our reports useful", which everyone answers politely, but "what did you do differently because of anything we sent you in the last quarter". If the answer is nothing, that is the finding. I would also ask what they wish they knew and cannot find out, which usually surfaces the real requirement.
Then I would look at four specific failure modes.
Altitude: am I sending tactical detail to someone who needed a risk judgement, or a strategic overview to engineers who needed a query? This is the most common mismatch.
Timing: is it arriving after the decision was made? A monthly report cadence chosen for the producer's convenience will consistently miss the consumer's decision points.
Format: is the judgement in the first paragraph, or is it on page three after the background and methodology? If a reader has to hunt for the "so what", they stop reading. And is it too long for the audience — a board member is not going to read six pages.
Relevance: is it scoped to this organisation, or is it a threat landscape summary they could get from a news feed?
Then I would change something structural rather than tinkering. Cut the products nobody named, which is uncomfortable but correct — producing an unread report every month is worse than producing nothing, because it consumes analyst time and creates the appearance of a function. Re-establish requirements with named stakeholders and named decisions. Match cadence to their decision cycles rather than ours. And agree what "answered" looks like so requirements can retire.
For measurement I would drop report volume entirely and track decisions influenced, requirements satisfied and retired, detections built from our work and their true-positive rate, and time from external disclosure to internal exposure assessment. Those are checkable and they are what justifies the team.
Mistakes that cost candidates points
- Treating it as a distribution or tooling problem and changing the mailing list.
- Measuring engagement by open rates rather than decisions.
- Defending the existing product rather than being willing to stop it.
- Not considering altitude, timing or format.
- No re-establishment of requirements with named stakeholders.
You have read the answer, which is the easy part. Answer it in your own words and get graded against this same rubric, with the follow-up probe an interviewer would ask next.
Go deeper
Related questions
- A board member asks you what your team does and why it is worth the budget. You have two minutes. What do you say?
- The incident is contained. You have 10 minutes with the board next week. The technical picture is still incomplete and attribution is unresolved. What do you present?
- Tell me about a time your analysis turned out to be wrong. What happened, and what did you change?
- A senior analyst has written an assessment you think is wrong. It is going out to the CISO tomorrow. What do you do?
- It is 2am during a live incident and the incident commander asks you "is this ransomware?" You genuinely do not know yet. What do you say?